How strong is that password — and has it already leaked? Strength is scored on your device; the breach check sends only the first 5 characters of a SHA-1 hash, never the password itself.
How the breach check stays private: your password is hashed with SHA-1 in the browser, only the 5-character hash prefix is sent to the Pwned Passwords API, and the response is a list of hash suffixes it matches locally against yours. A 5-character prefix is shared by millions of passwords — it cannot reveal yours.