Private Email Provider Comparison
This source-dated matrix compares five private email providers across thirteen documented attributes. It does not independently test, score, rank, or recommend a provider.
/* Not legal advice. This page is research, not compliance guidance. */ /* */
What this private-email comparison can establish
This is a source-dated comparison of Fastmail, iCloud+ Mail, Mailbox.org, Proton Mail, and Tuta Mail across thirteen preregistered attributes, not independent testing or a provider verdict.
The roster and attribute set were fixed before the page was written. Each provider row has one current persisted cell for every attribute, producing a sixty-five-cell evidence set. A displayed value comes from the exact provider and attribute shown in the matrix; it is not inferred from another column, filled from another provider, or broadened beyond the captured product, plan, region, platform, claim type, source class, source URL, capture date, and observation version.
The comparison separates account identity, operating entity, data-region language, encryption scope, domain and alias features, client access, retention, deletion, lawful-request reporting, assessment records, and source availability. Those fields answer different questions. Their presence on one page does not turn them into a composite privacy score or a claim that one provider is categorically stronger.
Published vendor documents remain vendor-stated evidence. Public repositories remain public records for the component, version, license, and scope they document. No account was created and no provider behavior was tested for this page. The matrix carries no score, rank, best label, highlighted row, affiliate parameter, superiority claim, or preferred-provider conclusion.
Private Pierce has no affiliate, referral, sponsorship, gift, preferred-access, or paid-placement relationship with any listed provider. Use the privacy-tool comparison methodology and corrections hub for its preregistered roster and attributes, claim labels, capture dates, and correction path. The email alias service comparison covers the alias or forwarding layer that may sit before an inbox.
Identity, operating entity, and data-region statements
Initial signup identifiers and later verification triggers are separate from operating-entity and data-region statements, and none of those fields by itself establishes residency, anonymity, or a universal jurisdictional outcome.
The signup column reports the identifier type, requiredness, collecting actor, plan, region, and platform stated by the current cell. The later-verification column separately reports an event after signup, the additional identifier requested, the collecting actor, who retains it, and any stated plan or region. A signup requirement does not describe every later identity check, and a later trigger does not rewrite the initial account path.
The operating-entity column records the legal name, incorporation jurisdiction, governing law, hosting jurisdiction, and document locator only where the vendor's captured text supports them. Those concepts are not interchangeable. A governing-law clause is not automatically an incorporation statement, and an entity jurisdiction does not establish where every category of inbox data is stored or processed.
The data-region column asks whether a choice is documented, which regions are named, when selection occurs, whether migration is supported, which data categories the statement covers, and what plan and scope qualify it. A region statement remains tied to those fields. It is not expanded into a guarantee about every subprocess, recipient, backup, client, support system, or legal request.
Missing qualifiers stay missing. If an operating-entity cell states incorporation but not hosting, the matrix can report the incorporation field without choosing a hosting location. If a data-region cell names regions but does not establish migration support or covered categories, those elements remain unsettled. This field-by-field treatment prevents a broad provider statement from supplying details the exact cell does not contain. It also prevents an answer about a legal entity from becoming an answer about storage choice, or an answer about storage choice from becoming an answer about governing law.
Each row preserves the exact evidence state for each question. An unsupported qualifier remains unknown instead of being inferred from a provider's brand, customer location, domain, or another matrix column. The result is a comparison of documented claims, not an anonymity guarantee or a conclusion about where every message-related record exists.
| Jurisdiction | Signup identifiers | Later verification | Operating entity | Data-region options |
|---|---|---|---|---|
| iCloud MailApple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.source | Apple's account-creation steps have users provide an email address, create a strong password, and set a device region; the primary email address is used to sign in to the Apple Account.source | Apple says it verifies that the requester is the account holder after an Apple Account deletion request.source | Apple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.source | Apple says personal data collected worldwide by Apple or an affiliated company is generally stored by Apple Inc. in the United States.source |
| FastmailFastmail says it is an Australian company named Fastmail Pty Ltd.source | Fastmail says it collects name, primary Fastmail username, billing and contact details, organization and domain names, IP address, browser type, communications records, and tokenized payment information.source | Fastmail says mobile-phone verification can occur at signup or during a trial.source | Fastmail says it is an Australian company named Fastmail Pty Ltd.source | Fastmail says all customers, including trial users, can choose servers in the European Union or United States regardless of location.source |
| mailbox.orgMailbox.org says it is operated by Heinlein Hosting GmbH.source | Mailbox.org says its online account request requires a desired user name, first and last name, a natural person's country of habitual residence or a juridical person's country of domicile, and a password.source | Mailbox.org says opening an account requires a first and last name, but it does not verify that information at any point and permits any pseudonym.source | Mailbox.org says it is operated by Heinlein Hosting GmbH.source | Mailbox.org says files are stored exclusively in its own data centers in Germany, across two independent locations in Berlin.source |
| Proton MailProton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.source | Proton Mail lets a user create a Proton account with either a Proton Mail address or an external non-Proton address.source | Proton Mail says verification may be requested for some sensitive operations beyond account creation using Proton Captcha, email, or SMS to protect against brute-force attacks.source | Proton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.source | Proton Mail says Proton owns and controls server hardware at several locations in Switzerland, keeps data out of the cloud, and uses data-center sites that require biometric access.source |
| Tuta MailTuta's imprint identifies Tutao GmbH in Hanover, Germany.source | Tuta says it collects the newly registered email address when starting a contractual relationship and providing the service.source | Tuta says paid-product invoicing and VAT determination collect the customer's country, an optionally provided private-user name and invoicing address, and a VAT number for business customers in some countries.source | Tuta's imprint identifies Tutao GmbH in Hanover, Germany.source | Tuta says all data is stored in ISO 27001-certified data centers in Germany.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Signup identifiers
- Identifier type, requiredness, collecting actor, plan, region, and platform stated for signup.
- Later verification
- Trigger, requested identifier, collecting actor, retained-by field, plan, and region stated by the cell.
- Operating entity
- Legal name, incorporation jurisdiction, governing law, hosting jurisdiction, and vendor document locator stated by the cell.
- Data-region options
- Choice availability, named regions, selection time, migration support, covered data categories, plan, and scope stated by the cell.
Encryption scope, domains, aliases, and client access
Documented end-to-end-encryption scope and client-access support answer different questions, while custom-domain and alias fields describe address capabilities rather than message confidentiality.
The encryption column preserves the captured statement for message bodies, subject lines, calendars, contacts, attachments, external-recipient boundaries, key control, platform, and plan. A statement about one content type does not supply an answer for another. Mail exchanged inside one system is not assumed to have the same boundary as mail sent to an external recipient, and a plan or platform statement does not automatically extend to every client.
Custom-domain support records whether sending and receiving are documented, along with domain limits, address limits, DNS requirements, plan, and region. Alias limits record the alias type, creation or active limit, send and reply support, deletion or reuse rule, custom-domain eligibility, and plan. A custom domain and an alias can both change an address, but the matrix does not treat them as the same product function or as proof of a particular encryption boundary.
The IMAP-or-bridge column records direct IMAP, direct SMTP, bridge availability and name, supported clients and platforms, local-processing statements, plan, and limitations. Protocol or bridge support answers how a local client may connect. It does not independently establish the end-to-end-encryption scope of stored content or messages exchanged outside a provider's system.
Plan and platform qualifiers stay attached to the feature that carries them. A domain limit does not become an alias limit, a supported client does not become a supported platform, and a bridge name does not establish direct protocol access. Likewise, an encryption statement for a message body does not answer the subject-line, calendar, contact, attachment, or external-recipient fields unless the same cell does so. Keeping those subfields visible prevents a partial statement from being summarized as universal coverage. It also lets a reader distinguish a documented absence, an unstated detail, and a positive feature statement without converting any of them into an overall provider grade.
These four columns stay separate because combining them would invent relationships the cells do not establish. Domain support does not prove alias capacity. Alias capacity does not prove client compatibility. Client compatibility does not prove message confidentiality. The matrix reports only the current cell for each provider and attribute, with the source class and capture date visible.
| Jurisdiction | End-to-end-encryption scope | Custom-domain support | Alias limits | IMAP or bridge |
|---|---|---|---|---|
| iCloud MailApple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.source | Apple says iCloud Mail does not use end-to-end encryption because it must interoperate with the global email system, while native Apple email clients support optional S/MIME message encryption.source | iCloud+ Mail lets subscribers use an existing custom domain to send and receive email from a personalized address.source | iCloud Mail lets users create up to three @icloud.com aliases after setting up a primary address, and use those aliases to send and receive mail on iCloud.com or devices with Mail enabled in iCloud settings.source | Apple says iCloud Mail uses IMAP and SMTP, which most modern email client apps support, and does not support POP.source |
| FastmailFastmail says it is an Australian company named Fastmail Pty Ltd.source | Fastmail says customers can use PGP or S/MIME in third-party apps, while its own apps do not offer end-to-end encryption.source | Fastmail says using a custom domain requires at least one account administrator on a non-Basic subscription plan.source | Fastmail says accounts can have up to 600 aliases, plus 15 for every user in the account.source | Fastmail says IMAP, POP, and SMTP allow an account to connect to a third-party email client.source |
| mailbox.orgMailbox.org says it is operated by Heinlein Hosting GmbH.source | Mailbox.org says its webmail client uses PGP and S/MIME so emails are encrypted securely from end to end.source | Mailbox.org says users can send and receive emails from a custom domain.source | Mailbox.org says email aliases are server-side forwarding addresses that direct multiple email addresses to one primary inbox.source | Mailbox.org says users can set up IMAP, POP 3, and SMTP in their chosen email software and integrate other email accounts.source |
| Proton MailProton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.source | Proton Mail says message bodies and attachments are stored with end-to-end encryption, while subject lines and sender and recipient addresses are encrypted but not end-to-end encrypted.source | Proton Mail lets users create addresses on their own domain names to send and receive messages.source | Proton Mail says users can create at least 10 additional addresses using any Proton domain or a custom domain they own, while the primary address and disabled custom-domain addresses do not count toward that limit.source | Proton Mail says Bridge runs in the background, encrypts and decrypts messages entering and leaving the computer, and provides a local IMAP/SMTP server for adding the account to an email client.source |
| Tuta MailTuta's imprint identifies Tutao GmbH in Hanover, Germany.source | Tuta says each user's encryption key belongs only to that user and is not shared with anyone, including Tuta.source | Tuta says all paid personal and business plans support adding a custom domain and as many email addresses as needed.source | Tuta says all paid plans support an unlimited number of custom-domain email addresses that can be disabled if an address is leaked.source | Tuta says it does not offer IMAP because that would require sending decrypted data to the device, and instead provides open-source desktop clients that store data encrypted.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- End-to-end-encryption scope
- Message body, subject line, calendar, contacts, attachments, external-recipient boundary, key control, platform, and plan stated by the cell.
- Custom-domain support
- Send and receive support, domain and address limits, DNS requirements, plan, and region stated by the cell.
- Alias limits
- Alias type, creation and active limits, send and reply support, deletion or reuse rule, custom-domain eligibility, and plan stated by the cell.
- IMAP or bridge
- Direct IMAP and SMTP, bridge availability and name, supported clients and platforms, local processing, plan, and limitations stated by the cell.
Retention and account deletion are lifecycle questions
Account-deletion instructions do not by themselves prove immediate erasure of every data category, so retention and deletion remain separate fields with their triggers, durations, exceptions, controllers, and timeframes intact.
The retention column records a data category, trigger, duration, exceptions, and controller when the captured document supplies them. A duration attached to one category does not become a schedule for all messages, account records, billing records, logs, backups, support records, or legal records. A stated exception stays connected to the rule it qualifies.
The deletion column separately records the initiation path, whether the source states completed erasure, exceptions, timeframe, and controller. A documented account-closing step does not establish that every data category is erased at the moment the step is taken. Likewise, a deletion timeframe does not answer the retention rule for a category the source treats separately.
A retention trigger and a deletion initiation path are not the same event unless the captured text makes that connection. The controller named for one category is not assigned to another, and an exception in one policy statement is not applied across the entire row. The matrix preserves each relationship as documented: category to trigger, trigger to duration, rule to exception, and deletion step to any completion statement or timeframe. This prevents a procedural instruction from being read as a data-state observation.
Relative and conditional language remains relative and conditional. The comparison does not convert a period tied to a trigger into a fixed calendar date, remove an exception for brevity, or infer completed erasure from an interface instruction. When the captured text does not settle one of the preregistered fields, that field remains unknown rather than being rewritten as immediate deletion or zero retention.
The lifecycle rows are vendor-stated evidence captured from the provider's own published documents. They are not an observation of a completed deletion request, a forensic test of storage systems, or a universal statement about future behavior. Reading the fields together can show what the documents say; it does not authorize a stronger outcome than the exact cells support.
| Jurisdiction | Retention | Account deletion |
|---|---|---|
| iCloud MailApple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.source | Apple says it is required to retain past transaction information for financial reporting purposes, may be required to retain certain information to comply with a court settlement or other ongoing legal procedure, and also retains a one-way hash of the deleted account's email address.source | Apple says that, after verification is complete, account details and data associated with the Apple Account are permanently deleted from its servers.source |
| FastmailFastmail says it is an Australian company named Fastmail Pty Ltd.source | Fastmail says IP logs are retained for up to one year to monitor for fraud, an email address is retained for up to twelve months after account closure to prevent impersonation, and account data is deleted within seven days after closure with a short archive period for recovery, and that it may store data longer if required for legal, regulatory, or dispute resolution purposes.source | Fastmail says users can cancel an account and then choose Learn more and delete all data to close the account immediately and permanently delete all data.source |
| mailbox.orgMailbox.org says it is operated by Heinlein Hosting GmbH.source | Mailbox.org says its web server, web portal, and administration interface store access times and originating IP addresses to protect against misuse and unauthorized access, then erase them after four days.source | Mailbox.org says users can cancel a contract through the cancellation form on its website or in the Mailbox Suite under All settings > Contract and payment > Contract.source |
| Proton MailProton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.source | Proton Mail says IP addresses, email addresses, and phone numbers supplied for verification codes and anti-spam purposes are retained temporarily, while permanently saved data is stored as a cryptographic hash whose raw values Proton says it cannot decipher.source | Proton Mail says deleting a Proton Account permanently deletes the account and all its data from Proton systems with no recovery path.source |
| Tuta MailTuta's imprint identifies Tutao GmbH in Hanover, Germany.source | Tuta says personal data is deleted no later than 30 days after contract termination, while inventory data may be retained for up to two years for complaint handling or other orderly-settlement reasons and other stated exceptions may apply.source | Tuta says personal data is deleted no later than 30 days after contract termination, subject to stated complaint, fee, legal, claim, tax, contract, and commercial-law exceptions.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Retention
- Data category, trigger, duration, exceptions, and controller stated by the current cell.
- Account deletion
- Initiation path, completed-erasure statement, exceptions, timeframe, and controller stated by the current cell.
Requests, audits, and source availability show different kinds of accountability
A transparency report, an audit disclosure, and a source repository answer different questions, so their presence or absence cannot be combined into one accountability or provider-quality verdict.
The request-reporting column records the published period, jurisdiction, unit, scope, count, and absence reason supplied by the current cell. Requests, orders, accounts, identifiers, disclosures, and challenged matters are not interchangeable units. A process statement is not a count, and the absence of a published report is not zero requests.
The assessment column records only the assessment date, assessor, scope, access, and report locator established by the vendor-published material. Recording that a report or locator exists does not create a Private Pierce quality verdict. A bounded assessment does not automatically cover every client, server, feature, release, policy, or period, and the matrix does not broaden its scope.
The source-availability column reports the repository, license, component, version, and release locator stated by the cell. A public repository supports a claim about the named artifact; it does not by itself establish operating jurisdiction, hosting region, retention, completed erasure, lawful-request counts, or the source status of an undocumented component.
Two source-availability rows are verified absences under the declared primary-document read. Those cells remain typed unknowns with their scope. They are not rewritten as no source, none, unsupported, or closed source, and they do not establish that the providers publish no code anywhere. The label describes what the specified documents did not disclose under the capture method.
Claim labels remain visible because the source classes carry different limits. Vendor-stated evidence reports what a provider published. Public-record evidence reports what a named repository or artifact establishes. Neither label is upgraded into independent product testing, and none of the three columns substitutes for either of the others.
| Jurisdiction | Request reporting | Assessment record | Source availability |
|---|---|---|---|
| iCloud MailApple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.source | Apple's transparency report lists, for July 1 through December 31, 2025 in the United States of America, 16,809 Apple Account requests received, 52,948 accounts specified in requests, 3,043 requests challenged in part or rejected in full, 7,431 requests where only non-content data was provided, 7,845 requests where content was provided, and data provided for 91% of requests; these figures cover Apple Account requests, not iCloud Mail alone.source | Apple says it undergoes annual independent attestation by an accredited registrar.source | Unknown Verified absenceNot disclosed in the captured primary source.source |
| FastmailFastmail says it is an Australian company named Fastmail Pty Ltd.source | Fastmail says all requests are checked for legal validity before being actioned.source | Fastmail says its Bug Bounty Program encourages third-party security review and that it performs regular internal audits.source | Fastmail says Cyrus stores email, contacts, and calendars and supports JMAP, IMAP, CardDAV, and CalDAV.source |
| mailbox.orgMailbox.org says it is operated by Heinlein Hosting GmbH.source | Mailbox.org says a total of 74 official requests for information were sent to Mailbox.org in 2025.source | Mailbox.org says Heinlein Hosting GmbH, the legal operator of Mailbox.org, has been awarded C5 Type 1 certification by the German Federal Office for Information Security.source | Unknown Verified absenceNot disclosed in the captured primary source.source |
| Proton MailProton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.source | Proton Mail says it rejects all requests from foreign authorities because Article 271 of the Swiss Criminal Code bars it from transmitting any data to foreign authorities directly.source | The Securitum document says it summarizes work Securitum conducted to test listed web applications.source | Proton Mail says all Proton apps are open source and have been audited and verified by third-party experts.source |
| Tuta MailTuta's imprint identifies Tutao GmbH in Hanover, Germany.source | Tuta says it releases an individual mailbox only after receiving a valid German court order and cannot decrypt the encrypted data stored in Tuta mailboxes.source | Tuta says its apps were audited by independent security experts before public release, and that SySS GmbH experts performed a penetration test of its system.source | Tuta's repository record identifies a GitHub repository at github.com/tutao/tutanota.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Assessment record
- Assessment date, assessor, scope, access, and report locator stated by the current cell.
- Source availability
- Repository URL, license, component, version, and release locator stated by the cell, preserving verified absences.
Limits, capture dates, and corrections
The matrix records what the cited sources stated when captured, not how an account, policy, repository, platform, or provider will behave after that date.
A capture date records when a source was read, not that the source has stayed the same since. Read each value with its provider, product, plan, region, platform, claim type, source class, source URL, capture date, and observation version. A statement that lacks one of the preregistered details remains bounded by what its exact cell supports.
The matrix does not establish anonymity, universal non-collection, a guaranteed jurisdictional outcome, or independent performance. It does not infer message confidentiality from domain, alias, IMAP, or bridge support. It does not infer complete erasure from an account-deletion instruction. It does not infer product-wide source availability from one repository or product-wide assurance from one assessment record.
A typed unknown preserves the evidence boundary for one field. A verified absence means the declared primary documents did not disclose that field under the capture method. Neither label proves that the underlying feature, record, process, or artifact cannot exist. Another provider's value never fills the gap, and another attribute in the same row never becomes a substitute.
Inclusion and alphabetical row order by operating entity are neutral. The page has no score, rank, best label, highlighted provider, affiliate parameter, recommendation, sponsorship, preferred access, gift, or paid placement. It compares the five frozen rows and thirteen attributes without turning their documentation into a provider preference.
Use the privacy-tool comparison methodology and corrections hub for the shared roster and attribute method, claim labels, capture-date meaning, and correction path. Use Email Alias Forwarding and Private Inboxes to separate the inbox from the forwarding layer. This page remains bounded to the five-row, sixty-five-cell evidence set it transcludes.
How to read Unknown
- Unknown: Verified absence
- The captured authority was searched and shows no such rule or filing. No value is printed because the absence is the finding. The reason and the authority are printed beside the badge.
- Unknown: Not yet verified
- The captured sources did not settle this field yet. No value is printed, not even an earlier one. The reason is printed beside the badge, and an authority is linked only when one was supplied.
Frequently asked questions
What does a private email provider comparison measure?
It compares thirteen documented attributes across five preregistered provider rows, with each value tied to its exact current cell, claim label, source, and capture date.
Is end-to-end encryption the same as IMAP or bridge support?
No. Encryption scope describes the content and exchange boundaries stated by its cell, while IMAP or bridge support describes a documented client-access path.
Does account deletion erase every retained data category immediately?
A deletion instruction does not establish that result. The matrix keeps initiation, completed-erasure statements, exceptions, timeframes, controllers, and separate retention fields intact.
What does a verified absence mean in this matrix?
It means the declared primary documents did not disclose the preregistered field under the capture method; it is not rewritten as no, none, unsupported, or closed source.