Thanks for the clarification (and thanks to throwaway above as well), seems this is standard. Is there a salt in this implementation? Is it bruteforced the first time I open the database on a new device?
It says the encryption is done client-side so a salt would be public.
edit: they may be salting with the username or email address.