Is is clear why they do the redirect?
https://old.reddit.com/r/ProtonMail/comments/62rfta/comment/...
Redirecting to the https site is a bit less secure than the hidden service, in that your traffic will only go over 3 hops (TOR client) rather than 6 (TOR client + hidden service circuit). But AFAIK they could also write a modified TOR client that served a hidden service without any additional hops. Those additional hops are best seen as security for the hidden service rather than the user. Also, a hidden service for a well known business is kind of a pointless marketing gimmick.
Same applies of course to chat apps that offer end to end encryption.
Maybe it's safe for messages to be intercepted, but can you trust the application decrypting messages and displaying to do just that?