Seems like there is a "password" required to encrypt/decrypt but the app's descriptions says:
> - No Sign Up / Log In / Usernames / Passwords.
So I'm guessing this password is stored server-side and the passwords are associated to device ids.
Seems like it would read your contacts and then send them to their servers too, not a fan of doing that personally.
I'm not sure why the app mentions encryption/security as it seems far from being the main point of the app.