tuta.com — 87/100 (Madal privaatsusrisk)
Viimati analüüsitud
Aruande sisu (kokkuvõte, leitud asjaolud, tsitaadid) on genereeritud inglise keeles ja seda pole lokaliseeritud.
Tutao GmbH · tuta.com
Aruande üksikasjad
Madal privaatsusriskTuta is a highly privacy-friendly encrypted email provider that stores all user data end-to-end encrypted in Germany, collects minimal metadata, uses no cookies, and shares data with third parties only for payment processing or under court order.
Tutao GmbH (Tuta) demonstrates strong privacy practices centered on end-to-end encryption and data minimization. All user content is encrypted so that even Tuta cannot access it. Only essential metadata (email addresses, timestamps) remains unencrypted. Data is stored exclusively in ISO 27001 certified German data centers. Third-party sharing is limited to payment processors. The policy is transparent and references specific GDPR legal bases. Areas of concern include the campaign analysis feature that hashes IP addresses and user agents with campaign IDs under legitimate interest rather than consent, and the policy's silence on AI/model training. Law enforcement disclosure is possible under court order, though encrypted content would be inaccessible to Tuta.
Kategooriate kaupa hinnang
Poliitika jaotus peamistele vastavusaladele. Hea = tugev, keskmine = segane, nõrk = muret tekitav.
End-to-end encryption of all user data, no cookies, only essential metadata stored unencrypted, and IP addresses stored only in anonymized form.
Policy clearly specifies each data category collected, its purpose, legal basis under GDPR, and retention periods with specific article references.
Data shared only with payment processors (credit institutions, PayPal) and law enforcement under court order; explicit statement that no data is sold.
All data stored in ISO 27001 certified data centers in Germany with no mention of any transfers outside the EU/EEA.
Policy is completely silent on AI or model training; while Tuta's encryption model makes unauthorized use unlikely, explicit confirmation is absent.
Comprehensive listing of GDPR rights (Articles 15-20, 21, 77) including access, rectification, erasure, restriction, portability, objection, and complaint to supervisory authority.
Peamised leitud asjaolud
Märkimisväärsed klauslid, probleemid või head tavad (kriitilised esimesena)
Campaign analysis processes hashed identifiers under legitimate interest without explicit consent
The policy states that when users arrive via campaign links, Tuta stores a cryptographic hash of IP address and user agent together with a campaign ID linked to the Tuta account. This is processed under Art. 6(1)(f) legitimate interest rather than consent. While the hash is claimed to prevent re-identification, the combination of hash + campaign ID + account linkage means Tuta can associate campaign attribution with specific users for 30 days. This is a form of tracking that relies on legitimate interest balancing rather than user consent.
Law enforcement disclosure clause could compel inventory and traffic data
The policy states: 'we can be legally bound to provide content data and traffic data (in case of a valid court order) and inventory data to law enforcement agencies.' While end-to-end encryption protects content from Tuta's own access, inventory data (email address, name, billing address) and traffic data (metadata such as sender/recipient addresses and timestamps) could be disclosed. Users should understand that metadata is not end-to-end encrypted and is accessible to Tuta and thus to authorities.
Email metadata is stored unencrypted and accessible to Tuta
The policy explicitly states: 'Only necessary metadata to provide the service (like the user's email addresses, email addresses of senders and recipients and the dates of emails) is stored unencrypted.' This means that while email content is protected by end-to-end encryption, the social graph of who communicates with whom and when is visible to Tuta and could be disclosed under court order. Mail server logs containing sender/recipient addresses and connection times are retained for up to 7 days.
No cookies and no third-party analytics tools used
The policy explicitly states 'We do not use cookies' and 'we do not use analysis tools such as Google Analytics or other third-party tools.' Usage statistics are opt-in, anonymized, and self-hosted. This is a notably strong anti-tracking stance that eliminates common web surveillance vectors.
Data retention after account termination has exceptions that could extend storage significantly
While the default is deletion within 30 days of contract termination, the policy lists multiple exceptions: accounting data may be retained until fee disputes are resolved, inventory data can be stored for up to two years for complaint handling, and deletion may be omitted where legal regulations or prosecution of claims require it. Tax, contract, and commercial law retention periods also apply to order-related data. These exceptions could result in some personal data persisting well beyond the 30-day baseline.
Kokkuvõte kasutajale
Tuta is one of the strongest privacy-oriented email services available, with genuine end-to-end encryption that even Tuta itself cannot bypass, though users should be aware that email metadata and campaign tracking data are not encrypted.
Vastavusseisund
Tuta demonstrates strong GDPR compliance with a German-based controller, appointed DPO, clear legal bases for each processing activity, and comprehensive data subject rights documentation.
EL-i ülekanded
No international transfers. All data is stored exclusively in ISO 27001 certified data centers in Germany, within the EU/EEA.
Tuvastatud signaalid
Tekstis tuvastatud konkreetsed andmed ja tavad
Tõendite väljavõtted
Otsesed tsitaadid poliitikast nende leidude toetuseks
All user data is stored end-to-end encrypted in Tuta. Only necessary metadata to provide the service (like the user's email addresses, email addresses of senders and recipients and the dates of emails) is stored unencrypted.
We do not use cookies.
In order to evaluate campaigns with partners and advertising campaigns...we store a cryptographic hash of connection data like the IP address and the user agent...together with the campaign ID when you visit our website via a campaign link.
The personal data shall be deleted no later than 30 days after termination of the contract, unless specific reasons to the contrary apply in an individual case.
However, we can be legally bound to provide content data and traffic data (in case of a valid court order) and inventory data to law enforcement agencies. There will be no sale of data.
Puudub või ebaselge
- Explicit statement on whether user data is used for AI or model training
- Details on data portability implementation (how to export data in machine-readable format)
- Specific retention periods for each data category beyond the general 30-day post-termination rule
- Whether campaign analysis can be opted out of
- Details on sub-processors beyond payment providers
- Whether Tuta has received law enforcement requests and published transparency reports
Küsimused, mida küsida
- How does Tuta implement the right to data portability (Art. 20 GDPR) for end-to-end encrypted data — can users export their encrypted and unencrypted data in a structured, machine-readable format?
- Can users opt out of campaign analysis tracking, or is the legitimate interest balancing the only recourse via the right to object under Art. 21 GDPR?
- Has Tuta published a transparency report detailing the number and types of law enforcement requests received and how they were responded to?
- What specific anonymization technique is used for IP addresses, and has Tuta assessed whether the combination of anonymized IP, device type, and geolocation could lead to re-identification?
- Does Tuta use any user data (including metadata or anonymized usage statistics) for training machine learning models or AI systems?
- What happens to the campaign analysis hash and campaign ID data if a user deletes their account during the 30-day retention window?
Jaga seda analüüsi
Igaüks, kellel on see link, saab ülalolevat tulemust vaadata.
DentroChati loodud
100% Euroopa tehisintellektivestlus kõigile
Vestle tehisintellektiga, tööta failidega, loo pilte ja otsi veebist. Andmed jäävad Euroopasse.
Teised analüüsitud privaatsuspoliitikad
Vaata kõikigdprchat.eu
88/100
Madal privaatsusriskGDPRchat pakub erakordselt tugevat ELi-keskset privaatsust ilma jälgimiseta ja iseteenindusega andmekontrolliga, kuid kasutajad peaksid teadma, et pildiprompte võib kolmanda osapoole pakkuja poolt kasutada AI treenimiseks.
Vaata aruannet →proton.me
88/100
Madal privaatsusriskProton pakub vaikimisi tugevat privaatsust, kasutades otsast lõpuni krüpteerimist, minimaalset andmekogumist ja ilma reklaamijälitamiseta, kuigi osa kasutajaandmeid liigub siiski USA-s asuvatele töötlejatele toe ja maksete jaoks.
Vaata aruannet →kolsetu.com
85/100
Madal privaatsusriskKolsetu austab üldiselt ELi privaatsuseeskirju, kuid kogub liigselt kasutusandmeid, tal puudub avalik andmekaitsejuht (DPO) ja ta annab mõnede rahvusvaheliste andmeedastuste kohta piiratud üksikasju.
Vaata aruannet →startpage.com
90/100
Madal privaatsusriskStartpage pakub erakordset privaatsust disaini järgi, kogudes peaaegu üldse mitte isikuandmeid ning lükates selgelt tagasi jälgimise, profileerimise ja otsingute logimise, kuigi esineb väikseid andmevooge kolmandate osapoolte reklaami- ja analüütikapakkujatele.
Vaata aruannet →