Stegstr
Stegstr is built so that the answer is usually "nothing". This page says exactly what changes when you turn Network on or upload a picture.
Network is off when you first open the app. In that state, embedding and detecting run entirely on your device, and the web version runs entirely in your browser tab. No image, message or key is sent anywhere. The only way data travels is the image you choose to share, and the message inside it is encrypted.
With Network on and a Nostr identity, posts, reactions and direct messages are published to Nostr relays. The default relay is wss://relay.stegstr.com, operated by Web3 Services LLC, the maker of Stegstr. Public relays can be enabled as secondaries in Settings. The relay list the app starts from is published at stegstr.com/config/relay.json.
Profile pictures, banners and post attachments are uploaded to nostr.build, a third-party host, signed with your key (NIP-98). They are stored unencrypted and readable by anyone with the URL. The app says so next to the upload buttons; you can paste a URL to an image hosted elsewhere instead.