Why free email isn't private
Free email feels private because it's password-protected. But a password controls who's allowed to open the drawer — it says nothing about who else already has a copy of the key.
1 The password illusion
A login screen checks identity: does this password match this account. It says nothing about who can access the data behind it — because at an ordinary provider, your password is identification, not protection. The disks may well be encrypted, but that encryption is transparent: the system applies the keys automatically for every request it lets through. And inside the provider's organisation, your password plays no part at all — there, access is decided by internal access rights alone. An engineer, a support agent resolving a ticket, an ad-matching pipeline, an administrator: they reach your data without ever needing your password, and it arrives already decrypted.
People treat "I have a strong password" as if it meant "my mail is private." Those are two different claims — and only one of them is actually being made.
2 What "encrypted" usually means
When a big provider says your email is "encrypted," they usually mean two things: the connection between your device and their servers — the same protection any ordinary website has — and encryption "at rest" on their disks. Both are real. Neither makes your mail private, because in both cases the provider holds the keys. Their systems decrypt your messages routinely and automatically: to index them for search, scan them for spam and malware, power convenience features, and answer a legal request in fully readable form.
"It says encrypted, so nobody but me can read it."
The provider holds the keys. They can read it — and so can anyone who can compel or compromise them.
3 One breach, everything
Most people never delete anything. A typical inbox that's been open for ten years quietly holds tax documents, medical correspondence, banking alerts, insurance claims, travel bookings — and the password-reset trail for nearly every other account tied to that address.
That last part is what makes email the master key. Break into the inbox and you don't just read old messages — you can walk into the bank account, the cloud storage, and the social accounts, one "forgot password" click at a time. This is why inbox takeovers are among the most common paths into identity theft: the target usually isn't the email itself, it's everything the email can unlock.
4 Free has a business model
Large-scale free inboxes are supported by advertising and data businesses, and your correspondence is part of the raw material. For years the major free providers scanned message content directly to target ads — Google only stopped doing that in 2017, and some others carried on longer. What remains is subtler but still valuable: your mail is machine-read for filtering and "smart" features, and the receipts, bookings, subscriptions, and contacts flowing through it feed the commercial profile attached to you across the provider's other services.
None of this is hidden. It's standard, disclosed-in-the-terms business practice — the terms you accepted permit automated processing of everything you send and receive.
5 What modern AI changes
Older ad-matching looked for keywords — "flight," "mortgage," "baby." Modern AI text processing can read far more than subject matter: it can infer sentiment, life stage, financial stress, relationship status, health concerns, and decision-making patterns from ordinary phrasing, without you ever naming the topic. A system doesn't need you to write "I'm getting divorced" — it can infer it from the shift in who you're emailing and how you're writing to them.
Whether any given provider runs this kind of analysis today is a policy choice they can change at any time. That it's now cheap and possible at scale is the new fact — and the only architecture it can't touch is one where the mail arrives already encrypted, unreadable to the machines that store it.
A profile like that isn't a harmless targeting label. It's a standing dataset about a real person's finances, health, and relationships — sitting on a server, one breach, subpoena, or vendor mistake away from becoming someone else's property.
The honest summary
The point isn't that every free provider is malicious — most of this is standard, disclosed business practice. The point is that "free," "password-protected," and "encrypted" are being used to imply a privacy guarantee that the underlying architecture was never built to make.
Confidesk is built the other way round: your mail and files are encrypted in your browser, on your device, and the server only ever holds scrambled data. Your key passphrase isn't identification — it is the lock itself, and only you hold it. That's the whole difference in one line: at an ordinary provider, an administrator sees everything; at Confidesk, an administrator sees nothing. Not even us.
See what email looks like when the provider can't read it — because the passphrase that unlocks it never leaves your device.