Runbox
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Norwegian private email since 1999 (Runbox Solutions AS), own NO data centre, 100% renewable hydro, PGP + 2FA + PFS, double carbon-negative.
Runbox is an EU-owned service hosted in Norway, with no identified CLOUD Act exposure. It is listed under Private email.
Assessment notes
Runbox is operated by Runbox Solutions AS, a Norwegian company in continuous operation since 1999 (among the longest-running independent privacy-email vendors in Europe) running its own infrastructure inside a Norwegian high-security data centre powered by 100% certified renewable hydropower, supporting PGP encryption, two-factor authentication, Perfect Forward Secrecy SSL, encrypted Web/POP/IMAP/SMTP, with public privacy policy and terms; Norwegian jurisdiction (EEA, outside EU), no CLOUD Act exposure. Gap: Runbox does not publish a publicly accessible DPA (customers are directed to a DPO contact rather than a self-serve document); no formal ISO 27001 attestation.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
End-to-end encryption: No
-
Public DPA: No
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Runbox
Runbox is operated by Runbox Solutions AS, a Norwegian company that has been in continuous operation as a privacy-focused email service since 1999, making it one of the longest-running independent vendors in this category, alongside Posteo (Berlin, 2009) and Mailbox.org (Berlin, 2014 in current form). The product is straightforward: secure IMAP/POP/SMTP email under Norwegian and EEA privacy law, with PGP encryption, two-factor authentication, Perfect Forward Secrecy on SSL, and standard mail-client compatibility; no proprietary lock-in, no advertising, no tracking.
The infrastructure story is genuinely strong. Runbox runs its own infrastructure inside a Norwegian high-security data centre, powered by 100% certified renewable energy from clean Norwegian hydropower, with multiple redundancy layers for high availability. The company is recognised by the Ethical Consumer "Best Buy" designation and carries a Carbon Balanced Certificate (double carbon-negative via World Land Trust), sustainability credentials that match Infomaniak's posture in the same Swiss-Norwegian-Nordic privacy band. As a Norwegian operator, Runbox is explicitly outside the reach of the US CLOUD Act.
For an EU-sovereignty audit the only gaps are formal compliance documentation: no ISO/IEC 27001 attestation, no SOC 2, and no publicly linked DPA or sub-processors list were surfaced at audit. None of those gaps suggest poor practice; they just mean that procurement-grade buyers needing those documents will need to request them. Norway is EEA rather than EU, and no formal certifications were documented at audit.
Pricing is paid-only (no free tier), competitive and storage-tiered: Micro €19.95/year (€1.66/month, 2 GB); Mini €34.95/year (€2.91/month, 10 GB); Medium €49.95/year (€4.16/month, 25 GB); Max €79.95/year (€6.66/month, 50 GB). 20% discount on 3-year subscriptions. Best fit: privacy-conscious EU/EEA users who want a long-established Norwegian privacy-email service with first-class PGP support, ethical / sustainability credentials, and explicit CLOUD-Act-non-applicability, and who do not require a free tier or formal ISO 27001 attestation.
Sub-processor map · none disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Runbox
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €3/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: Yes Public DPA: No Sub-processors: Yes Open source: No -
-
Germany · €1/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
E2E: No Public DPA: Not assessed Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: Yes
Public DPA: No
Sub-processors: Yes
Open source: No
|
€3/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
E2E: No
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
|
€1/mo |