The public key model appears to be TOFU [4]. It's doing a distinct crypto_box per notification [5]. It doesn't use an authenticated key exchange or offer key rotation or forward secrecy, but that's probably fine for this use case. Not too long ago, I wrote a guide to end-to-end encryption [6], and I would classify the "end-to-end encryption" here as meeting the minimum definition (data is encrypted between devices, rather than in a client-server architecture where the server has access to plaintext), even if it's not suitable for more sensitive threat models.
One thing I didn't see was message padding of location data prior to encryption, to prevent side-channel attacks via ciphertext length. [7] I don't know if I missed this, or if it was omitted.
[1] https://github.com/zood/george/blob/52ddae2b5f65d324e1785c2d...
[2] https://github.com/zood/george/blob/52ddae2b5f65d324e1785c2d...
[3] https://github.com/zood/george/blob/52ddae2b5f65d324e1785c2d...
[4] https://github.com/zood/george/blob/52ddae2b5f65d324e1785c2d...
[5] https://github.com/zood/george/blob/52ddae2b5f65d324e1785c2d...
[6] https://soatok.blog/2020/11/14/going-bark-a-furrys-guide-to-...
[7] https://ioactive.com/ssl-traffic-analysis-on-google-maps/