wow, I was assuming that everything is stored encrypted on Googles servers. Would be cool if someone could clarify this, as the explanation in the Google help is a bit vague IMHO.
To my understanding they started providing the option to encrypt only very recently.
My take is obviously that it's bad for the company policy to have this stuff encrypted (any regular guy would have had built-in encryption when making such a sync service).
But on the other hand it would be pretty bad advertising when Firefox always had full encryption. Providing the option (but not making it mandatory) gives the proper advertising/evangelizing arguments.