Yes, look at the setting on your Android client, you can see where the option for Encryption has a large blue button, You need to set it up for it to work.

As far as your question above, yes I suppose if someone gets your unlocked phone that is not using encryption (which is rare now days) then perhaps they could get to and retrieve un encrypted notes from the phone.

On scenario I can see this happening is if you use an SD card, some Android phones will NOT encrypt an SD card. My Moto G6 will not, my older Samsung will. If you use a utility to move the Joplin notes to the SD card and it's nt encrypted then you could be vulnerable.