It's hardly surprising that, with physical access to the device, the encrypted messages can be decrypted. Logic dictates that, for the app itself to be able to do so, the keys must be either stored locally or retrievable.
A more worrying attack would be something able to decrypt the traffic on the wire, or a man-in-the-middle.