I share that concern and would not rely on my messaging being secure. Anyways as far as they state it themself, your private key for decrypting should stay on your device (in fact it uses the signal protocol and does a few more steps, e.g. to implement shared sessions over multiple devices. You can have a look at their FAQ, they've linked a white paper within it describing the technical details). But the main question is in my opinion: do you trust the guarantees they give you? It's the same struggle as with any proprietary software. You can trust them or you don't, but you will never know without access to the source code.
I share that concern and would not rely on my messaging being secure. Anyways as far as they state it themself, your private key for decrypting should stay on your device (in fact it uses the signal protocol and does a few more steps, e.g. to implement shared sessions over multiple devices. You can have a look at their FAQ, they've linked a white paper within it describing the technical details). But the main question is in my opinion: do you trust the guarantees they give you? It's the same struggle as with any proprietary software. You can trust them or you don't, but you will never know without access to the source code.