Everything sent over the wire to their apis is encrypted, but using an easily reversible fashion. The encryption key is a combination of a static salt and the user's session id. The session id is also sent to the api as an http header, so it's pretty easy to decrypt that anyway.
n.b. I wrote the windows phone app
On the other hand, if we're talking about an adversary with a more limited capabilities - maybe he can access only 50% of the computers in the world and that cannot crack encryption at will - Than there are papers talking about theoretically sound systems that can give you anonymity with very high reliability.
On the other hand I guess the whole point is knowing your friends secrets, not just people secrets.