That is understandable.
The note is stored encrypted using AES 256-bit keys. The only time it's decrypted without your credentials is when you don't login during the check-in period.
I also want to make it end-to-end encrypted (still looking into it) but that has a UX problem. If the recipients need a key to decrypt it, a new problem of keeping the key safe and not forget about it also appears. And if we keep the key on our server then it also kills the whole point of e2e.
I'd love to know any change I can make to make your more confident in it?