Like Threema, they use the PGP model, instead of OTR...
What do you mean exactly? According to the FAQ, Threema offers perfect forward secrecy: Yes, Threema provides forward secrecy on the network connection. Client and server negotiate temporary random keys, which are only stored in RAM and replaced every time the app restarts (and at least once every 7 days). An attacker who has captured the network traffic will not be able to decrypt it even if he finds out the long-te…
They do use forward secrecy on SSL, but not on the messages themselves.