Not easy to describe it or ask about it Yes you are correct.
When you are at home, you use the network 'as is': no VPN. No encryption from VPN. If your internet link is already encrypted e.g. using TOR, then that stays the same. (BTW I would not be inclined to use VPN over TOR as TOR can be quite slow).
When you leave home, you use a device (laptop / tablet / phone /another desktop) which has the VPN software installed (I use OpenVPN connect client on my devices). You take the certificates which you created when you installed VPN on the Pi, a different one for each device, and use the client to import the certificates and then create the enycrpted tunnel.
You then access your network remotely and all traffic is encrypted from the Pi to your remote device. Safe Surfing
Hope that helps explain it all.