The email goes through our server and is NOT encrypted. However, you don't have to include the sensitive data in the email. You can instead just include a link and read the submitted data securely on our site.
You might also want to consider the on-site version of our application, which you can run on your own server and database. More info here: http://onsite.formassembly.com
For the record (this was also answered by email), when checking the 'Use SSL' box in the form "display & processing" configuration tab, the data submitted with the form is transmitted encrypted, using the SSL protocol (the standard for encrypted transmissions over the internet).
Regarding the statement: "However, you don't have to include the sensitive data in the email. You can instead just include a link and read the submitted data securely on our site."
I'm sorry if I missed that but how can you link the users of your form to their submitted data?