(384-bit prime) - Why not just use X448 since that's now an Internet Standard?
AES-256-CCM is an interesting choice. At least it's an AEAD mode.
It also uses Fortuna for IVs, etc. instead of directly /dev/urandom (or window.crypto in JS land). Userspace CSPRNGs are a devastatingly stupid idea.
Where is the identity verification ("How do I know I'm speaking to the correct public key?")?
> Europeans: Did you know that when you use U.S. cloud services, your data is stored under US jurisdiction, and handled under under the Patriot Act? This means that a foreign government can inspect your or your client's data even without informing you.
FUD. Where you host the data shouldn't matter, because the server should never be given access to your plaintext.
My advice: Avoid like the plague.