My thoughts exactly. With their closed source app running on the client, they can do literally anything with the plaintext before encrypting it.
Be ready for an expansion of their fear-mongering ad campaigns about how anyone in your office or home can read your messages when you send them unencrypted.