“Twitter can probably obtain your private keys, and admit that they can MITM you and have full access to your metadata.”
XChat has no forward secrecy, so one leaked key opens every past message. The private key sits behind a 4-digit PIN on Juicebox servers, and X runs all of them. X supplies the other person’s public key with no way to check it. The “built in Rust” encryption is the C version of libsodium.