Adding a device to your account and encrypting the tokens are distinct unreleated steps.
When you enable encryption, they derive an encryption key off the passcode you provide, encrypt the tokens, then store them on authy's cloud storage. The encrypption key is never sent to authy's servers, and only stored on device. When you add a new device, you're prompted to enter the passcode, which generates an encryption key and decrypts the tokens.
How is support going to decrypt the tokens for you? They need the password, which they don't have.
You use support to add a device to your account, and then you use the password to decrypt your tokens.
Granted, an attacker could gain access to your authy account and then delete all your tokens, but that's different from being able to log in and start using your TOTP 2fa codes. You should also have recovery codes written down somewhere in the case this happens for all your services.
I literally just restarted everything from my previous post with more words.