There are indeed two options, the one where you have to trust us and the security of our server is just there to quickly test the procedure or for small amount addresses.
In both cases, the private key we send you is not the final private key, you still have to combine it with your own private key. Since we don't have that one, your address is safe.
The combination procedure is described in the solution email. I suggest you try to order a free address to see how it all works

I actually tried to order an address(1Money) with no case sensitive setting on. I thought it was free, but it turned out I had to pay 0.01 for the address

Not a particularly desirable price to pay for a 5 letter vanity with no cases.
I will try with a 4 letter one though, I'll let you know how it works out

''"
EDIT: It worked out fine. Very clear on the instructions. You probably should make it clear that you must use the "Add" option instead of "Multiply" on bitaddress.org though.