I read it as something like this: "We really promise not to mess up your account. Really-really. Oh wait, our server has been hacked".
However, we never store your authorization tokens in our server, and instead just directly pass your authorization token into a client-side cookie.