The real short answer seems to be: encryption is done client-side by Javascript.
I'd worry about the extra attack vectors because of that - man in the middle, snooping browser extensions, etc (or even just strong-arming them into silently changing their javascript do no encryption)
To his credit, he writes about this as well:
> On a trust scale, is it better to use PGP or PrivateSky if you want to be 100% sure that no one can see your data? Answer: There is no question that [...] a system such as PGP is better [...]
> There is only one problem. PGP and the current state of the art are too damn hard for the general population at large to use. [...]