quite right, xpubs are / should be kept private
best to avoid the vendor sites if possible and connect your HW device to your own node
I don't know how well-known it is that you can skip the vendor software mostly (once firmware is up-to-date, I think - maybe for initial seed generation but while offline?).