The claim is that (a) both entities are properly encrypting the data _in transit_ and (b) either company could _steal_ the plaintext client-side (after decryption).
Trust that a third-party application isn't stealing the decrypted messages requires the same type and amount of trust that Apple is not stealing the decrypted messages (or maybe less trust if the third-party solution is open source, etc.).