Official comment
Yes, you can definitely restrict visibility on projects for normal users. You just need to change your permissions in Settings and normal users will need to be explicitly assigned to a project in order to view the project (the projects won't even show up in reports and dashboards unless the user running the report has access).