The first thing I looked at is the security model page. It doesn't give much detail, other than saying "we use libsodium defaults". Ok...which defaults, and how are they used?
The mention of RSA is also a bit of a red flag. RSA is extremely out dated, what excuse is there for using it in new apps?
(Also: I try to avoid being overly critical of people's projects, but password managers are critical pieces of software.)