The extension keeps everything locally, only the information necessary to make payments is transferred. There is even a blacklist in place that prevents any information about sensitive sites (online banking, mail accounts, other adult content) from ever being stored.
Here is a blogpost about it: https://blog.flattr.net/2017/06/key-elements-of-the-new-flat...