If Google decides to change how they save drafts you're compromised. They also have complete control of the page so any key press or mouse movement you do they can catch.
Yup, you're right. I tried to inspect and intercept every XHR call that gmail was making to ensure we weren't missing any holes. But it's entirely possible that there's analytics/tracking data that got passed.
Like we said, this is a starting point. It's open source. As with any type of security product that has a hope of being good, try and break it and let's fix it together :)