Every mailbox has AI in it now — summaries, smart replies, sorting, search that understands meaning. All of it requires something to process your mail. The interesting question is not whether software reads your email; it is what happens to your mail afterwards, and that is where providers genuinely differ.
Privacy pages are written to survive that question rather than answer it. These four ask it directly.
1. Is my mail used to train models?
This is the one that matters most and gets answered least clearly. Processing your mail to give you a result is transient. Training is permanent: your content shapes a model that then exists independently of you, cannot be meaningfully un-trained, and may be used for everyone else.
What to look for: an unconditional "we do not train on your content", not "we do not train without your permission" — which means there is a setting, and a default, and the default can change. Ask about subprocessors too: a provider that does not train on your mail but sends it to an API that does has not actually answered.
2. Where does the processing physically happen?
"EU-hosted" often describes only storage. If your mailbox sits in Frankfurt but every AI feature ships message text to an API in the United States, your mail crosses a border every time you use the product — and the guarantee you were sold covers the disk, not the workload.
What to look for: an explicit statement about where inference runs, not just where data is stored, and named subprocessors with their jurisdictions. Mailotte runs its AI on its own servers in Europe, with an EU-resident fallback that is contractually prohibited from training on user content — that phrasing is deliberate, because "EU-hosted" alone would not have told you.
3. Can I turn it off, and what breaks?
A provider confident about its AI will let you disable it and tell you plainly what stops working. A provider that cannot is telling you the feature is not really optional.
What to look for: a real off switch, per-feature rather than one global toggle, and an honest description of the consequence. "Turning this off disables smart sorting" is a good answer. No switch at all is also an answer.
4. What is the business model?
This one predicts the others. A provider funded by subscriptions has a commercial reason to keep your mail boring. A provider funded by advertising has a permanent, structural incentive to know more about you, and the strength of its current policy is a decision that can be revisited by its next executive team.
What to look for: how the company makes money, in one sentence, without a diagram. If the answer is advertising, the privacy policy is a promise, not a structure.
A note on "we don't read your email"
Taken literally this is false for every provider that is not end-to-end encrypted — spam filtering alone requires reading message content. Providers that say it usually mean "no human reads it", which is a much weaker and much less interesting claim. The honest framing is: our systems process your mail to deliver these specific features, and here is everything that happens to it afterwards. Be suspicious of anyone unwilling to say the first half.
The short version
End-to-end encrypted providers (Proton, Tuta) answer all four by making the questions inapplicable — and pay for it in features. Everyone else is asking you to trust a policy, in which case the four questions above are how you find out whether the policy is specific enough to be worth anything. Mailotte's answers are on the Trust page, and the comparison pages set them next to everyone else's.