Well I can audit the source code of my client and be assured that it will only rekey when it sees proof (posted via twitter) that the person the data was encrypted for has joined.
Keybase doesn't have my private key (only I do), so they can't re-encrypt the contents.
(sorry if I misunderstood your question)