I don't think this service is End-to-End encrypted the way we would like to think it is. If you can share pictures with friends by just giving them a link to a page, the server app has the encryption keys too.
Some bits of the blog post are outdated, since the feature has matured since then. But the implementation details are roughly the same.
TL;DR: The keys are added to the URL fragment (the part that follows the #), and these fragments are not accessible to the server.