We implemented a system where the key used to encrypt messages is generated in the browser and never leaves the browser. This ensures even we cant decrypt messages. The downside is the end user has to remember a 'Room Secret Key'.
You can read more here: https://www.tesla.im/#encrypted_rooms
We are just a few weeks into beta and have only a few hundred users. Been working well so far. However it's too early for us to give solid validations.