Privacy-friendly services

A service that advertises privacy does not automatically minimise data. What matters is which data is technically processed, what is retained, and which provider you ultimately have to trust.

Transparency: If you use a recommendation marked with *, you may support our work. We may receive a commission. Recommendations and assessments are made independently of that.

Email with less tracking

Email privacy is not only about advertising. Relevant issues include tracking pixels, access to message contents, metadata, server location and whether a provider analyses messages for advertising purposes.

ProviderWhy it is interestingImportant note
Proton Mail*No advertising profile built from email content; tracking-pixel protection; encrypted storageEmail metadata is still technically generated; external unencrypted mail is also processed for purposes such as spam and malware protection
Tuta MailAd-free, no tracking; servers in Germany; strong encryptionThe scope of encryption also depends on whether both parties use Tuta or an encrypted delivery method
mailbox.orgAd-free; provider states no tracking; German data centres; PGP/S/MIME availableEnd-to-end encryption has to be configured and used appropriately

Password managers

A password manager helps you use a unique strong password or passkey for every service. From a privacy perspective, the most relevant issues are vault encryption, account protection and metadata handling.

ProviderDocumented propertiesImportant note
NordPass*Password and passkey manager; according to the provider, a zero-knowledge architecture with local encryption of vault data before synchronisationProtection also depends on the master password, account security and the security of the devices used
Proton Pass*Password and passkey manager; zero-knowledge end-to-end encryption including metadata; open-source apps and independent security auditsVault security also depends on protection of the Proton account and devices used; forwarding email aliases are not technically end-to-end encrypted

VPN: less visibility for your internet provider

What does a VPN do? A VPN encrypts the connection between your device and the VPN server. Your internet provider can therefore normally no longer see directly which websites and services you access. Services you visit usually see the VPN server's IP address instead of your home connection IP. This can also provide additional protection on unfamiliar or public networks.

Important: A VPN does not make you automatically anonymous. Your internet provider can still see that a VPN connection exists and approximately when and how much data is transferred. At the same time, part of the required trust shifts to the VPN provider. We therefore explicitly state whether and for how long IP or connection data is retained.

ProviderDocumented propertiesIP / connection loggingLink
Proton VPN*According to the provider, a strict no-logs policy without logging visited websites, traffic, IP address, session duration or location; independently auditedAccording to the provider, no retention of IP address, connection logs, session duration or locationOpen provider
NordVPN*According to the provider, a no-logs policy; implementation was again independently examined by Deloitte in an assurance engagement at the end of 2025According to the no-logs policy, no retention of activity logs or extensive connection logs such as IP address, connection date/duration or VPN server usedOpen provider
Surfshark*According to the provider, no retention of visited websites or permanent activity logsUser ID and/or IP address and connection timestamps may be processed temporarily; automatic deletion within 15 minutes after the session endsOpen provider
ExpressVPNAccording to its privacy policy, no activity or connection logs; no retention of browsing history, traffic destinations or DNS queriesAccording to the provider, no retention of source IP, assigned VPN exit IP, connection timestamp or session durationOpen provider

DNS & tracking blocking

DNS filters can block known advertising, tracking, phishing and malware domains before a connection is established. This does not replace browser-side protection, but it can reduce many unnecessary third-party connections across a device or network.

ServiceData-minimising useLink
AdGuard DNS*For its public DNS service, AdGuard describes operation without personal DNS usage data; private DNS can keep query logs, which can be disabled or limited in the account settingsAdGuard DNS
AdGuard*Local ad and tracker blocker; can reduce unwanted third-party connections directly on the deviceOpen AdGuard

Cloud storage

With cloud storage, a key question is whether the provider can decrypt stored contents itself or whether sensitive files are encrypted on your device before upload.

ProviderDocumented propertiesImportant note
pCloud*Cloud storage with selectable EU or US data region; pCloud Encryption offers client-side zero-knowledge encryptionClient-side zero-knowledge encryption applies to the activated Crypto folder; other files are not automatically encrypted client-side in the same way

How we assess providers

  • Which data is technically required to provide the service?
  • Which data is retained permanently?
  • Is there tracking or advertising profiling?
  • Can logging be disabled or limited?
  • How transparent are the privacy policy and technical documentation?
  • Are there independent audits or verifiable security evidence?

Last updated: 29 September 2026. Provider terms and technical properties can change.