Earlier quoted context omitted.
The problem is that phone numbers are a small space for brute force, and depending on how much they truncate, this could be very close to uploading one's address book.
Yup. Hashing phone numbers is basically useless. If they truncate enough there might be plausible deniability due to possible collisions but I suspect the chance of collision is still quite low as they don't want to annoy people with false positives.
There is indeed a way to truncate enough to balance the amount of data sent to the device vs privacy.