They are also certainly not deleted from your record either. I have requested a copy of my data from Facebook, and it contained messages that both parties have been deleted. That's to be expected though.
Sure the javascript is open source, but how many people will actually read and understand it before running it?
Not saying that this specific script or post has any nefarious intent, but it's obvious how easy it would be to trick a bunch of otherwise intelligent people to give away access to their facebook account by posting something that claims to protect privacy.
Cydia, most linux repositories, any browser extension you find. Most of the time you are just hoping that the author wasn't malicious, and that somebody else has audited the code before you ran it.