Blog & References
Privacy insights, technical analysis, and long-running references from CodaMail’s founder and engineering team.
No email service can protect you from governments. A foreign provider expands your jurisdictional exposure rather than shrinking it: their privacy laws probably don't cover non-residents, foreign traffic gets weaker protection everywhere, MLATs and data-sharing agreements still give your own country access, and servers often sit in more jurisdictions than the marketing admits. The details, fully sourced and regularly updated, are in the Privacy Law Directory below.
What a privacy service can do is keep your data away from data brokers, trackers, spammers, email leaks, AI training, and the unwashed masses. Real zero-knowledge encryption means the service never touches the cryptography or your private key; strong encryption is never proprietary. A paid service should add functionality and interoperability, not remove them, and it should include unlimited aliases, the heart of true anti-spam control and privacy. Above all, you must trust the provider: no matter how strong the encryption, they still handle a lot of your plain text and know a lot about you (see the articles below). If their marketing misleads you, what exactly are you trusting?
Privacy Law Directory
38+ jurisdictions across US federal/state, the EU, and the wider world. The intelligence-sharing alliances, MLATs, and cross-border frameworks that reach your data, plus each jurisdiction’s surveillance powers, privacy laws, and over-rides.
Browse the directory →
Data Broker Directory
1,700+ named entities across 17 categories — adtech, consumer, financial, health, location, employment, insurance, education, and more. Who has your data, where they got it, who they sell it to, with sourced profiles and opt-out information.
Browse the directory →
VPN Infrastructure Exposed
Who really runs your VPN. Corporate ownership chains, jurisdiction shopping, logging contradictions, and what the marketing leaves out. A technical look at the gap between “no logs” claims and operational reality.
Read the investigation →
Stephen Gielda is the founder of Packetderm, LLC, the company behind CodaMail and Cotse.Net. Steve has 30 years of computer security and privacy experience and has been running privacy services since 1997.
-
Analysis
The Truth About Zero Knowledge / Zero Trust
-
Comparison
Understanding E2EE, TLS/SSL, and Zero Access Storage
-
Analysis
The Walled Garden Approach: What Privacy Email Services Don’t Tell You About E2EE
-
Analysis
Why You Should Never Let a Provider Generate or Store Your Private Key
-
Analysis
Why Commercial Open Source Is Not a Trust Model
