Keep Factually independent
Whether you agree or disagree with our analysis, these conversations matter for democracy. We don't take money from political groups - even a $5 donation helps us keep it that way.
Fact check: What are the differences between Tutanota and ProtonMail, when it comes to user encryptions and privacy?
1. Summary of the results
Both Tutanota and ProtonMail offer robust end-to-end encryption but employ different approaches and have distinct features:
*Encryption Methods:
- Tutanota uses its own encryption method with AES-128 cipher, encrypting entire email threads including subject lines [1] [2]
- ProtonMail uses the PGP standard and does not encrypt subject lines [1] [2]
- Both services use RSA for user-to-user communications and AES for user-to-non-user communications [3]
Location and Privacy Laws:
- ProtonMail operates from Switzerland with strong privacy laws [1]
- Tutanota is based in Germany, protected by GDPR but part of the Fourteen Eyes intelligence alliance [1]
**2. Missing context/alternative viewpoints**
The original question focuses solely on encryption and privacy, but there are other important factors to consider:
Additional Features:
- ProtonMail offers self-destructing emails and allows 150 free messages daily [2]
- Tutanota provides 1GB storage in its free version [2]
- Both services offer two-factor authentication [4]
Privacy Implementations:
- Tutanota demonstrates stronger privacy features by not using cookies and anonymizing IP addresses [3]
- Tutanota allows anonymous account creation without phone numbers [2]
**3. Potential misinformation/bias in the original statement**
The original question's narrow focus on encryption and privacy might lead to overlooking:
1. Business Model Implications:
- Both services offer free versions with different limitations [2], suggesting their business models might influence feature availability
2. Regulatory Compliance:
- The location of these services (Switzerland vs. Germany) affects their compliance requirements and data handling capabilities [1]
3. Technical Standards:*
- While both are secure, they use different technical standards (PGP vs. proprietary encryption) [1], which might affect compatibility with other email services and long-term sustainability
The choice between these services might depend more on specific use cases and requirements rather than purely on encryption and privacy features.