I don't want to harp on about this again, but I really don't think you can put any sort of trust into such things as this. With GPG, you're producing an encrypted version of some text/data with a bit of code you can build yourself and run completely on your equipment, airgapped or whatever.
With signal/whatsapp, there is no way of even knowing if the code you're using "in app" is the code in github or in whatever rev wherever. Yes, I know reproducable builds -- but what stops the app fetching more code from elsewhere? Wanna bet there's a webview and some JS in that app somewhere?
It's nice to make things harder for the NSA to read, but this architecture seems to be just creating the illusion of safety and it's kind of weird to see how much advocacy it gets here when there are such obvious faults in it.
I'm not saying there's a better alternative, and congrats to all who are working on it and I'm happy to see it succeed -- but this isn't a solved problem and there's massive danger in trusting such things.
I'd love to have the time to really inspect whatsapp/signal to see what I'm sending/getting -- has anyone done this? Google isn't giving me much..