After local training, a client must communicate what it learned. It does not send its data. It sends a model update: either the full updated model parameters, or equivalently the difference between the model it received and the model it ended up with.
A model's parameters are just numbers — the weights of a neural network, for example. An update is a collection of numbers describing how those weights should change. The server can add or average these numbers without knowing anything about the emails, photos, or medical records that produced them.
This is what makes FL possible at all: updates are compact compared to datasets, and they are the only thing that crosses the network. But a warning worth repeating from Week 1: an update is not nothing. Clever attacks can sometimes infer information about training data from updates, which is why privacy mechanisms like secure aggregation exist.
So the round's flow of information is: model goes down to clients, updates come up to the server. Day 5 explains what the server does with a pile of updates once it has them.