Privacy-friendly services
A service that advertises privacy does not automatically minimise data. What matters is which data is technically processed, what is retained, and which provider you ultimately have to trust.
Transparency: If you use a recommendation marked with *, you may support our work. We may receive a commission. Recommendations and assessments are made independently of that.
Email with less tracking
Email privacy is not only about advertising. Relevant issues include tracking pixels, access to message contents, metadata, server location and whether a provider analyses messages for advertising purposes.
| Provider | Why it is interesting | Important note |
|---|---|---|
| Proton Mail* | No advertising profile built from email content; tracking-pixel protection; encrypted storage | Email metadata is still technically generated; external unencrypted mail is also processed for purposes such as spam and malware protection |
| Tuta Mail | Ad-free, no tracking; servers in Germany; strong encryption | The scope of encryption also depends on whether both parties use Tuta or an encrypted delivery method |
| mailbox.org | Ad-free; provider states no tracking; German data centres; PGP/S/MIME available | End-to-end encryption has to be configured and used appropriately |
Password managers
A password manager helps you use a unique strong password or passkey for every service. From a privacy perspective, the most relevant issues are vault encryption, account protection and metadata handling.
| Provider | Documented properties | Important note |
|---|---|---|
| NordPass* | Password and passkey manager; according to the provider, a zero-knowledge architecture with local encryption of vault data before synchronisation | Protection also depends on the master password, account security and the security of the devices used |
| Proton Pass* | Password and passkey manager; zero-knowledge end-to-end encryption including metadata; open-source apps and independent security audits | Vault security also depends on protection of the Proton account and devices used; forwarding email aliases are not technically end-to-end encrypted |
VPN: less visibility for your internet provider
What does a VPN do? A VPN encrypts the connection between your device and the VPN server. Your internet provider can therefore normally no longer see directly which websites and services you access. Services you visit usually see the VPN server's IP address instead of your home connection IP. This can also provide additional protection on unfamiliar or public networks.
Important: A VPN does not make you automatically anonymous. Your internet provider can still see that a VPN connection exists and approximately when and how much data is transferred. At the same time, part of the required trust shifts to the VPN provider. We therefore explicitly state whether and for how long IP or connection data is retained.
| Provider | Documented properties | IP / connection logging | Link |
|---|---|---|---|
| Proton VPN* | According to the provider, a strict no-logs policy without logging visited websites, traffic, IP address, session duration or location; independently audited | According to the provider, no retention of IP address, connection logs, session duration or location | Open provider |
| NordVPN* | According to the provider, a no-logs policy; implementation was again independently examined by Deloitte in an assurance engagement at the end of 2025 | According to the no-logs policy, no retention of activity logs or extensive connection logs such as IP address, connection date/duration or VPN server used | Open provider |
| Surfshark* | According to the provider, no retention of visited websites or permanent activity logs | User ID and/or IP address and connection timestamps may be processed temporarily; automatic deletion within 15 minutes after the session ends | Open provider |
| ExpressVPN | According to its privacy policy, no activity or connection logs; no retention of browsing history, traffic destinations or DNS queries | According to the provider, no retention of source IP, assigned VPN exit IP, connection timestamp or session duration | Open provider |
DNS & tracking blocking
DNS filters can block known advertising, tracking, phishing and malware domains before a connection is established. This does not replace browser-side protection, but it can reduce many unnecessary third-party connections across a device or network.
| Service | Data-minimising use | Link |
|---|---|---|
| AdGuard DNS* | For its public DNS service, AdGuard describes operation without personal DNS usage data; private DNS can keep query logs, which can be disabled or limited in the account settings | AdGuard DNS |
| AdGuard* | Local ad and tracker blocker; can reduce unwanted third-party connections directly on the device | Open AdGuard |
Cloud storage
With cloud storage, a key question is whether the provider can decrypt stored contents itself or whether sensitive files are encrypted on your device before upload.
| Provider | Documented properties | Important note |
|---|---|---|
| pCloud* | Cloud storage with selectable EU or US data region; pCloud Encryption offers client-side zero-knowledge encryption | Client-side zero-knowledge encryption applies to the activated Crypto folder; other files are not automatically encrypted client-side in the same way |
How we assess providers
- Which data is technically required to provide the service?
- Which data is retained permanently?
- Is there tracking or advertising profiling?
- Can logging be disabled or limited?
- How transparent are the privacy policy and technical documentation?
- Are there independent audits or verifiable security evidence?
Last updated: 29 September 2026. Provider terms and technical properties can change.