{
  "cells": {
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says accounts can have up to 600 aliases, plus 15 for every user in the account.",
      "fetch_event_id": "77505258-afa2-5fd2-ade0-82b038e719d7",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Accounts can have up to 600 aliases, plus 15 for every user in the account. More details on limits can be found at our Account limits help page.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "07f3a26d554835a10f9b26e0ddec9c9a81c5d0f56d96bde43b58864656d762f3",
      "source_url": "https://www.fastmail.help/hc/en-us/articles/360060591073-How-to-set-up-aliases",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says its Bug Bounty Program encourages third-party security review and that it performs regular internal audits.",
      "fetch_event_id": "2762e437-bacc-5775-92c7-d66e8698bc9f",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The Fastmail Bug Bounty Program encourages third party review of our security. We also perform regular internal audits and stay aware of the latest best practice and security research.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "7a05a9e605005ab843270fcb64aab1742ba73a28a9c7e4eccd77be32b72a8a13",
      "source_url": "https://www.fastmail.com/features/security/",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says using a custom domain requires at least one account administrator on a non-Basic subscription plan.",
      "fetch_event_id": "6492deee-4124-5154-abdc-d0892557267d",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "In order to use custom domains with Fastmail, at least one admin of the account must be on a non-Basic subscription plan.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "cbc8bfa89eacb663920e1b807be845fe4f1d96d0b38ff89da381509627b6b580",
      "source_url": "https://www.fastmail.help/hc/en-us/articles/360058753394-Custom-domains-with-Fastmail",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says all customers, including trial users, can choose servers in the European Union or United States regardless of location.",
      "fetch_event_id": "828f24f6-3d25-572d-ade3-e880ce617368",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "All customers, including trial users, have the option to choose EU or US servers, regardless of where you are located.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "25ee37769e62ff3698b1fb5f28fa100d0ea63fef5e3214e8a706ecb247c112dc",
      "source_url": "https://www.fastmail.help/hc/en-us/articles/16796454162063-Choosing-your-data-residency",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says users can cancel an account and then choose Learn more and delete all data to close the account immediately and permanently delete all data.",
      "fetch_event_id": "7508b935-686e-5d41-818f-1b21c9cda256",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "If you would prefer to close your account immediately and permanently delete all your data, you can follow the above steps to cancel your account, and then return to Settings → Billing & Plan and click Learn more and delete all data .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "4f1e63b1cf22938f3a83bdf8575a9b01b4338ab63ef2966df0081a3eab07cfff",
      "source_url": "https://www.fastmail.help/hc/en-us/articles/1500000277342-Canceling-and-deleting-accounts",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says customers can use PGP or S/MIME in third-party apps, while its own apps do not offer end-to-end encryption.",
      "fetch_event_id": "2381bb93-d877-5723-9d1b-fdee14fdb112",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Fastmail customers looking for end-to-end encryption can use PGP or s/mime in many popular 3rd party apps. We don’t offer end-to-end encryption in our own apps, as we don’t believe it provides a meaningful increase in security for most users, while the trade-offs are significant.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "7a05a9e605005ab843270fcb64aab1742ba73a28a9c7e4eccd77be32b72a8a13",
      "source_url": "https://www.fastmail.com/features/security/",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says IMAP, POP, and SMTP allow an account to connect to a third-party email client.",
      "fetch_event_id": "67d9477f-623f-5992-9b8d-c78a29a454f8",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "IMAP, POP, and SMTP are standards that allow you to connect your Fastmail account to a third-party email client of your choice.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "c4cb3c47dd72109b5c99cf5d455eb997678376e81c5136ca30af8b5f1e1518fb",
      "source_url": "https://www.fastmail.help/hc/en-us/articles/1500000279921-IMAP-POP-and-SMTP",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says mobile-phone verification can occur at signup or during a trial.",
      "fetch_event_id": "dcd09e46-24f8-5be2-8360-b77d6d84ebd4",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "If you experience any issues verifying via mobile phone at signup or during your trial, please contact our support team .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "74e95179359408ee06fa97a589cfe554f22b6292ef847cc314048309f4aae43d",
      "source_url": "https://www.fastmail.help/hc/en-us/articles/1500009438961-I-can-t-sign-up",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says it is an Australian company named Fastmail Pty Ltd.",
      "fetch_event_id": "a821de74-816e-547d-9465-06610d71f60c",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Fastmail is an Australian company, Fastmail Pty Ltd ( “Fastmail” ).",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "9afad1dfd2b824daec0e5706a94cc9e2f585832b0591672de4489dc689a741e8",
      "source_url": "https://www.fastmail.com/policies/privacy/",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says all requests are checked for legal validity before being actioned.",
      "fetch_event_id": "0fbb18e3-8ad8-598f-9d2e-e56fe54ac366",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "All requests are checked for legal validity before being actioned.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "05b87623883b4cb1cef96079818a3452f6e28b8a60bf845b40be15d0d0b7b385",
      "source_url": "https://www.fastmail.com/policies/transparency-report/",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says IP logs are retained for up to one year to monitor for fraud, an email address is retained for up to twelve months after account closure to prevent impersonation, and account data is deleted within seven days after closure with a short archive period for recovery, and that it may store data longer if required for legal, regulatory, or dispute resolution purposes.",
      "fetch_event_id": "be4085f9-ab8f-5ab7-af1e-b081502fec07",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Specific retention periods include:",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "9afad1dfd2b824daec0e5706a94cc9e2f585832b0591672de4489dc689a741e8",
      "source_url": "https://www.fastmail.com/policies/privacy/",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says it collects name, primary Fastmail username, billing and contact details, organization and domain names, IP address, browser type, communications records, and tokenized payment information.",
      "fetch_event_id": "19389926-adfa-50f1-9456-675a86d3f561",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "When you sign up for or use our services, such as Fastmail or Topicbox , we collect Personal Information such as your name, primary username - Fastmail email, billing and contact details, organization and domain names, and technical data like your IP address and browser type. We will also keep records of your communications with us. We also collect tokenized payment information to Process transactions securely.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "9afad1dfd2b824daec0e5706a94cc9e2f585832b0591672de4489dc689a741e8",
      "source_url": "https://www.fastmail.com/policies/privacy/",
      "table": "vendor"
    },
    "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Fastmail says Cyrus stores email, contacts, and calendars and supports JMAP, IMAP, CardDAV, and CalDAV.",
      "fetch_event_id": "73b44465-e05d-5c28-83c0-fbd04756b2bb",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Cyrus is the battle-tested server that stores your email, contacts, and calendars at Fastmail, and supports access via JMAP, IMAP, CardDAV & CalDAV.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "564ea9fa4ce1815877d3f614ab057539261c356e42eb1b07398e9b480ccd5b8e",
      "source_url": "https://www.fastmail.com/company/open-source/",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "iCloud Mail lets users create up to three @icloud.com aliases after setting up a primary address, and use those aliases to send and receive mail on iCloud.com or devices with Mail enabled in iCloud settings.",
      "fetch_event_id": "50547e47-a154-53ab-8ee9-69f315dafedb",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "After you set up a primary iCloud Mail address , you can create up to\nthree @icloud.com email aliases on iCloud.com. After you set up an\nalias, you can send and receive mail from that alias on iCloud.com and\non any device that has Mail turned on in iCloud settings .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a37ca10104c9b4c2e1df87a1120ea469104597c1bd803072245bad1c6a43f1cd",
      "source_url": "https://support.apple.com/guide/icloud/add-and-manage-email-aliases-mm6b1a490a/icloud",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple says it undergoes annual independent attestation by an accredited registrar.",
      "fetch_event_id": "6c7fd353-4c04-5d14-a180-8a20d4026dbe",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Apple undergoes an independent attestation by\nan accredited registrar on an annual basis.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "9bab79d0ee0b6c5b039d9acb68bd3555a9583b426aa52f15514e9f7c98b390f8",
      "source_url": "https://support.apple.com/guide/certifications/apple-internet-services-security-apc34d2c0468b/1/web/1.0",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "iCloud+ Mail lets subscribers use an existing custom domain to send and receive email from a personalized address.",
      "fetch_event_id": "913397bd-31e6-596f-8930-c91d83fc94c8",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "If you subscribe to iCloud+, you can use a custom domain that you\nalready own to send and receive email from a personalized email address\nwith iCloud Mail.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "ae736446957292444ae8ed15f134c6b4bf2415f242b5118b59ae3615439434fd",
      "source_url": "https://support.apple.com/en-us/102540",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple says personal data collected worldwide by Apple or an affiliated company is generally stored by Apple Inc. in the United States.",
      "fetch_event_id": "bee07725-c90d-5c68-b249-de341a3bb629",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Personal data collected by Apple or an Apple-affiliated company worldwide is generally stored by Apple Inc. in the United States.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "dbbad8a02adb6060887d387b0bb0dc85ba1220f813fddb84ab20eb78cb56c8b0",
      "source_url": "https://www.apple.com/legal/privacy/en-ww/",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple says that, after verification is complete, account details and data associated with the Apple Account are permanently deleted from its servers.",
      "fetch_event_id": "ac708536-3327-5ba4-b39a-053a488a630d",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "After this verification is\ncomplete, account details and data associated with your Apple Account\nare permanently deleted from Apple’s servers.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "76ee2472bcc3c72d11d7158eaade06deab5a9bfa708fffc9d4bf137867c2eb05",
      "source_url": "https://support.apple.com/en-us/102559",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple says iCloud Mail does not use end-to-end encryption because it must interoperate with the global email system, while native Apple email clients support optional S/MIME message encryption.",
      "fetch_event_id": "c9b95f5b-f131-5d4f-bc1c-2b0bb694ca28",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "iCloud Mail : iCloud Mail does not use end-to-end encryption because\n    of the need to interoperate with the global email system. All native\n    Apple email clients support optional S/MIME for message encryption.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "2c09eae66bb30fe6a9d67111515abf9cc2a5095975d5faeac84f90a7d971b9b9",
      "source_url": "https://support.apple.com/en-us/102651",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple says iCloud Mail uses IMAP and SMTP, which most modern email client apps support, and does not support POP.",
      "fetch_event_id": "a92a05e4-ac6f-5e79-b2b2-a28521473da1",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "iCloud Mail uses the IMAP and SMTP standards supported by most modern\nemail client apps. iCloud Mail does not support POP.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "9caecdf409f72a5e84f90048d2fffa4ecc4c001148cebe5607ba3dfb1f700c04",
      "source_url": "https://support.apple.com/en-us/102525",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple says it verifies that the requester is the account holder after an Apple Account deletion request.",
      "fetch_event_id": "5d94f404-5c14-5acb-9415-46f3f8bd99c6",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "After you request deletion of your Apple Account, we verify that you are\nthe account holder who made the request.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "76ee2472bcc3c72d11d7158eaade06deab5a9bfa708fffc9d4bf137867c2eb05",
      "source_url": "https://support.apple.com/en-us/102559",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.",
      "fetch_event_id": "31a34d1b-a761-59c4-bda4-61c479fbbbd9",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "• Apple Inc., located at One Apple Park Way, Cupertino, California\n  95014, for users in the United States, including Puerto Rico;",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a5dfe99fda95a9b05d372df6648585206238b35e329e43034b989d538616e359",
      "source_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple's transparency report lists, for July 1 through December 31, 2025 in the United States of America, 16,809 Apple Account requests received, 52,948 accounts specified in requests, 3,043 requests challenged in part or rejected in full, 7,431 requests where only non-content data was provided, 7,845 requests where content was provided, and data provided for 91% of requests; these figures cover Apple Account requests, not iCloud Mail alone.",
      "fetch_event_id": "b968ef22-c748-5450-89b5-f781a636ea74",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "2025 H2,7/1/25,12/31/25,United States of America,\"16,809\",\"52,948\",\"3,043\",\"7,431\",\"7,845\",91%",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a4a877634513a2dc61aedf6c97c1204aa713870fa9209fb0155f111bfe949dea",
      "source_url": "https://www.apple.com/legal/zip/transparency/Apple_Transparency_Report.zip",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple says it is required to retain past transaction information for financial reporting purposes, may be required to retain certain information to comply with a court settlement or other ongoing legal procedure, and also retains a one-way hash of the deleted account's email address.",
      "fetch_event_id": "bbb5184c-ce64-5636-bfc1-7e94d9afbe50",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "When you delete your Apple Account, Apple makes our best effort to\ndelete all personal data associated with your account. However, we are\nrequired to retain past transaction information for financial reporting\npurposes, and we may be required to retain certain information to comply\nwith a court settlement or other ongoing legal procedure. We also retain\na one-way hash of the email address of the deleted account to comply\nwith legal obligations, and for so long as necessary for the legitimate\ninterests of demonstrating our compliance with data protection laws and\nfor account security. This hash of your email address will be retained\nas evidence that Apple complied with your deletion request. For\nthird-party (non-Apple) domain accounts, the one-way hash is deleted\nafter six years. For other accounts, this hash is retained in line with\nour retention policy, which is reviewed regularly.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "76ee2472bcc3c72d11d7158eaade06deab5a9bfa708fffc9d4bf137867c2eb05",
      "source_url": "https://support.apple.com/en-us/102559",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Apple's account-creation steps have users provide an email address, create a strong password, and set a device region; the primary email address is used to sign in to the Apple Account.",
      "fetch_event_id": "46b197df-67f8-5a1e-a1f7-0c292a40f927",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Follow the onscreen steps to provide an email address, create a\n    strong password, and set your device region. This primary email\n    address will be what you use to sign in to your Apple Account.*",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b25c802b7a63b94fcd40a60f96cb58d10ea6bb36abd89bc590c6a5501b796c55",
      "source_url": "https://support.apple.com/en-us/108647",
      "table": "vendor"
    },
    "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": null,
      "fetch_event_id": "d8d47c1b-9ef9-5d82-8c74-1bde3a81b862",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": null,
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "ea1e26b0f878268f19dcb4c535c611f6d5d82b5266915ae6c9e58680f4faaad7",
      "source_url": "https://opensource.apple.com/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says email aliases are server-side forwarding addresses that direct multiple email addresses to one primary inbox.",
      "fetch_event_id": "ed059a57-0ebc-56aa-aa6e-17faaf823306",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Email aliases are essentially server-side forwarding addresses that allow multiple email addresses to be directed to a single primary inbox.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "754f07cee923793631a0c6e54dd5a82ec5012b0937a29d8850e9ebf784732d30",
      "source_url": "https://kb.mailbox.org/en/private/e-mail/what-is-an-alias-and-how-do-i-use-it/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says Heinlein Hosting GmbH, the legal operator of Mailbox.org, has been awarded C5 Type 1 certification by the German Federal Office for Information Security.",
      "fetch_event_id": "23ee1048-7f84-5b4a-9c79-8d5da79bdb53",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Heinlein Hosting GmbH, the legal operator of mailbox, has now been awarded C5 Type 1 certification by the German Federal Office for Information Security (BSI).",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "fa4306cb8302c07cfa057cd17a7a376fa49f250773965fa8881ddb4dbebc3b66",
      "source_url": "https://mailbox.org/en/news/bsi-c5-certification-mailbox-full-compliance-bsi-criteria-cloud-security-confirmed/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says users can send and receive emails from a custom domain.",
      "fetch_event_id": "98733ed2-4385-5930-bda1-b3d46948c8ab",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You can also send and receive emails from your custom domain",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "29398d8fd89c62434a92db7300acb2d8e56ecd4bcf1a8f9820e955c19a338699",
      "source_url": "https://kb.mailbox.org/en/private/custom-domains/using-emails-with-a-custom-domain/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says files are stored exclusively in its own data centers in Germany, across two independent locations in Berlin.",
      "fetch_event_id": "84f5f76c-52da-548b-b9d9-43befc14921b",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Your files are stored exclusively in our own data centers in Germany – spread across two independent locations in Berlin.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "fd6e141f5aa0625711b68e1227d52571cdf1034ceec0899971bb2abf92df2e14",
      "source_url": "https://mailbox.org/en/product/mail/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says users can cancel a contract through the cancellation form on its website or in the Mailbox Suite under All settings > Contract and payment > Contract.",
      "fetch_event_id": "1919b367-c662-587c-a9f6-ad0669faf2ed",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You can cancel your contract directly via the cancellation form on our website . You can also access the form in the mailbox Suite via All settings > Contract and payment > Contract section.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "4329de4d1e24ae62853527ea71a51bff1482bf219764d9c169dfa17cb2bfebb1",
      "source_url": "https://kb.mailbox.org/en/private/account/how-do-i-cancel-my-mailbox-account/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says its webmail client uses PGP and S/MIME so emails are encrypted securely from end to end.",
      "fetch_event_id": "7ebee39b-182b-5483-b7f2-3df88731b8fc",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "With PGP and S/MIME in our webmail client, your emails are always encrypted securely from end to end.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "fd6e141f5aa0625711b68e1227d52571cdf1034ceec0899971bb2abf92df2e14",
      "source_url": "https://mailbox.org/en/product/mail/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says users can set up IMAP, POP 3, and SMTP in their chosen email software and integrate other email accounts.",
      "fetch_event_id": "37f4f294-f2f8-5d7d-b099-5683b9964896",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Easy setup with IMAP, POP 3 and SMTP in the email software of your choice, with integration of any of your other email accounts.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "fd6e141f5aa0625711b68e1227d52571cdf1034ceec0899971bb2abf92df2e14",
      "source_url": "https://mailbox.org/en/product/mail/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says opening an account requires a first and last name, but it does not verify that information at any point and permits any pseudonym.",
      "fetch_event_id": "2a3d41ca-9b50-5bd0-9648-e69ccc4ddebf",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "To open a mailbox account, we require you to provide a first and last name. However, since we do not verify this information at any point, you may choose any pseudonym.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "59712bc859e7069a85e57e9d561ffd45b6cf72898d3a039b7dd2bebee9d1de87",
      "source_url": "https://kb.mailbox.org/en/private/security-and-privacy/anonymous-new-registration/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says it is operated by Heinlein Hosting GmbH.",
      "fetch_event_id": "f1fcb949-4c73-5eb8-9272-b372b1eb46fd",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "mailbox.org is operated by:\nHeinlein Hosting GmbH",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "26e29ec005210c51faaf5e669f396dadcd5e2f8eb767348d25f3bfab2c303ed5",
      "source_url": "https://mailbox.org/en/legal-information/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says a total of 74 official requests for information were sent to Mailbox.org in 2025.",
      "fetch_event_id": "304d8b97-81aa-5161-a8a5-429959c0679e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "In 2025, a total of 74 official requests for information were sent to mailbox.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "e007ce90175c9e19c9ff5155b9ba2eab1bbb99018e6046bdfd7be5235fb1be07",
      "source_url": "https://mailbox.org/en/news/transparency-report-2025/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says its web server, web portal, and administration interface store access times and originating IP addresses to protect against misuse and unauthorized access, then erase them after four days.",
      "fetch_event_id": "52d79b1d-b3c2-5f75-91da-72bceb9b6248",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Type: web server / web portal / administration interface\nStored data: when and from which IP address our platform was accessed.\nPurpose: protection against misuse and unauthorised access\nErasure period: after 4 days.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "e7b00d472f065f941a24d3b535dee8f97b26fb29e5a2652fd7a7634f91a6376a",
      "source_url": "https://mailbox.org/en/data-protection/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Mailbox.org says its online account request requires a desired user name, first and last name, a natural person's country of habitual residence or a juridical person's country of domicile, and a password.",
      "fetch_event_id": "a89d1245-6bcc-5c41-a536-0406141ea125",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The contract is concluded exclusively online via the website mailbox.org. Only the desired user name, a first and last name, the country of habitual residence (for natural persons) or the country of domicile (for juridical persons) and a password selected by the User are required when requesting an account.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "8242233aa014b4f100627301f27a00da619da3cffb6cfa8c2b4d8246869a1470",
      "source_url": "https://mailbox.org/en/t-cs-cancellation-policy/",
      "table": "vendor"
    },
    "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": null,
      "fetch_event_id": "d5b3c6f4-3e7e-5aa9-ae04-a16f4d7b275b",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": null,
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "7ee515e3e0ea9a52b9a40ec718353850cf2d99253036473bc3270f16d01a50a0",
      "source_url": "https://mailbox.org/en/why-mailbox/",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says users can create at least 10 additional addresses using any Proton domain or a custom domain they own, while the primary address and disabled custom-domain addresses do not count toward that limit.",
      "fetch_event_id": "62320575-ccbe-516b-9844-d425c9d7cadd",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You can create at least 10 additional addresses, using any Proton domain\nor a custom domain you own. Your primary address doesn’t count toward\nthis limit. Disabled custom domain addresses don’t count either.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "444a5c7247b5f9b671f9a0e10b945309049ddb0d4c6103f7f3f20eb5046069ee",
      "source_url": "https://proton.me/support/addresses-and-aliases",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "The Securitum document says it summarizes work Securitum conducted to test listed web applications.",
      "fetch_event_id": "64b25204-783a-5fe4-a738-85ef04304d64",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "This document is a summary of work conducted by Securitum. The subject of the tests were the\nfollowing web applications:",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "9fa6707cfd6f919ba9f324df8ef05301dbd276df07ad2af53756c2228ba8df2a",
      "source_url": "https://res.cloudinary.com/dbulfrlrz/images/v1707571626/wp-pme/securitum-protonmail-security-audit/securitum-protonmail-security-audit.pdf?_i=AA",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail lets users create addresses on their own domain names to send and receive messages.",
      "fetch_event_id": "6a58796c-e7fb-5ce2-98b7-4d5562f3d87f",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You can create email addresses with your own domain name in Proton Mail,\nsuch as yourname@yourdomain.com , to send and receive messages.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "1ed387e54a1fe7b4bbf5ec1b81d1ebdaf8a08dda084941756c437253e12dbb45",
      "source_url": "https://proton.me/support/custom-domain",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says Proton owns and controls server hardware at several locations in Switzerland, keeps data out of the cloud, and uses data-center sites that require biometric access.",
      "fetch_event_id": "b33aba3c-56f8-5fb3-af03-0ac342bd3cec",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We have invested heavily in owning and controlling our own server\nhardware at several locations within Switzerland, so your data never\ngoes to the cloud. Our data centers are located at highly secure sites\nthat require biometric access.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "707893db8a80280e673226177b1e23e2d6aeda3e476db3a562b08c5b41b89daa",
      "source_url": "https://proton.me/mail/security",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says deleting a Proton Account permanently deletes the account and all its data from Proton systems with no recovery path.",
      "fetch_event_id": "9323e878-e760-51fb-979c-37f758c0764f",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "When you delete your Proton Account, there is no way to recover it. Your\naccount and all its data will be permanently deleted from our systems.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "2eb2182b71483e01a6effb9e019e549e9892f6439eec0dac5bb47719a40bd19e",
      "source_url": "https://proton.me/support/delete-account",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says message bodies and attachments are stored with end-to-end encryption, while subject lines and sender and recipient addresses are encrypted but not end-to-end encrypted.",
      "fetch_event_id": "4ccca158-8b31-501c-92c5-d3c9835ee90a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Body content and attachments are stored with end-to-end encryption.\nSubject lines, recipient email addresses, and sender email addresses are\nencrypted, but not end-to-end encrypted.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "7e421771b7d793fec7575fb2ae43cf5a233135dfc1ead219493f2d978e8f021c",
      "source_url": "https://proton.me/support/proton-mail-encryption-explained",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says Bridge runs in the background, encrypts and decrypts messages entering and leaving the computer, and provides a local IMAP/SMTP server for adding the account to an email client.",
      "fetch_event_id": "2d32f929-4710-5b1e-bb33-e9414d59128a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Proton Mail Bridge is a desktop application that runs in the background,\nencrypting and decrypting messages as they enter and leave your\ncomputer. It lets you add your Proton Mail account to your favorite\nemail client via IMAP/SMTP by creating a local email server on your\ncomputer.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "fabe820ff2aa1b2415296e0a7a73ae1c6fc5e4c13fff17b419532144e14d30b0",
      "source_url": "https://proton.me/mail/bridge",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says verification may be requested for some sensitive operations beyond account creation using Proton Captcha, email, or SMS to protect against brute-force attacks.",
      "fetch_event_id": "7e80ddc2-3a2d-5806-8049-c468406cb3c9",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Verification may also be requested for some\nsensitive operations besides account creation in order to protect\nagainst brute-force attacks. You may be asked to verify using either\nProton Captcha, email, or SMS.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "68ea40a13d44b83d72e62eb4fa5c1a6bd510c3c9f0a5cba5d5ea96504fa030ee",
      "source_url": "https://proton.me/legal/privacy",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.",
      "fetch_event_id": "c523a312-3e5f-5e1b-b3bf-a337b0fa21f4",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The Services are operated by Proton AG (the “Company”, “We”), domiciled\nat Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland. It\nis therefore governed by the laws and regulations of Switzerland.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "68ea40a13d44b83d72e62eb4fa5c1a6bd510c3c9f0a5cba5d5ea96504fa030ee",
      "source_url": "https://proton.me/legal/privacy",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says it rejects all requests from foreign authorities because Article 271 of the Swiss Criminal Code bars it from transmitting any data to foreign authorities directly.",
      "fetch_event_id": "6fdb0a4e-b22c-5dac-9b5c-3151f01a9a73",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Under Article 271 of the Swiss Criminal Code, Proton may not transmit\nany data to foreign authorities directly, and we therefore reject all\nrequests from foreign authorities. Swiss authorities may from time to\ntime assist foreign authorities with requests, provided that they are\nvalid under international legal assistance procedures and determined to\nbe in compliance with Swiss law. In these cases, the standard of\nlegality is again based on Swiss law. In general, Swiss authorities do\nnot assist foreign authorities from countries with a history of human\nrights abuses.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "69850e516d92678e8f948b8b68f599177bf4a081ffea7f20cee6bc6eae3194b2",
      "source_url": "https://proton.me/legal/transparency",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says IP addresses, email addresses, and phone numbers supplied for verification codes and anti-spam purposes are retained temporarily, while permanently saved data is stored as a cryptographic hash whose raw values Proton says it cannot decipher.",
      "fetch_event_id": "b85c953e-8670-597c-bd05-465f5cd72b7d",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "IP addresses, email addresses, and phone\nnumbers provided are saved temporarily in order to send you a\nverification code and for anti-spam purposes. The period of temporary\ndata retention is determined by our legitimate interests of protecting\nthe service from spam, and also by any applicable Swiss legal\nrequirements we must comply with. If this data is saved permanently, it\nis always saved as a cryptographic hash, which ensures that the raw\nvalues cannot be deciphered by us.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "68ea40a13d44b83d72e62eb4fa5c1a6bd510c3c9f0a5cba5d5ea96504fa030ee",
      "source_url": "https://proton.me/legal/privacy",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail lets a user create a Proton account with either a Proton Mail address or an external non-Proton address.",
      "fetch_event_id": "43b8c3e2-533d-59cc-b167-e48aa9adbd9e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "either create a Proton account with a Proton Mail address, or use an\nexternal (non-Proton) address.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "68ea40a13d44b83d72e62eb4fa5c1a6bd510c3c9f0a5cba5d5ea96504fa030ee",
      "source_url": "https://proton.me/legal/privacy",
      "table": "vendor"
    },
    "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Proton Mail says all Proton apps are open source and have been audited and verified by third-party experts.",
      "fetch_event_id": "54c0c3c4-bbab-573d-9d4f-1e7b8ea68b40",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "All Proton apps are open source and have been independently audited and\nverified by third-party experts. Anyone can see and verify that our apps\ndo what we claim.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "0cdff84fe9ca60988df03e874ecbc8ede01bb249748b4e643658b817f3beb66c",
      "source_url": "https://proton.me/community/open-source",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says all paid plans support an unlimited number of custom-domain email addresses that can be disabled if an address is leaked.",
      "fetch_event_id": "5cceda0e-2d66-5bd2-9217-44d0c5b5d72c",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "All paid plans of Tuta support an unlimited number of custom domain email addresses which gives you unlimited options and flexibility in using your own domain. For instance, you can create a separate email address for any service and newsletter you subscribe to so that you can easily disable the alias address again to\nstop spam\nin case the email address gets leaked.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "39a508102b33905f63edeeaaac9087ea5d847352772715102eaaecd934367395",
      "source_url": "https://tuta.com/blog/own-domain-email",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says its apps were audited by independent security experts before public release, and that SySS GmbH experts performed a penetration test of its system.",
      "fetch_event_id": "49002393-4dd1-58ef-a881-e8acfc321b42",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Before the public release of Tuta, all our apps have been audited by independent security experts. In an extensive penetration test, experts from SySS GmbH have not been able to hack into our system or retrieve any encrypted data.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a573f104ef008590afc496827fa550617a03bb72d87a126161498f34c4139040",
      "source_url": "https://tuta.com/open-source",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says all paid personal and business plans support adding a custom domain and as many email addresses as needed.",
      "fetch_event_id": "11e80030-4dfa-5dd8-bfd4-63ad83c2baeb",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Tuta Mail has a range of paid\npersonal\nor\nbusiness\nplans. All of these plans support adding your custom domain to your mailbox, including the option to add as many email addresses as needed.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "39a508102b33905f63edeeaaac9087ea5d847352772715102eaaecd934367395",
      "source_url": "https://tuta.com/blog/own-domain-email",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says all data is stored in ISO 27001-certified data centers in Germany.",
      "fetch_event_id": "e4d1fa2c-6d42-53a1-b6c9-cf98384cc0da",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "All data is stored in ISO 27001 certified data centers in Germany.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "714cade87b7d505b8babd1981d063cdb2fd6838cf5c1794bd15133ec3439fa57",
      "source_url": "https://tuta.com/privacy-policy",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says personal data is deleted no later than 30 days after contract termination, subject to stated complaint, fee, legal, claim, tax, contract, and commercial-law exceptions.",
      "fetch_event_id": "5dfe840f-148f-5934-b2b1-d1e753b4d71d",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The personal data shall be deleted no later than 30 days after termination of the contract, unless specific reasons to the contrary apply in an individual case. In case a customer objected to the amount of the charged fees, the accounting data may be stored until the objections are terminally clarified. Furthermore, inventory data can be stored for up to two years if the handling of a complaint and other reasons require this for an orderly settlement of the contract. Moreover the deletion of inventory and billing data may be omitted provided that legal regulations or the prosecution of claims require this. Order-related data and the addresses associated with the order are stored in respect to tax, contract and commercial law retention periods and erased at the end of those periods.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "714cade87b7d505b8babd1981d063cdb2fd6838cf5c1794bd15133ec3439fa57",
      "source_url": "https://tuta.com/privacy-policy",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says each user's encryption key belongs only to that user and is not shared with anyone, including Tuta.",
      "fetch_event_id": "a1dfa5ed-7d2e-5d5f-9934-8136195784a0",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Your encryption key belongs to you, and to you alone. It is never shared with anyone else, not even with Tuta.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "8338af4eceb402648dfe29a81c696537c966ed6ce7e754a9c7478b0a725e4df2",
      "source_url": "https://tuta.com/encryption",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says it does not offer IMAP because that would require sending decrypted data to the device, and instead provides open-source desktop clients that store data encrypted.",
      "fetch_event_id": "5d931859-e61f-5a81-a9bc-c3c170dff5e9",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We do not offer IMAP as it would only work if we sent\ndecrypted\ndata to your device. Instead we have built our own\nopen source desktop clients\n, which store your data encrypted.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "51761980fdd90e0752125bc0583933b8f1bbe8999bd11c83b07aefb0f783ed5b",
      "source_url": "https://tuta.com/security",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says paid-product invoicing and VAT determination collect the customer's country, an optionally provided private-user name and invoicing address, and a VAT number for business customers in some countries.",
      "fetch_event_id": "8935c0da-5f85-54b1-ae2a-ce2c4441f906",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "For invoicing and determining the VAT we collect for paid product variants\nthe domicile of the customer (country)\nthe name and invoicing address (for private users optional)\nthe VAT identification number (only for business customers of some countries)\nas inventory data.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "714cade87b7d505b8babd1981d063cdb2fd6838cf5c1794bd15133ec3439fa57",
      "source_url": "https://tuta.com/privacy-policy",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta's imprint identifies Tutao GmbH in Hanover, Germany.",
      "fetch_event_id": "ab409d55-074b-507e-b072-a03a8deb4c22",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Tutao GmbH\nDeisterstr. 17a\n30449 Hanover\nGermany",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "fc73b10cffe1c791adb7770b8572b52a0c9fff6df72cc343beb40769b120f658",
      "source_url": "https://tuta.com/imprint",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says it releases an individual mailbox only after receiving a valid German court order and cannot decrypt the encrypted data stored in Tuta mailboxes.",
      "fetch_event_id": "0820d81c-85d6-56cd-a9c4-465fa8372f33",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We only release individual mailboxes if we receive a valid German court order. The encrypted data stored in Tuta\nmailboxes can not be decrypted by us.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "623e2262b3b59cb4d81a0477b97ffd927cb34a07e42e21edab2181de961e299a",
      "source_url": "https://tuta.com/blog/transparency-report",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says personal data is deleted no later than 30 days after contract termination, while inventory data may be retained for up to two years for complaint handling or other orderly-settlement reasons and other stated exceptions may apply.",
      "fetch_event_id": "a9ec7d47-e60b-58c9-ab05-6a67320a6c94",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The personal data shall be deleted no later than 30 days after termination of the contract, unless specific reasons to the contrary apply in an individual case. In case a customer objected to the amount of the charged fees, the accounting data may be stored until the objections are terminally clarified. Furthermore, inventory data can be stored for up to two years if the handling of a complaint and other reasons require this for an orderly settlement of the contract. Moreover the deletion of inventory and billing data may be omitted provided that legal regulations or the prosecution of claims require this. Order-related data and the addresses associated with the order are stored in respect to tax, contract and commercial law retention periods and erased at the end of those periods.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "714cade87b7d505b8babd1981d063cdb2fd6838cf5c1794bd15133ec3439fa57",
      "source_url": "https://tuta.com/privacy-policy",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Tuta says it collects the newly registered email address when starting a contractual relationship and providing the service.",
      "fetch_event_id": "f000e412-eb3b-5916-bf61-376a527c93d1",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "For the initiation of a contractual relationship and for service provision we collect\nthe newly registered email address\nas inventory data.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "714cade87b7d505b8babd1981d063cdb2fd6838cf5c1794bd15133ec3439fa57",
      "source_url": "https://tuta.com/privacy-policy",
      "table": "vendor"
    },
    "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "Tuta's repository record identifies a GitHub repository at github.com/tutao/tutanota.",
      "fetch_event_id": "58758337-c27c-5cde-bed7-6c4f4c39699e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "\"html_url\": \"https://github.com/tutao/tutanota\"",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "944f6d0fc6b3ba1821a109ed2da16185cbb6e712a287a9367033cf09d0d6976e",
      "source_url": "https://api.github.com/repos/tutao/tutanota",
      "table": "vendor"
    }
  },
  "class": "MAGNET",
  "content_file_sha256": "03f4afc5e13702efc597421cfdcdd697314c9f773c70b0bc905d5f9c3e1e6311",
  "figure_slots": [],
  "generator": "page-generator/1",
  "held": {
    "cells": [],
    "counts": {
      "gap": 0,
      "no_quote": 0,
      "unconfirmed": 0,
      "unresolved": 0
    },
    "is_held": false
  },
  "last_updated": "2026-10-07",
  "route": "/privacy-tools/private-email-provider-comparison/",
  "schema": "pp-page-sources.v1",
  "tables": {
    "accountability-evidence": {
      "field_definitions": {
        "audit_report": "Assessment date, assessor, scope, access, and report locator stated by the current cell.",
        "request_reporting": "Published period, jurisdiction, unit, scope, count, and absence reason stated by the current cell.",
        "source_availability": "Repository URL, license, component, version, and release locator stated by the cell, preserving verified absences."
      },
      "last_updated": "2026-10-07",
      "matrix_id": "vendor-inbox:accountability-evidence",
      "rows": [
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://support.apple.com/guide/certifications/apple-internet-services-security-apc34d2c0468b/1/web/1.0",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "Apple says it undergoes annual independent attestation by an accredited registrar."
            },
            "request_reporting": {
              "cell_citation_url": "https://www.apple.com/legal/zip/transparency/Apple_Transparency_Report.zip",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "Apple's transparency report lists, for July 1 through December 31, 2025 in the United States of America, 16,809 Apple Account requests received, 52,948 accounts specified in requests, 3,043 requests challenged in part or rejected in full, 7,431 requests where only non-content data was provided, 7,845 requests where content was provided, and data provided for 91% of requests; these figures cover Apple Account requests, not iCloud Mail alone."
            },
            "source_availability": {
              "cell_citation_url": "https://opensource.apple.com/",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.source_availability",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "source_availability",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
          "operating_entity_citation_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
          "operating_entity_subline": "Apple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.",
          "row_anchor": "accountability-evidence-icloud-mail",
          "row_id": "icloud-mail",
          "state": "iCloud Mail"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://www.fastmail.com/features/security/",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "Fastmail says its Bug Bounty Program encourages third-party security review and that it performs regular internal audits."
            },
            "request_reporting": {
              "cell_citation_url": "https://www.fastmail.com/policies/transparency-report/",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "Fastmail says all requests are checked for legal validity before being actioned."
            },
            "source_availability": {
              "cell_citation_url": "https://www.fastmail.com/company/open-source/",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "Fastmail says Cyrus stores email, contacts, and calendars and supports JMAP, IMAP, CardDAV, and CalDAV."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.fastmail.com/policies/privacy/",
          "operating_entity_citation_url": "https://www.fastmail.com/policies/privacy/",
          "operating_entity_subline": "Fastmail says it is an Australian company named Fastmail Pty Ltd.",
          "row_anchor": "accountability-evidence-fastmail",
          "row_id": "fastmail",
          "state": "Fastmail"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://mailbox.org/en/news/bsi-c5-certification-mailbox-full-compliance-bsi-criteria-cloud-security-confirmed/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "Mailbox.org says Heinlein Hosting GmbH, the legal operator of Mailbox.org, has been awarded C5 Type 1 certification by the German Federal Office for Information Security."
            },
            "request_reporting": {
              "cell_citation_url": "https://mailbox.org/en/news/transparency-report-2025/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "Mailbox.org says a total of 74 official requests for information were sent to Mailbox.org in 2025."
            },
            "source_availability": {
              "cell_citation_url": "https://mailbox.org/en/why-mailbox/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.source_availability",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "source_availability",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://mailbox.org/en/legal-information/",
          "operating_entity_citation_url": "https://mailbox.org/en/legal-information/",
          "operating_entity_subline": "Mailbox.org says it is operated by Heinlein Hosting GmbH.",
          "row_anchor": "accountability-evidence-mailbox-org",
          "row_id": "mailbox-org",
          "state": "mailbox.org"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://res.cloudinary.com/dbulfrlrz/images/v1707571626/wp-pme/securitum-protonmail-security-audit/securitum-protonmail-security-audit.pdf?_i=AA",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "The Securitum document says it summarizes work Securitum conducted to test listed web applications."
            },
            "request_reporting": {
              "cell_citation_url": "https://proton.me/legal/transparency",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "Proton Mail says it rejects all requests from foreign authorities because Article 271 of the Swiss Criminal Code bars it from transmitting any data to foreign authorities directly."
            },
            "source_availability": {
              "cell_citation_url": "https://proton.me/community/open-source",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "Proton Mail says all Proton apps are open source and have been audited and verified by third-party experts."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.",
          "row_anchor": "accountability-evidence-proton-mail",
          "row_id": "proton-mail",
          "state": "Proton Mail"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://tuta.com/open-source",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "Tuta says its apps were audited by independent security experts before public release, and that SySS GmbH experts performed a penetration test of its system."
            },
            "request_reporting": {
              "cell_citation_url": "https://tuta.com/blog/transparency-report",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "Tuta says it releases an individual mailbox only after receiving a valid German court order and cannot decrypt the encrypted data stored in Tuta mailboxes."
            },
            "source_availability": {
              "cell_citation_url": "https://api.github.com/repos/tutao/tutanota",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "Tuta's repository record identifies a GitHub repository at github.com/tutao/tutanota."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://tuta.com/imprint",
          "operating_entity_citation_url": "https://tuta.com/imprint",
          "operating_entity_subline": "Tuta's imprint identifies Tutao GmbH in Hanover, Germany.",
          "row_anchor": "accountability-evidence-tuta",
          "row_id": "tuta",
          "state": "Tuta Mail"
        }
      ],
      "scope_label": "5 products"
    },
    "encryption-addressing-and-access": {
      "field_definitions": {
        "alias_limits": "Alias type, creation and active limits, send and reply support, deletion or reuse rule, custom-domain eligibility, and plan stated by the cell.",
        "custom_domain_support": "Send and receive support, domain and address limits, DNS requirements, plan, and region stated by the cell.",
        "end_to_end_encryption_scope": "Message body, subject line, calendar, contacts, attachments, external-recipient boundary, key control, platform, and plan stated by the cell.",
        "imap_or_bridge": "Direct IMAP and SMTP, bridge availability and name, supported clients and platforms, local processing, plan, and limitations stated by the cell."
      },
      "last_updated": "2026-10-07",
      "matrix_id": "vendor-inbox:encryption-addressing-and-access",
      "rows": [
        {
          "cells": {
            "alias_limits": {
              "cell_citation_url": "https://support.apple.com/guide/icloud/add-and-manage-email-aliases-mm6b1a490a/icloud",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits",
              "publish_status": "publish_ready",
              "source_field": "alias_limits",
              "value": "iCloud Mail lets users create up to three @icloud.com aliases after setting up a primary address, and use those aliases to send and receive mail on iCloud.com or devices with Mail enabled in iCloud settings."
            },
            "custom_domain_support": {
              "cell_citation_url": "https://support.apple.com/en-us/102540",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support",
              "publish_status": "publish_ready",
              "source_field": "custom_domain_support",
              "value": "iCloud+ Mail lets subscribers use an existing custom domain to send and receive email from a personalized address."
            },
            "end_to_end_encryption_scope": {
              "cell_citation_url": "https://support.apple.com/en-us/102651",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope",
              "publish_status": "publish_ready",
              "source_field": "end_to_end_encryption_scope",
              "value": "Apple says iCloud Mail does not use end-to-end encryption because it must interoperate with the global email system, while native Apple email clients support optional S/MIME message encryption."
            },
            "imap_or_bridge": {
              "cell_citation_url": "https://support.apple.com/en-us/102525",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge",
              "publish_status": "publish_ready",
              "source_field": "imap_or_bridge",
              "value": "Apple says iCloud Mail uses IMAP and SMTP, which most modern email client apps support, and does not support POP."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
          "operating_entity_citation_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
          "operating_entity_subline": "Apple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.",
          "row_anchor": "encryption-addressing-and-access-icloud-mail",
          "row_id": "icloud-mail",
          "state": "iCloud Mail"
        },
        {
          "cells": {
            "alias_limits": {
              "cell_citation_url": "https://www.fastmail.help/hc/en-us/articles/360060591073-How-to-set-up-aliases",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits",
              "publish_status": "publish_ready",
              "source_field": "alias_limits",
              "value": "Fastmail says accounts can have up to 600 aliases, plus 15 for every user in the account."
            },
            "custom_domain_support": {
              "cell_citation_url": "https://www.fastmail.help/hc/en-us/articles/360058753394-Custom-domains-with-Fastmail",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support",
              "publish_status": "publish_ready",
              "source_field": "custom_domain_support",
              "value": "Fastmail says using a custom domain requires at least one account administrator on a non-Basic subscription plan."
            },
            "end_to_end_encryption_scope": {
              "cell_citation_url": "https://www.fastmail.com/features/security/",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope",
              "publish_status": "publish_ready",
              "source_field": "end_to_end_encryption_scope",
              "value": "Fastmail says customers can use PGP or S/MIME in third-party apps, while its own apps do not offer end-to-end encryption."
            },
            "imap_or_bridge": {
              "cell_citation_url": "https://www.fastmail.help/hc/en-us/articles/1500000279921-IMAP-POP-and-SMTP",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge",
              "publish_status": "publish_ready",
              "source_field": "imap_or_bridge",
              "value": "Fastmail says IMAP, POP, and SMTP allow an account to connect to a third-party email client."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.fastmail.com/policies/privacy/",
          "operating_entity_citation_url": "https://www.fastmail.com/policies/privacy/",
          "operating_entity_subline": "Fastmail says it is an Australian company named Fastmail Pty Ltd.",
          "row_anchor": "encryption-addressing-and-access-fastmail",
          "row_id": "fastmail",
          "state": "Fastmail"
        },
        {
          "cells": {
            "alias_limits": {
              "cell_citation_url": "https://kb.mailbox.org/en/private/e-mail/what-is-an-alias-and-how-do-i-use-it/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits",
              "publish_status": "publish_ready",
              "source_field": "alias_limits",
              "value": "Mailbox.org says email aliases are server-side forwarding addresses that direct multiple email addresses to one primary inbox."
            },
            "custom_domain_support": {
              "cell_citation_url": "https://kb.mailbox.org/en/private/custom-domains/using-emails-with-a-custom-domain/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support",
              "publish_status": "publish_ready",
              "source_field": "custom_domain_support",
              "value": "Mailbox.org says users can send and receive emails from a custom domain."
            },
            "end_to_end_encryption_scope": {
              "cell_citation_url": "https://mailbox.org/en/product/mail/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope",
              "publish_status": "publish_ready",
              "source_field": "end_to_end_encryption_scope",
              "value": "Mailbox.org says its webmail client uses PGP and S/MIME so emails are encrypted securely from end to end."
            },
            "imap_or_bridge": {
              "cell_citation_url": "https://mailbox.org/en/product/mail/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge",
              "publish_status": "publish_ready",
              "source_field": "imap_or_bridge",
              "value": "Mailbox.org says users can set up IMAP, POP 3, and SMTP in their chosen email software and integrate other email accounts."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://mailbox.org/en/legal-information/",
          "operating_entity_citation_url": "https://mailbox.org/en/legal-information/",
          "operating_entity_subline": "Mailbox.org says it is operated by Heinlein Hosting GmbH.",
          "row_anchor": "encryption-addressing-and-access-mailbox-org",
          "row_id": "mailbox-org",
          "state": "mailbox.org"
        },
        {
          "cells": {
            "alias_limits": {
              "cell_citation_url": "https://proton.me/support/addresses-and-aliases",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits",
              "publish_status": "publish_ready",
              "source_field": "alias_limits",
              "value": "Proton Mail says users can create at least 10 additional addresses using any Proton domain or a custom domain they own, while the primary address and disabled custom-domain addresses do not count toward that limit."
            },
            "custom_domain_support": {
              "cell_citation_url": "https://proton.me/support/custom-domain",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support",
              "publish_status": "publish_ready",
              "source_field": "custom_domain_support",
              "value": "Proton Mail lets users create addresses on their own domain names to send and receive messages."
            },
            "end_to_end_encryption_scope": {
              "cell_citation_url": "https://proton.me/support/proton-mail-encryption-explained",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope",
              "publish_status": "publish_ready",
              "source_field": "end_to_end_encryption_scope",
              "value": "Proton Mail says message bodies and attachments are stored with end-to-end encryption, while subject lines and sender and recipient addresses are encrypted but not end-to-end encrypted."
            },
            "imap_or_bridge": {
              "cell_citation_url": "https://proton.me/mail/bridge",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge",
              "publish_status": "publish_ready",
              "source_field": "imap_or_bridge",
              "value": "Proton Mail says Bridge runs in the background, encrypts and decrypts messages entering and leaving the computer, and provides a local IMAP/SMTP server for adding the account to an email client."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.",
          "row_anchor": "encryption-addressing-and-access-proton-mail",
          "row_id": "proton-mail",
          "state": "Proton Mail"
        },
        {
          "cells": {
            "alias_limits": {
              "cell_citation_url": "https://tuta.com/blog/own-domain-email",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.alias_limits",
              "publish_status": "publish_ready",
              "source_field": "alias_limits",
              "value": "Tuta says all paid plans support an unlimited number of custom-domain email addresses that can be disabled if an address is leaked."
            },
            "custom_domain_support": {
              "cell_citation_url": "https://tuta.com/blog/own-domain-email",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.custom_domain_support",
              "publish_status": "publish_ready",
              "source_field": "custom_domain_support",
              "value": "Tuta says all paid personal and business plans support adding a custom domain and as many email addresses as needed."
            },
            "end_to_end_encryption_scope": {
              "cell_citation_url": "https://tuta.com/encryption",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.end_to_end_encryption_scope",
              "publish_status": "publish_ready",
              "source_field": "end_to_end_encryption_scope",
              "value": "Tuta says each user's encryption key belongs only to that user and is not shared with anyone, including Tuta."
            },
            "imap_or_bridge": {
              "cell_citation_url": "https://tuta.com/security",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.imap_or_bridge",
              "publish_status": "publish_ready",
              "source_field": "imap_or_bridge",
              "value": "Tuta says it does not offer IMAP because that would require sending decrypted data to the device, and instead provides open-source desktop clients that store data encrypted."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://tuta.com/imprint",
          "operating_entity_citation_url": "https://tuta.com/imprint",
          "operating_entity_subline": "Tuta's imprint identifies Tutao GmbH in Hanover, Germany.",
          "row_anchor": "encryption-addressing-and-access-tuta",
          "row_id": "tuta",
          "state": "Tuta Mail"
        }
      ],
      "scope_label": "5 products"
    },
    "identity-entity-and-region": {
      "field_definitions": {
        "data_region_options": "Choice availability, named regions, selection time, migration support, covered data categories, plan, and scope stated by the cell.",
        "later_verification_triggers": "Trigger, requested identifier, collecting actor, retained-by field, plan, and region stated by the cell.",
        "operating_entity": "Legal name, incorporation jurisdiction, governing law, hosting jurisdiction, and vendor document locator stated by the cell.",
        "signup_identifiers": "Identifier type, requiredness, collecting actor, plan, region, and platform stated for signup."
      },
      "last_updated": "2026-10-07",
      "matrix_id": "vendor-inbox:identity-entity-and-region",
      "rows": [
        {
          "cells": {
            "data_region_options": {
              "cell_citation_url": "https://www.apple.com/legal/privacy/en-ww/",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options",
              "publish_status": "publish_ready",
              "source_field": "data_region_options",
              "value": "Apple says personal data collected worldwide by Apple or an affiliated company is generally stored by Apple Inc. in the United States."
            },
            "later_verification_triggers": {
              "cell_citation_url": "https://support.apple.com/en-us/102559",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers",
              "publish_status": "publish_ready",
              "source_field": "later_verification_triggers",
              "value": "Apple says it verifies that the requester is the account holder after an Apple Account deletion request."
            },
            "operating_entity": {
              "cell_citation_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "Apple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://support.apple.com/en-us/108647",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "Apple's account-creation steps have users provide an email address, create a strong password, and set a device region; the primary email address is used to sign in to the Apple Account."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
          "operating_entity_citation_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
          "operating_entity_subline": "Apple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.",
          "row_anchor": "identity-entity-and-region-icloud-mail",
          "row_id": "icloud-mail",
          "state": "iCloud Mail"
        },
        {
          "cells": {
            "data_region_options": {
              "cell_citation_url": "https://www.fastmail.help/hc/en-us/articles/16796454162063-Choosing-your-data-residency",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options",
              "publish_status": "publish_ready",
              "source_field": "data_region_options",
              "value": "Fastmail says all customers, including trial users, can choose servers in the European Union or United States regardless of location."
            },
            "later_verification_triggers": {
              "cell_citation_url": "https://www.fastmail.help/hc/en-us/articles/1500009438961-I-can-t-sign-up",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers",
              "publish_status": "publish_ready",
              "source_field": "later_verification_triggers",
              "value": "Fastmail says mobile-phone verification can occur at signup or during a trial."
            },
            "operating_entity": {
              "cell_citation_url": "https://www.fastmail.com/policies/privacy/",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "Fastmail says it is an Australian company named Fastmail Pty Ltd."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://www.fastmail.com/policies/privacy/",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "Fastmail says it collects name, primary Fastmail username, billing and contact details, organization and domain names, IP address, browser type, communications records, and tokenized payment information."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.fastmail.com/policies/privacy/",
          "operating_entity_citation_url": "https://www.fastmail.com/policies/privacy/",
          "operating_entity_subline": "Fastmail says it is an Australian company named Fastmail Pty Ltd.",
          "row_anchor": "identity-entity-and-region-fastmail",
          "row_id": "fastmail",
          "state": "Fastmail"
        },
        {
          "cells": {
            "data_region_options": {
              "cell_citation_url": "https://mailbox.org/en/product/mail/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options",
              "publish_status": "publish_ready",
              "source_field": "data_region_options",
              "value": "Mailbox.org says files are stored exclusively in its own data centers in Germany, across two independent locations in Berlin."
            },
            "later_verification_triggers": {
              "cell_citation_url": "https://kb.mailbox.org/en/private/security-and-privacy/anonymous-new-registration/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers",
              "publish_status": "publish_ready",
              "source_field": "later_verification_triggers",
              "value": "Mailbox.org says opening an account requires a first and last name, but it does not verify that information at any point and permits any pseudonym."
            },
            "operating_entity": {
              "cell_citation_url": "https://mailbox.org/en/legal-information/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "Mailbox.org says it is operated by Heinlein Hosting GmbH."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://mailbox.org/en/t-cs-cancellation-policy/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "Mailbox.org says its online account request requires a desired user name, first and last name, a natural person's country of habitual residence or a juridical person's country of domicile, and a password."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://mailbox.org/en/legal-information/",
          "operating_entity_citation_url": "https://mailbox.org/en/legal-information/",
          "operating_entity_subline": "Mailbox.org says it is operated by Heinlein Hosting GmbH.",
          "row_anchor": "identity-entity-and-region-mailbox-org",
          "row_id": "mailbox-org",
          "state": "mailbox.org"
        },
        {
          "cells": {
            "data_region_options": {
              "cell_citation_url": "https://proton.me/mail/security",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options",
              "publish_status": "publish_ready",
              "source_field": "data_region_options",
              "value": "Proton Mail says Proton owns and controls server hardware at several locations in Switzerland, keeps data out of the cloud, and uses data-center sites that require biometric access."
            },
            "later_verification_triggers": {
              "cell_citation_url": "https://proton.me/legal/privacy",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers",
              "publish_status": "publish_ready",
              "source_field": "later_verification_triggers",
              "value": "Proton Mail says verification may be requested for some sensitive operations beyond account creation using Proton Captcha, email, or SMS to protect against brute-force attacks."
            },
            "operating_entity": {
              "cell_citation_url": "https://proton.me/legal/privacy",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "Proton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://proton.me/legal/privacy",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "Proton Mail lets a user create a Proton account with either a Proton Mail address or an external non-Proton address."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.",
          "row_anchor": "identity-entity-and-region-proton-mail",
          "row_id": "proton-mail",
          "state": "Proton Mail"
        },
        {
          "cells": {
            "data_region_options": {
              "cell_citation_url": "https://tuta.com/privacy-policy",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.data_region_options",
              "publish_status": "publish_ready",
              "source_field": "data_region_options",
              "value": "Tuta says all data is stored in ISO 27001-certified data centers in Germany."
            },
            "later_verification_triggers": {
              "cell_citation_url": "https://tuta.com/privacy-policy",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers",
              "publish_status": "publish_ready",
              "source_field": "later_verification_triggers",
              "value": "Tuta says paid-product invoicing and VAT determination collect the customer's country, an optionally provided private-user name and invoicing address, and a VAT number for business customers in some countries."
            },
            "operating_entity": {
              "cell_citation_url": "https://tuta.com/imprint",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "Tuta's imprint identifies Tutao GmbH in Hanover, Germany."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://tuta.com/privacy-policy",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "Tuta says it collects the newly registered email address when starting a contractual relationship and providing the service."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://tuta.com/imprint",
          "operating_entity_citation_url": "https://tuta.com/imprint",
          "operating_entity_subline": "Tuta's imprint identifies Tutao GmbH in Hanover, Germany.",
          "row_anchor": "identity-entity-and-region-tuta",
          "row_id": "tuta",
          "state": "Tuta Mail"
        }
      ],
      "scope_label": "5 products"
    },
    "retention-and-deletion": {
      "field_definitions": {
        "deletion": "Initiation path, completed-erasure statement, exceptions, timeframe, and controller stated by the current cell.",
        "retention": "Data category, trigger, duration, exceptions, and controller stated by the current cell."
      },
      "last_updated": "2026-10-07",
      "matrix_id": "vendor-inbox:retention-and-deletion",
      "rows": [
        {
          "cells": {
            "deletion": {
              "cell_citation_url": "https://support.apple.com/en-us/102559",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "Apple says that, after verification is complete, account details and data associated with the Apple Account are permanently deleted from its servers."
            },
            "retention": {
              "cell_citation_url": "https://support.apple.com/en-us/102559",
              "cell_locator": "icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "Apple says it is required to retain past transaction information for financial reporting purposes, may be required to retain certain information to comply with a court settlement or other ongoing legal procedure, and also retains a one-way hash of the deleted account's email address."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#icloud-mail.icloud-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
          "operating_entity_citation_url": "https://www.apple.com/legal/internet-services/icloud/us-en/terms.html",
          "operating_entity_subline": "Apple lists Apple Inc. for iCloud Mail users in the United States, including Puerto Rico.",
          "row_anchor": "retention-and-deletion-icloud-mail",
          "row_id": "icloud-mail",
          "state": "iCloud Mail"
        },
        {
          "cells": {
            "deletion": {
              "cell_citation_url": "https://www.fastmail.help/hc/en-us/articles/1500000277342-Canceling-and-deleting-accounts",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "Fastmail says users can cancel an account and then choose Learn more and delete all data to close the account immediately and permanently delete all data."
            },
            "retention": {
              "cell_citation_url": "https://www.fastmail.com/policies/privacy/",
              "cell_locator": "fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "Fastmail says IP logs are retained for up to one year to monitor for fraud, an email address is retained for up to twelve months after account closure to prevent impersonation, and account data is deleted within seven days after closure with a short archive period for recovery, and that it may store data longer if required for legal, regulatory, or dispute resolution purposes."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#fastmail.fastmail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.fastmail.com/policies/privacy/",
          "operating_entity_citation_url": "https://www.fastmail.com/policies/privacy/",
          "operating_entity_subline": "Fastmail says it is an Australian company named Fastmail Pty Ltd.",
          "row_anchor": "retention-and-deletion-fastmail",
          "row_id": "fastmail",
          "state": "Fastmail"
        },
        {
          "cells": {
            "deletion": {
              "cell_citation_url": "https://kb.mailbox.org/en/private/account/how-do-i-cancel-my-mailbox-account/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "Mailbox.org says users can cancel a contract through the cancellation form on its website or in the Mailbox Suite under All settings > Contract and payment > Contract."
            },
            "retention": {
              "cell_citation_url": "https://mailbox.org/en/data-protection/",
              "cell_locator": "mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "Mailbox.org says its web server, web portal, and administration interface store access times and originating IP addresses to protect against misuse and unauthorized access, then erase them after four days."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#mailbox-org.mailbox-org.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://mailbox.org/en/legal-information/",
          "operating_entity_citation_url": "https://mailbox.org/en/legal-information/",
          "operating_entity_subline": "Mailbox.org says it is operated by Heinlein Hosting GmbH.",
          "row_anchor": "retention-and-deletion-mailbox-org",
          "row_id": "mailbox-org",
          "state": "mailbox.org"
        },
        {
          "cells": {
            "deletion": {
              "cell_citation_url": "https://proton.me/support/delete-account",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "Proton Mail says deleting a Proton Account permanently deletes the account and all its data from Proton systems with no recovery path."
            },
            "retention": {
              "cell_citation_url": "https://proton.me/legal/privacy",
              "cell_locator": "proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "Proton Mail says IP addresses, email addresses, and phone numbers supplied for verification codes and anti-spam purposes are retained temporarily, while permanently saved data is stored as a cryptographic hash whose raw values Proton says it cannot decipher."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#proton-mail.proton-mail.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton Mail says Proton AG operates the services and is domiciled in Geneva, Switzerland, and that the services are governed by Swiss laws and regulations.",
          "row_anchor": "retention-and-deletion-proton-mail",
          "row_id": "proton-mail",
          "state": "Proton Mail"
        },
        {
          "cells": {
            "deletion": {
              "cell_citation_url": "https://tuta.com/privacy-policy",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "Tuta says personal data is deleted no later than 30 days after contract termination, subject to stated complaint, fee, legal, claim, tax, contract, and commercial-law exceptions."
            },
            "retention": {
              "cell_citation_url": "https://tuta.com/privacy-policy",
              "cell_locator": "tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "Tuta says personal data is deleted no later than 30 days after contract termination, while inventory data may be retained for up to two years for complaint handling or other orderly-settlement reasons and other stated exceptions may apply."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#tuta.tuta.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://tuta.com/imprint",
          "operating_entity_citation_url": "https://tuta.com/imprint",
          "operating_entity_subline": "Tuta's imprint identifies Tutao GmbH in Hanover, Germany.",
          "row_anchor": "retention-and-deletion-tuta",
          "row_id": "tuta",
          "state": "Tuta Mail"
        }
      ],
      "scope_label": "5 products"
    }
  },
  "template": "matrix",
  "tier": "T1",
  "warnings": [
    "sideways label \"Email Alias Service Comparison\" differs from the known title \"Email-Alias Service Comparison: Identity, Retention, Replying, and Limits\" of /privacy-tools/email-alias-service-comparison/"
  ]
}
