Skip to content
Independently verified · Quarterly re-audit
EU VETTED

StartMail

VERIFIED
Private email · Netherlands
Founded 2014 · startmail.com ↗

Dutch private email (StartMail B.V., est. ~2014, by Startpage founders), NL-hosted, one-click PGP, unlimited aliases, USD-priced from $4.99/mo annual.

Why this score?

StartMail is operated by StartMail B.V. in the Netherlands, founded around 2014 by Robert E.G. Beens and David Bodnick — the same founders behind the Startpage privacy search engine — with servers physically located in the Netherlands under Dutch privacy law and GDPR, PGP encryption support including one-click encryption and password-protected encrypted messages, unlimited disposable email aliases, and a published transparency report; score held at 3/5 because (a) the broader Startpage group has had US ad-tech investor exposure historically (the 2019 Privacy One Group / System1 investment was widely covered and triggered community concern — current 2026 status needs human verification before publishing), (b) pricing is published in USD rather than EUR (an unusual choice for a Dutch company and a small but real signal worth noting), and (c) DPA and sub-processors URLs were not captured at audit.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About StartMail

StartMail is a privacy-focused email service operated by StartMail B.V. in the Netherlands. It was founded around 2014 by **Robert E.G. Beens** and **David Bodnick** — the same founders behind the **Startpage** privacy-focused search engine — and the two products share the broader Startpage / Surfboard Holding group history. The product positioning is straightforward: encrypted email under Dutch privacy legislation and GDPR, with one-click PGP encryption support, password-protected encrypted messages for recipients without PGP, unlimited disposable / alias email addresses, no advertising and no tracking, and IMAP/SMTP compatibility with standard email clients. The infrastructure side is clean: StartMail explicitly states that "our servers are located here as well" — referring to the Netherlands — meaning email storage stays under Dutch and EU law. PGP support is a real differentiator versus Gmail / Outlook / iCloud Mail (none of which offer first-class PGP) and against some other privacy-email vendors. A transparency report and a separate data-processing whitepaper are published. For an EU-sovereignty audit, two caveats keep the score below maximum. First, the **Startpage group ownership history**: in 2019 Startpage announced a strategic investment from Privacy One Group, a subsidiary of US ad-tech company **System1** — the deal triggered significant community concern at the time about a US ad-tech investor's relationship to a privacy product. The 2026 status of that investor relationship needs human verification before this listing publishes; the rationale flags it as an open question rather than treating it as resolved either way. Second, StartMail's own **pricing page is denominated in USD** (Personal $4.99/month annual = $59.88/year; Business $6.99/month annual = $83.88/year) — an unusual choice for a Dutch B.V. and a small but real signal worth surfacing. Combined with the fact that DPA and sub-processors URLs were not directly captured at audit, the score is held at 3/5. Best fit: privacy-conscious EU users who want PGP-capable email under Dutch law with unlimited aliases — and who are willing to weigh the Startpage-group US-investor history. Buyers who want the strongest possible EU-sovereignty posture should prefer Tuta (DE, founder-owned, post-quantum), Mailbox.org (DE, BSI C5), Posteo (DE, anonymous signup) or Proton Mail (CH, Foundation-controlled) — all elsewhere in this directory.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-15).
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API No
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
from €5/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    www.startmail.com/terms-of-service…
    Open ↗
ALTERNATIVES

Alternatives in this category