Encrypted before storage
Every card number is encrypted with AES-GCM on your device before it is written to storage. The local database and the cloud mirror only ever contain ciphertext.
Where the key lives
The encryption key is held in your device's secure keystore, the iOS Keychain on iPhone, the Android Keystore on Android, protected end to end. That is what lets your other devices decrypt synced cards while nobody else, including us, can.