I love these sorts of projects, but I don't trust them as a rule. If I can't independently verify the security myself, I don't use them. What sort of symetric key encryption does it use? What cypher? What hash algorithm? Does it provide perfect forward secrecy? Does it anonymize the sender in some way? What data is logged? Etc.
By the way, wasn't Cryptocat shot down initially for its "host-based security" [1]? Why didn't ChatStep learn from that?<p>[1]: <a href="http://www.wired.com/threatlevel/2012/08/wired_opinion_patrick_ball/all/" rel="nofollow">http://www.wired.com/threatlevel/2012/08/wired_opinion_patri...</a>