← All categories
Email
Your most private conversations. Gmail reads them for AI training. Outlook sends your passwords to Microsoft. The alternatives aren't perfect either.
4 devices analyzed. Set your privacy comfort level to filter.
What we found
Microsoft Outlook: DRussian military hackers used an Outlook vulnerability to steal credentials — just receiving an email was enough, you didn't even have to open it.
CVE-2023-23397 (CVSS 9.8): Russian military intelligence (APT28) exploited Outlook to steal NTLM credentials via a specially crafted email — no user interaction required, just receiving the email was enough. CVE-2025-21298 (CVSS 9.8): zero-click RCE via the preview pane. Opening Outlook and looking at your inbox was enough to be compromised.
Gmail: DGoogle said they stopped reading your email in 2017.
Gmail still scans every email for Smart Reply, Smart Compose, nudges, travel cards, package tracking, event extraction, and payment detection. In late 2025, Google enabled Gemini AI to read emails by default — requiring opt-out across two separate settings pages. Google stopped scanning for ads but never stopped scanning. The machine reading your email just got smarter.
Proton Mail: DProton says they can't read your email.
Incoming email from non-Proton senders arrives in plaintext. Proton processes this plaintext email for spam scanning BEFORE encrypting it at rest. During this processing window, Proton can and does read email content. 'Zero-access encryption' only applies after processing is complete — not during the spam scan that happens to every external email you receive.
How audits work in this category
Common standard: SOC 2 Type II / ISO 27001
What it covers: Verifies security controls around infrastructure and access management.
What it misses: Does not verify whether the provider can read your email. Gmail holds SOC 2 and still scans every message for ad targeting. Encryption at rest means nothing if the provider holds the key.
Product Auditor Standard Trust signals
Gmail DEY, EYSOC 2 Type II, ISO 27001Big Four
Gold standard for this category:
  • End-to-end encryption
  • Zero-access architecture
  • Open-source clients
  • Jurisdiction (Swiss/EU)
Encrypts subject lines, open source, German jurisdiction, fights 75% of government requests.
For the auditors' own track record, see Who Audits the Auditors?

Your privacy tolerance