Federated learning trains a model on data that cannot legally move — but it is private only with secure aggregation and differential privacy. The architecture and honest limits.