Earlier quoted context omitted.
I'm building a chat platform with js and https crypto. It's better than nothing in my opinion.
A false sense of security is worse than nothing at all.
This will thwart your nosy flatmate/little-brother.
This is reasonably likely to keep curious or nosy corporate IT or HR staff at bay if you use it at work. It's not going to keep a properly authorised and resourced corporate IT investigation/surveillance out - at least not for any hardware that's got corporate ssl roots installed (or device management that allows installation of those).
It'll likely keep local cops out. It's less likely to keep feds out if they're determined. It 100% will not help against people who've got browser trusted ssl signing roots and the ability to run QUANTUM on exploited backbone routers to deliver their own versions of the javascript appropriately ssl encrypted to you before the actual site has a chance to respond.