Let's not forget that this decryption and re-encryption[1] is going on in the AWS cloud, which is ostensibly shared infrastructure. Its not just what Amazon can see, but what other people who happen to be running on the boxes doing this re-encryption can see (through security vulnerabilities).
[1] I'm making the assumption here that re-encryption is actually occurring. It could be the case that its not and the phrasing was simply poor.