I implemented a similar architecture, but within three weeks http://i.imgur.com/hfoyz.png :)
The user's master password is not encrypted, it is used to create the key to encrypt and decrypt user's data, and the encryption key created from the master password, as a derivative of the master password, is never stored or transmitted.
This way, we can assure our users that even us cannot ever access their data.