Seems the crux is in the auto-updating, right? So now we have security people telling us to always run the latest updates, to protect against 0-days, and security people telling us to not update, because that lets the service spy on us.
It does not seem to me that there is any middle ground, barring writing your own client, from scratch, against an open protocol.
EDIT: seems to me that web-based e2e encryption, as described here, still protects you from irresponsible employees of the service reading your messages. And database leaks etc. Getting an update that spies on customers shipped is not a trivial thing in most organisations.