Open your email inbox and search for attachments from the last five years. What comes back isn’t just correspondence — it’s a document archive that most people have never consciously chosen to create.
Bank statements sent monthly as PDFs. Tax-related forms from employers and investment accounts. Medical appointment confirmations with diagnosis codes in the body. Insurance documents, including claim histories. Employment contracts, offer letters, and salary details. Lease agreements and mortgage documents. Passport or ID scans sent to book accommodation or complete a registration.
The average person’s email inbox contains more sensitive personal financial and identity documentation than their actual filing cabinet. And unlike a filing cabinet, it’s stored with a company that can technically read everything in it, it’s a primary target for attackers, and it lives across thousands of servers in data centres they’ve never seen.
How the Inbox Became an Accidental Archive
Nobody set out to use their email as a document storage system. It happened gradually, through the accumulation of things sent to them.
When banks and utility companies transitioned from paper statements to email notifications, the PDFs started arriving in inboxes. When healthcare providers began sending appointment confirmations and test results electronically, the details landed in email. When employers moved to electronic payroll and HR systems, offer letters, contracts, and pay stubs arrived as attachments.
Users didn’t file these elsewhere because they didn’t need to — email search made them findable, and the inbox was always there. The habit of downloading and organising documents into separate storage never developed, because retrieval from the inbox was good enough.
The result, after years of this pattern, is an inbox that functions as an extensive personal record. The person who has used Gmail since 2010 has fifteen years of financial and personal documents sitting there, attached to individual emails, indexed and searchable by their provider.
What Email Providers Can Access
Email is not encrypted in the way that would protect attachments from provider access. Google can read your Gmail. Microsoft can read your Outlook. The privacy policies of major email providers explicitly acknowledge this, while emphasising the ways they limit what they actually do with that access.
Google’s current privacy policy describes how it processes email content to provide services including spam filtering, smart features like suggested replies, and — depending on your account settings — personalisation. Google’s AI products, including Gemini, can be granted access to analyse your email content and attachments to assist with tasks.
Microsoft’s equivalent features in Outlook and Microsoft 365 similarly process email content to power features. Microsoft Copilot can access your email attachments to summarise documents and assist with tasks, where enabled.
The practical implication: when your email provider scans for spam, processes content for smart features, or enables AI assistance over your inbox, your attachments are included. The bank statement PDF, the medical form, the scanned contract — these are processable content, not inert files sitting outside the system.
This isn’t a violation of most providers’ terms. It’s what you agreed to when you created the account. But it’s also not what most people imagined when they created the account.
The Breach Risk
Email accounts are among the highest-value targets for attackers. Compromising someone’s primary email gives access to the current inbox, years of archived messages, and — because of password reset flows — the ability to take over other accounts.
When an email account is compromised, the sensitive documents accumulated as attachments over the years become immediately accessible. A breach of a Gmail account doesn’t expose just the emails: it exposes every PDF ever received there.
The scale of email credential exposure is documented. The Have I Been Pwned database, which tracks known breach data, includes hundreds of millions of email addresses and associated credentials from breaches across thousands of services. Many of these breaches were unrelated to the email provider itself — they were breaches of third-party services where users had registered with their email address and reused the same password.
The 2026 stealer log compilations — databases of credentials harvested by information-stealing malware — contain a substantial proportion of email account credentials. These compiled credentials are used in credential stuffing attacks: automated tools testing whether the stolen email and password combination works against webmail login pages.
A successful credential stuffing attack against a Gmail account doesn’t just hand over the inbox. It hands over years of sensitive document attachments.
Government Access and Legal Requests
Beyond commercial data processing, email stored with major providers is subject to government access requests.
In the United States, law enforcement can obtain email content held by providers through search warrants, National Security Letters, and court orders under the Electronic Communications Privacy Act, among other legal mechanisms. The specific procedural requirements depend on the type of access and the age of the content.
Google and Microsoft publish transparency reports disclosing the number and nature of government data requests they receive. Both receive tens of thousands of requests annually. Both comply with valid legal requests, typically notifying users when permitted by law.
This isn’t a reason to assume the worst or to distrust email as a communication medium. It is a reason to be thoughtful about what you store in email long-term. A bank statement you need to retain for seven years for tax purposes has a different risk profile when stored in Gmail than when stored in a private service outside the scope of your email account.
The Specific Risk of Shared and Forwarded Attachments
Sensitive documents sent as email attachments often pass through more hands than intended.
You send a lease agreement to a landlord via email. They forward it to a property manager. The property manager sends it to a verification service. At each step, the document lives in more inboxes, across more providers, in more data centre locations.
You fill out a form with your medical history and email it to a clinic. The clinic’s email system is hosted by a provider with a different privacy policy than your own. The document now exists in your outbox and in their inbox.
This chain is invisible and difficult to control after the fact. Once an attachment has been sent, you can’t retrieve it from the recipient’s inbox. You can only control what you send — which means being deliberate about which documents you email versus which you share through more controlled channels.
What to Do About It
The goal isn’t to abandon email — it’s to stop using your inbox as a passive long-term document repository.
Download and delete sensitive attachments
Spend some time with your inbox, searching for sensitive attachments: statements, contracts, medical documents, identity documents, payroll records. For each one, download it to a more appropriate location and consider deleting the email.
Deleting from your Gmail or Outlook inbox removes it from the interface — but many providers retain deleted content for a period before permanent removal. Check your provider’s data retention settings.
Move documents to dedicated storage
A personal file storage service designed for private document management is a more appropriate home for sensitive files than an email inbox. Unlike email, which is fundamentally a communication tool, a dedicated storage service lets you organise, version, and control access to your documents deliberately.
When you need to retain a document long-term, the question worth asking is: should this live in email, or should it live somewhere I’ve specifically chosen for personal document storage?
Change where statements are sent
For ongoing documents — bank statements, utility bills, insurance notices — most services now offer the option to download directly from a portal rather than receive by email. Switching to this model means sensitive PDFs go to your download folder rather than your inbox, which gives you more direct control over where they end up.
Be deliberate about what you send
When emailing sensitive documents, consider whether email is the right channel. Secure file transfer services, or sharing links from a private cloud service (with appropriate access controls), leave less accidental residue across multiple inboxes.
The Inbox as Infrastructure
Email inboxes have become critical personal infrastructure — the hub that receives everything important, from which accounts are managed and reset. Their centrality makes them valuable. Their openness and their lack of document-specific security controls make accumulated sensitive files there a specific and underappreciated risk.
A banking password stored in a password manager is deliberately protected. A bank statement sitting as a PDF in an email attachment has received no such deliberate protection — it arrived there passively and has accumulated there by default.
The most effective response isn’t paranoia about using email. It’s periodically asking whether the sensitive documents that have accumulated in your inbox belong there, and moving the ones that don’t to somewhere you’ve chosen for the right reasons.
Your inbox was designed to receive messages. It has become, for most people, something considerably more permanent. Treating it accordingly is a straightforward privacy improvement that requires no technical expertise — only the habit of looking.