PrivacyPick
In This Article
Email

Why Not Just Use Gmail?

Gmail, Yahoo, and Outlook.com can technically read your mail's content. What that means, and which of our reviewed providers actually close the gap.

Published September 26, 2026By Juan Martinez

Why Not Just Use Gmail?

Most people never chose Gmail. They ended up there — a school account, a phone setup screen, a friend’s invite in 2006 — and the question of what the provider can technically do with the messages sitting in that mailbox never came up. It’s a fair question to ask late. The answer isn’t a conspiracy, and it isn’t nothing: the largest free email providers retain the technical ability to have automated systems process the content of your messages, and what they do with that ability is a matter of settings, defaults, and policy that have changed before.

What the big three actually reserve the right to do

Google is explicit that Gmail content is not used for advertising. Its own support documentation says plainly that it will not scan or read Gmail messages to show ads.[1] That’s a real commitment and it’s been in place for years.

What sits alongside it is a separate setting called “smart features and personalization,” which does use Gmail, Chat, and Meet content — for sorting mail into Primary, Social, and Promotions, for Smart Compose’s suggested text, for the travel and package summary cards, and for Gemini features like summarizing and drafting.[2] Google’s own page lists where it’s off by default: the European Economic Area, Japan, Switzerland, and the United Kingdom.[2] Everywhere else, including the United States, it’s on unless you turn it off.

How contested that arrangement is showed up in court. A lawsuit filed in the Northern District of California in November 2025 alleged that Google silently enabled Gemini access to Gmail, Chat, and Meet content around October 10 of that year for roughly 130 million US Gmail users without clear consent, claiming violations of California’s Invasion of Privacy Act.[3] In July 2026 the judge dismissed that version of the complaint — but on standing, not on the merits. The reasoning was that alleging what an AI tool could do isn’t enough; plaintiffs had to plausibly allege what it actually did, and they hadn’t identified specific data accessed or concrete ongoing harm.[4] Nothing was decided about whether Google did what was alleged. Plaintiffs refiled a second amended complaint two months later, and the case is still active as of this writing.[4] The useful takeaway isn’t “Google was caught” — it’s that the dispute is live, unresolved, and turns entirely on a capability nobody disputes exists.

Yahoo is more direct about it. Its privacy policy states that analysis of email content to build advertising interest profiles relies on mail from retailers and other organizations, not personal messages between individuals.[5] Its Communications Products FAQ is broader: Yahoo’s automated systems may analyze all content, including Mail and Messenger messages and uploaded photos, for purposes spanning targeted advertising keywords, product features, fraud detection, and analytics.[6] There’s an opt-out in the ad-preference controls that stops the advertising use.[6]

Microsoft draws the tightest line of the three on what leaves its systems. Its support page on ads in Outlook says the content of your emails is never shared with ad networks, and that Outlook passes no name, email address, or other identifying data to them — only a cookie or device identifier.[7] For users who opt in, Microsoft may use received mail to identify brands and businesses you shop with, while stating it does not analyze the content of emails from friends, family, or other individuals for ad personalization.[7]

Read together, the pattern is consistent. Every provider, including the encrypted ones, runs automated spam and malware checks — that part is uncontroversial. What differs is everything past that: feature processing, AI summarization, commercial-mail profiling, each with its own defaults and carve-outs. The common denominator is architectural. Your mail sits on their servers in a form they can read. Whether they read it is a policy question, and policy questions get revisited.

What actually removes the question

A different architecture makes the policy question moot. If the provider holds no key to your stored mail, there’s no plaintext on their side to process, and it stops mattering what the terms say this year. Of the eight providers we’ve reviewed in our encrypted email section, three are built that way.

Proton Mail logo
8.5
out of 10

This link earns us nothing — no tracking, just the review.

Proton Mail encrypts messages with your key the moment they arrive, including mail from outside senders who never encrypted anything — Proton’s own security documentation states that messages are encrypted at all times and that Proton can never access them.[8] Proton-to-Proton mail is end-to-end encrypted automatically. PGP is available by manual import for corresponding with PGP users elsewhere. Full details in our Proton Mail review.

Tuta logo
7.9
out of 10

This link earns us nothing — no tracking, just the review.

Tuta encrypts the whole mailbox — mail, calendar, contacts, and the search index. Its documentation describes servers storing only encrypted data, with the decryption key available solely to the user.[9] Tuta deliberately doesn’t support PGP at all, citing PGP’s inability to encrypt the subject line, the difficulty of moving it to post-quantum cryptography, and its lack of forward secrecy; it uses its own protocol instead.[10] See the Tuta review.

Posteo logo
6.1
out of 10

This link earns us nothing — no tracking, just the review.

Posteo offers encryption of all stored data at the touch of a button, and has been independently audited by Cure53 — the web application in 2017, and encrypted storage specifically in 2015.[11] Our Posteo review covers the tradeoffs.

The other five protect you in real but partial ways, and the differences between them are technical rather than a matter of degree.

Two offer OpenPGP that works as advertised but doesn’t cover everything. Mailfence performs encryption client-side in the browser, so PGP-encrypted bodies aren’t server-visible — but most mail isn’t sent with PGP enabled, since it requires the sender to turn it on and generally the recipient to support it, and that mail sits on the server unprotected. Mailbox.org documents that malware and spam scanning happens before any optional PGP encryption is applied, which leaves a window where content is readable server-side even for users who opted in.

One is a case where the marketing and the architecture don’t line up.

StartMail logo
6.4
out of 10

This link earns us nothing — no tracking, just the review.

StartMail lists native PGP support, but its own technical white paper describes encryption and decryption happening server-side rather than in the browser — meaning plaintext or working keys pass through StartMail’s infrastructure during the operation. PGP support is a true statement about the feature list and a misleading one about who can see what. Full write-up in our StartMail review.

Two run on stated policy rather than architecture. Fastmail supports PGP only via manual import, and its anti-spam documentation describes content-based scoring of accepted mail on the server — spam filtering, not advertising, but plaintext processing all the same. Disroot is a donation-funded non-profit with no ads and no profiling in its policy, and no zero-access encryption behind that promise; it asks for the same kind of trust Gmail does, from a very different organization.

Where encrypted email stops

Zero-access encryption solves one problem precisely and leaves others untouched.

Metadata is the big one. Who you email, when, and how often stays visible to your provider regardless of how the message body is protected, because delivery requires it. Subject lines usually go in the clear too — standard PGP doesn’t cover them, which is one of Tuta’s stated reasons for skipping PGP in favor of a protocol that does encrypt the subject.[10]

The other end of the conversation is outside your control entirely. Encrypting mail at rest in your own mailbox says nothing about the copy sitting in your recipient’s Gmail account. If you email someone on a mainstream provider, that provider has the message in a readable form on their side, and no setting on yours changes it. The protection is real for what lands in your inbox and for anything sent between users of the same encrypted provider; beyond that, it depends on the other party.

And none of it survives a compromised device or a reused account password. Server-side architecture protects mail on the server.

Summary

The reason to move off Gmail isn’t that Google reads your mail for ads — it says it doesn’t, and there’s no evidence it does. It’s that Gmail, Yahoo Mail, and Outlook.com all keep your messages in a form their systems can process, and each has documented uses for that capability beyond spam filtering: feature personalization and AI summarization at Google, advertising-interest profiling from commercial mail at Yahoo and Microsoft. Defaults differ by country, opt-outs exist, and the terms have moved before. A provider that holds no key to your mailbox takes that whole category of question off the table. Three of the eight providers we’ve reviewed are built that way; the rest are worth understanding on their specific terms rather than on the word “encrypted.”