how-to

ProtonMail vs Tuta: What Private Email Actually Means

Private email providers like ProtonMail and Tuta differ in what they actually protect. Here's how they compare—and what neither can fully defend against.

If you’ve started thinking about email privacy, you’ve almost certainly encountered two names: Proton Mail (formerly ProtonMail) and Tuta (formerly Tutanota). Both are European-based, both emphasize encryption, both are popular in privacy communities.

They’re genuinely good choices compared to Gmail, Outlook, or Yahoo — but the ways they protect you, the specific threats they address, and the practical trade-offs they involve are meaningfully different. Understanding those differences helps you choose the right tool for what you actually need.


The Core Problem With Mainstream Email

Before comparing the alternatives, it’s worth being precise about what makes mainstream email private by default: almost nothing.

Gmail scans the content of your inbox to enable ad targeting, smart replies, and AI-powered features. The terms of service and privacy policy make this clear. When you use Gmail, Google has read access to every email you receive and send. This is not a vulnerability — it’s a feature, from Google’s perspective. The same applies to Yahoo and Microsoft’s consumer mail products.

Email addresses are also permanent identifiers. Every service you sign up for gets your email address, and those addresses accumulate across data brokers, marketing lists, and breach databases. Your inbox is both a content store and an identity anchor.

Private email providers address the content problem through encryption. Email alias services — a separate category — address the identity problem. The two aren’t interchangeable, and a complete privacy strategy often uses both.


How Proton Mail Works

Proton Mail uses end-to-end encryption for email exchanged between Proton Mail users. When both sender and recipient use Proton Mail, the content of the email is encrypted before it leaves your device and can only be decrypted by the recipient’s device. Proton’s servers store only encrypted ciphertext — the company cannot read the content of these emails.

For email sent to non-Proton users (the majority of email most people send), Proton Mail offers two options:

  • Standard delivery: the email is sent over standard SMTP, meaning neither Proton’s servers nor the recipient’s mail server apply end-to-end encryption.
  • Password-protected email: you can send an encrypted message to a non-Proton recipient, who can open it via a web link after entering a password you’ve shared with them through a separate channel.

Proton Mail supports PGP encryption for sending to non-Proton recipients who have public PGP keys. This is the established open standard for email encryption and works across mail providers — but it requires the recipient to also be using PGP, which essentially none of the general public does.

Proton’s servers are in Switzerland, subject to Swiss law. Switzerland requires judicial review for government data requests and sits outside EU and US legal jurisdiction, though Switzerland has mutual legal assistance treaties that can create pathways for international data requests in criminal investigations.


How Tuta Works

Tuta uses its own encryption protocol rather than PGP. Like Proton, Tuta provides end-to-end encryption for emails between Tuta users.

Unlike Proton, Tuta encrypts the email subject line by default — a meaningful difference. Email metadata including subject lines is visible even to encrypted-email providers unless they specifically address this. A subject like “re: diagnosis” or “follow-up from attorney” discloses information even when the body is encrypted.

For emails to non-Tuta users, Tuta follows the same pattern as Proton: standard SMTP for unencrypted delivery, or a password-protected link for secured communication with external recipients.

Tuta is based in Germany, subject to GDPR. Germany is an EU member state with strong data protection enforcement. The trade-off compared to Switzerland is that Germany is subject to EU-level legal frameworks and their associated judicial review processes — different from Switzerland’s but also meaningful.

A notable technical development: Tuta has implemented post-quantum cryptographic algorithms in its encryption, protecting against the theoretical future threat of quantum computers capable of breaking current encryption. This is the right direction — and it’s deployed, not promised.


Key Practical Differences

PGP compatibility

Proton Mail supports PGP with external recipients. Tuta doesn’t. This matters if you need to integrate with the broader PGP ecosystem — corporate environments that use encrypted email, security researchers, journalists with established PGP keys. If your encrypted email needs go beyond Tuta-to-Tuta, this is a real limitation.

Subject line encryption

Tuta encrypts email subjects. Proton Mail does not apply end-to-end encryption to incoming mail subjects by default. Subject line metadata can be revealing even when the body is encrypted — particularly for sensitive personal, medical, or legal correspondence.

Quantum-safe cryptography

Tuta has deployed hybrid post-quantum encryption for email, calendar, and contacts. Proton has announced intentions for quantum-safe encryption but the rollout has extended further. For most users today, this distinction doesn’t matter — current quantum computers can’t break modern cryptography at scale. For data that needs to remain private over decades, it’s a consideration worth noting.

Ecosystem breadth

Proton offers an integrated suite: Proton Mail, Proton Calendar, Proton Drive, Proton VPN, and Proton Pass (a password manager). If you want a privacy-focused ecosystem around a single account and provider relationship, Proton’s offering is more complete.

Tuta’s additional products are more limited — email, calendar, and contacts — without the storage, VPN, or password manager integrations.


What Neither Service Fully Protects

This is the part of most comparisons that gets omitted.

Email to non-users is unencrypted in transit

The vast majority of email most people send goes to Gmail, Outlook, and Yahoo accounts. Those emails travel over standard SMTP, are delivered in readable form to the recipient’s mail provider, and are stored however that provider stores email. Switching to Proton Mail or Tuta does not encrypt your emails to your family on Gmail, your colleagues on Outlook, or your dentist’s office on whatever shared hosting they use.

End-to-end encryption for email is effectively only available between users of the same encrypted service, or between people who have set up PGP — which almost nobody has done.

Metadata remains exposed

Even with end-to-end encryption, your email provider can see metadata: who you email, when, and how often. This contact graph is often more revealing than the content of any individual message. Proton and Tuta both acknowledge this in their privacy policies. Metadata is technically unavoidable given how email protocols function.

Both Proton and Tuta have received and complied with legally valid government requests. Proton disclosed that it provided IP address data in a French case in 2021. Both companies publish transparency reports showing compliance with lawful orders from their home jurisdictions. This is not a failing — it’s how legal systems work. But it is important to understand: “private email” doesn’t mean “inaccessible to law enforcement with valid legal process.”

The distinction matters for your threat model. Private email protects you from Google scanning your inbox for ad targeting. It does not protect you from a lawful court order.


Choosing Between Them

Use Proton Mail if:

  • You need PGP compatibility for communicating with external parties
  • You want an integrated privacy ecosystem (VPN, Drive, Calendar, password manager)
  • You’re specifically concerned about EU legal frameworks and prefer Swiss jurisdiction

Use Tuta if:

  • Subject line encryption matters to your threat model
  • You want post-quantum cryptography deployed and active now
  • You prefer a simpler interface and a lower entry cost

For most people, either is a significant improvement over Gmail for reducing what the email provider can see and use. The encryption they provide is real. The limitations described above are also real.


The Email Alias Addition

Private email providers address the content-exposure problem. They don’t fully address the identity problem — the fact that every service knows your email address, which becomes a permanent identifier across data brokers and breach databases.

Email alias services like SimpleLogin (now part of Proton), AnonAddy, and Apple’s Hide My Email let you create disposable addresses that forward to your real inbox. Each service gets a different alias, so a breach at one service doesn’t expose your actual email, and you can disable an alias without changing your main address.

Using a private email provider and email aliases together addresses both the content exposure and the identity persistence problems. Neither alone solves both.


The Practical Migration Question

Switching email providers is more work than switching browsers. Your email address is attached to every account you’ve ever created, and migrating comprehensively takes time.

A practical middle path: use a private email address as your primary going forward — for new accounts, for sensitive communications — while maintaining your existing address for legacy purposes. Over time, the balance shifts without requiring an immediate full migration.

The most private email setup is one you’ll actually use consistently. A partially-migrated setup that you maintain beats a fully-private setup you abandoned after a month because it added too much friction.


Where Email Fits in a Privacy Stack

Email privacy is one layer of a broader question about where your personal data lives and who has access to it.

Your email contains receipts, legal documents, medical communications, financial statements, and years of personal correspondence. Keeping those contents away from ad-targeting systems and data brokers is a reasonable goal. Proton Mail and Tuta both make progress toward it.

Alongside private email, the question of where you store files and documents that accompany that correspondence is worth asking separately. A private email that forwards documents to a general-purpose cloud storage service creates a different kind of exposure. The storage layer and the communication layer are both worth thinking through, ideally with providers that share consistent data practices rather than providers with conflicting incentives.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts