That was my understanding as well, but there were definitely unencrypted portions like URL. I assume for sharing purposes.
Doesn’t seem critical if we’re talking Facebook and twitter but becomes problematic with human rights orgs and the like.
The justification was that it was used to match login fields against vault items. I’m no crypto expert but it seemed flimsy to me