They're either stored in your choice of third party service or you can host it yourself if you really want.
I don't see if the private half of the key is shared with the web app to decrypt the cypher text, or if the cypher text is sent to the key service which responds with plain text.
> I also wouldn't be surprised if the shit only works in Chrome.
I don't see any evidence of this in the documentation. I can't think what API it would require beyond the widely adopted fetch API.
> Also, wasn't Zoom sued for bastardizing the concept of "end-to-end encryption" to mislead people?
I don't see any reason to think this is much different from any other end-to-end system. All the mobile end-to-end apps require you trust the code they run on your device. As described this requires you to trust the JavaScript they run on your browser.