Earlier quoted context omitted.
With 1Password you also have a randomly generated secret key. As I recall it’s a 128-bits, but could be wrong. To access your vault an attacker will need both your master password and the secret key. These are effectively combined to generate your keys for decryption. This protects against an attacker gaining access to 1Password servers. They can’t control whether you chose an awful password or not. So to protect the…
Sorry, I don't get it. The secret key has to be stored somewhere, right? If it's on the server, the attacker gets it together with the vault. If it's on the client, then you lose your phone → you lose your passwords, which is, while secure, very risky and I wouldn't expect it from a company focused on regular customers.
You could save it in a local keepassXC database if you like.
This 128bit key is only saved locally, not on their servers. So contrary to you disbelief, 1Password does actually prioritise security in this manner over focusing on ‘regular customers’.
Its also fairly common to have more than one device, so you would have the key on more than one device as a result too.