Posteo
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Berlin one-person-shop privacy email at €1/mo (Posteo e.K., since 2009); anonymous signup, BSI TR-03108 certified.
Posteo is an EU-owned service hosted in Germany, with no identified CLOUD Act exposure. It is listed under Private email.
Assessment notes
Posteo e.K. (Berlin DE, since 2009) is a small founder-owned privacy-maximalist email service: €1/mo flat, anonymous signup + anonymous payment, German data centres, 100% renewable energy (Green Planet Energy), BSI TR-03108 v2 certified for secure email transport, public transparency reports for authority requests; PGP + S/MIME end-to-end encryption support; EU-owned, EU-hosted, no CLOUD Act exposure.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
End-to-end encryption: NoOptional at-rest inbound encryption with your PGP key; not zero-access by default.
-
Public DPA: Not assessed
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Posteo
Posteo (Berlin, founded 2009, Posteo e.K., owner Patrik Löhr) is the small-and-cult European privacy email service: €1/mo flat-rate for 4GB, anonymous signup and anonymous payment options (postal cash, no payment-to-account link kept), all servers in German data centres, 100% renewable energy from Green Planet Energy, no advertising, no profiling. BSI TR-03108 v2 certified (Bundesamt für Sicherheit in der Informationstechnik standard for secure email transport). Supports PGP and S/MIME end-to-end encryption. Publishes annual transparency reports for authority requests. The Guardian and Stiftung Warentest both cite Posteo as a global leader in secure email. Single-vendor concentration risk because of the tiny team, but for personal privacy-first use this is the cleanest possible pick.
Sub-processor map · none disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Posteo
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
n/aData Processing Addendum (DPA)— not assessed
-
OpenSub-processors listposteo.de/en…
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €3/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: No Sub-processors: Yes Open source: No -
-
Germany · €1/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: No Public DPA: Not assessed Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: No
Sub-processors: Yes
Open source: No
|
€3/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: No
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
|
€1/mo |