As far as I can see the disappearing messages feature is ‘burn on read’, the time start to count after reading the message as it does on Signal. I’m not sure this is the best approach, especially for high-risk users.
A group of activists being in risk will shorten the disappearing messages time, but a seized device or any device off / not checked will compromise the group by storing messages in the server. If the user is forced to open the device, the messages will be downloaded and sensible info could be revealed despite the burn on read feature.
If I had to choose between burn on read and expiring disappearing messages, I would choose expire (the type the time starts to count at sending). If forced to reveal the password no message would be retrieved after the expiring time. Expiring messages with the current delete old messages Delta feature would be much safer, IMHO. Even better with a temporal, burner account.
Wickr me, for example, with both burn on read and expiring features has a much better approach on the issue than signal. Not to say the info revealed by signal would be linked to phone numbers, which are like ID cards in many countries.