Isn't this a big assumption? The way I envision it is
1. client encrypts data with their key
2. server computes on data without decrypting and without needing the key
3. client decrypts computation output with their key.
Or is it always required at step 2 that the server also has the key needed for encryption (but not decryption obviously)?