I mentioned your repo knows everything you have installed. How is that not substantive?
There's not some kind of zero-knowledge k-anonymity (https://blog.cloudflare.com/validating-leaked-passwords-with...) type feature. It simply doesn't exist. Apt doesn't use it, yum doesn't use it, pacman doesn't use it. They all know everything.
If you wanted more detail, you could have asked. Instead you said my comment had no substance.
Please read this very carefully: GFY.