Rather than using something like libsodium's public-key box API, which is wonderful, it's using a 2048-bit Diffie-Hellman Prime group. This isn't really great. You should definitely upgrade to more modern primitives. I can highly suggest libsodium as a drop-in replacement.
The other thing about this that's more concerning is that I have no idea if there is any validation going on to prevent small subgroup confinement attacks on this, but I don't really want to spend anymore free time checking this out and I'll leave it as an exercise for the reader/author.
Personally, I wouldn't use this product until a few cryptography design decisions were changed. If you're marketing this as a privacy-centric product, there's a lot of work to be done--not just on the Diffie-Hellman usage.
0. https://github.com/encrypted-dev/userbase/blob/master/src/us...