Privacy & AI

Your email isn't as private as you think

1 Sep 20267 min read
In short
  • Standard email is encrypted in transit, but your provider can still read the contents.
  • "Encrypted" on the login page is not the same as end-to-end encrypted.
  • Inbox AI features now read message content to work, widening the privacy gap.
  • End-to-end encryption is the only model where only you and your recipient can read a message.

Most people treat email like a sealed letter. In reality it is closer to a postcard that a few trusted companies agree not to read out loud. The inbox you already use — Gmail, Outlook, or an IMAP account — is protected in transit, but that is not the same as being private.

What "encrypted" usually means

When you sign in to Gmail or Outlook, the connection is encrypted with TLS. That protects your password and stops someone on the same Wi-Fi from reading the traffic. It is real and important, but it only covers the message while it moves between servers.

Once an email lands in a mailbox, it is typically stored in a form the provider can read. That is what lets them search your mail, filter spam, show ads in some products, and now run AI features over the content.

Who can actually read your email

With standard email, the list is longer than most people expect: your email provider, your recipient's provider, anyone who gains access to either account, and in some cases third-party apps you have connected. None of that requires "hacking" — it is how the system is designed to work.

Why inbox AI widens the gap

AI assistants that summarise threads, draft replies, or surface "important" mail need to read the content to do their job. That can be genuinely useful. But it means your plaintext email is now processed by more systems than before, and the privacy trade-off is rarely made explicit to the user.

The one model that closes it

End-to-end encryption (E2EE) is different. The message is encrypted on your device before it leaves, and only your recipient can decrypt it. The provider stores ciphertext it cannot read. That is the difference between "the company promises not to look" and "the company cannot look."

You do not have to abandon Gmail or Outlook to get it. A browser-based tool can add end-to-end encryption inside the inbox you already use, which is exactly the approach ProtectMyMail takes.

Frequently asked

Isn't my email already encrypted?

In transit, usually yes (via TLS). But your provider can still read the stored contents. End-to-end encryption is what stops that.

Does using a strong password make my email private?

It protects access to your account, not the privacy of the content from your provider or connected apps. Those are separate problems.

Keep the inbox you already use — private.

ProtectMyMail adds end-to-end encryption to Gmail, Outlook and IMAP, right in your browser. Start with 4 weeks free, then $5/month.

Add to browser →