The encryption export laws are draconian in how strict they are (considering the fact that software can be transmitted over a network effortlessly), but this requirement has nothing to do with whether a particular encryption approach or implementation is authorized, but that the system (your app) utilizing it is vetted first. #IANAL, however.