The fact that its default chats are not end-to-end encrypted and are stored in plaintext on its servers is a concern. Everyone who talks about this as a huge deficiency should also consider that this applies to email too, unless one always uses encryption (like GPG/PGP or S/MIME). Sharing personal photos and such may have shifted from emails and websites to chat platforms, but email is still a place where the most sensitive of information tends to be exchanged. That said, the UX of end-to-end email encryption in a federated and widespread way is not yet a solved problem (without kludges, like for example, hosting the encrypted email on a site and sending the link across if the email is sent to a user on another provider), whereas key end-to-end encryption on chat apps is a (mostly/completely?) solved problem.