they offer a web client, so, they already have decryption keys for your email. They should just offer IMAPS like everybody else and stop pretending they couldn’t read your email if they wanted to.
They say[1] they only store subject line and to/from addresses accessible to them.
This should be sufficient to implement a web client which does client-side decryption of the content, in which case they indeed could not read the contents.
And they do have the IMAP bridge, I've been using it for a year with Thunderbird without any issues so far.