Playing the Devil's advocate (IANOCoder), but perhaps the bulk of the 1s&0s are being uploaded and then decrypted by sending a small string when the user selects "publish"?
That's a little silly. How is trusting them to correctly implement an encryption scheme terribly different from trusting them to responsibly delete aborted photos in the first place?
Surely they probably got it covered in the Terms, but it still strikes me as playing slightly dirty..