They didn't need to. When you start denying IAMP to your customer in the name of "encryption" at that point it becomes privacy theatre, instead of privacy, irrespective of how nobly activist their intensions are. It is probably slightly worse than a mail provider assuming they can't trust their users with encrypting their emails when needed.
Tuta is always encrypted I don't know where you got the impression that it was optional or that they could somehow magically make it work over IMAP without a bridge like proton.