Every word in your first and third sentences are true. As written, your second sentence is iffy at best. [0][1]
However, the situation that those sentences describes does not apply to end-to-end encryption in Signal. Signal's crypto keys are generated on the end-user's device and never leave that device.
Signal neither requires OOB key exchange, nor does it require that you set a password to encrypt Signal data while on disk.
Because Signal has the same properties that you claim are indicators of a lack of E2E encryption, but actually is E2E encrypted, it's clear that these properties are not proof positive of a lack of E2E encryption.
So, I reword my previous question, which you failed to address:
What happens when a WhatsApp user gets a new phone, wipes his existing phone, or simply clears all locally stored WhatsApp app data? Does he get a new set of crypto keys, and are his conversation partners alerted of this fact as happens in Signal?
I ask because I don't use WhatsApp and don't know the answer to the question.
[0] Consider Diffie-Hellman key exchange. This is a method whereby two parties who wish to communicate securely over a hostile channel can do so without divulging any key material to eavesdroppers listening in on the exchange.
[1] To address the possibility that you're talking about key verification, rather than secure peer-to-peer session creation: if you like, Signal will show you the fingerprint of your encryption key. You can use that fingerprint to perform any OOB key verification that you want.