Your real IP address will be visible to all peers, even when using a VPN. This is inherent to WebRTC P2P.
Malicious extensions can access all content including encryption keys. Use trusted extensions only.
If your device is compromised later, recorded messages could be decrypted. Avoid highly sensitive topics.
Use the fingerprint button to verify peer identities. Compare out-of-band to prevent MITM attacks.
Always scan downloads for malware. Files are not scanned. Only download from trusted sources.
Compare these fingerprints with your peer over a secure channel (phone, in person) to verify identity.
[ok] if fingerprints match: connection is secure
[!] if fingerprints don't match: possible mitm attack