i'm cross-posting my comment originally from this thread about some other snakeoil to these two threads about databag i see now:
is the databag protocol/design documented somewhere? does it claim to have forward secrecy?
from a quick glance I see here they're generating an AES key from a passphrase and using it to encrypt an RSA private key, which is... not a good sign.
fwiw https://simplex.chat is another thing which seems to have similar goals and functionality but is better documented.