I think that they have an extremely durable/redundant data store, which is effectively "write-only". You write to some server that replicates its data to other machines, possibly in remote data centres. Read about "eventual consistency" if you are interested.
This makes it practically impossible to delete data reliably. You can never be sure whether or not "ghost" copies remain after you delete data. For example on machines that failed and went offline between the write and the delete. You can expect that such machines "eventually" will receive the delete command, but you cannot be sure. Especially as the system is designed to heavily prefer data redundancy.
I would guess that encryption itself is a "trick" to avoid having to solve the "deletion problem".