Their handy little program could quite easily be quietly uploading your passwords in a side-channel, and it'd be very hard to detect. Basically, what they're assuring you is "you have to trust us not to be deliberately malicious, but you don't have to trust that we're not incompetent, too". Which is definitely a better assertion than blanket trust.
However, if they should, maliciously or accidentally, do something bad that costs me thousands of dollars, I'd still have absolutely no recourse. Whereas, if my bank did the same thing, I'd be entitled to a complete refund of what their mistake or malicious act cost me. |