I'm no crypto or security expert, but this worries me:
"For security, the online password databases are encrypted with client-side keys derived from your master password"
What is going on here? Does it hash my master password, generating a new pass? If so, this seems like it would only increase the number of bits in the possible keyspace but not increase the number of possible keys, while actually lowering security (since hash collisions can occur).
This worries me because non-standard crypto applications tend to actually introduce holes and vulnerabilities. What other vulnerabilities lie hidden here?