Email Dossier

Tuta

End-to-end-encrypted email and calendar from Germany, open-source and ad-free.

Alternative to: gmail , google workspace

Headquarters
Tutao GmbH, Hannover, Germany
Jurisdiction
German law; subject to GDPR and German data-protection regulation
Ownership
Founder-led; no publicly disclosed controlling non-EU parent
Data location
Data stored in ISO 27001 certified data centres in Germany (self-declared)
Category
email
Country
DE

The evidence

Dimension Finding Region Confidence Source
Jurisdiction
Governing law German law; subject to GDPR and German data-protection regulation EU / EEA Verified 2026-06-17 ↗
Legal HQ Tutao GmbH, Hannover, Germany EU / EEA Verified 2026-06-17 ↗
Independence · Control
Ownership Founder-led; no publicly disclosed controlling non-EU parent EU / EEA Claimed 2026-06-17 ↗
Independence · Operational
Data location Data stored in ISO 27001 certified data centres in Germany (self-declared) EU / EEA Claimed 2026-06-17 ↗
Operations Not established Unknown no source
Suppliers Not established Unknown no source
Independence · Openness
Tech & portability Open-source clients (GPLv3) covering web, Android, iOS, Windows, macOS, Linux; data export available EU / EEA Verified 2026-06-17 ↗
Trust (informational)
Security E2E encryption (AES-256, post-quantum Kyber-1024); independent pentest by SySS GmbH; GDPR-compliant EU / EEA Verified 2026-06-17 ↗
Sustainability 100% renewable electricity in own servers and office since March 2019 EU / EEA Claimed 2026-06-17 ↗

Coverage 83% · 4 of 7 dimensions verified · How is this scored?

Cite: FindInEurope, "Tuta" company dossier, Sovereignty Score 91, Partial, SEAL-1, model v2.1.0, verified 2026-06-17.

The full picture

What is Tuta, and why does the name keep changing

If you signed up before November 2023, your inbox still says Tutanota somewhere in the settings menu. Same company, servers, and encryption; only the name changed. Tutao GmbH rebranded its email service to Tuta that month, folding the old tutanota.com domain into the shorter tuta.com. Nothing about the switch changed who runs it, where it sits, or what law governs it, which is the part that actually matters if you’re comparing it to Gmail or Google Workspace.

Tuta is an end-to-end encrypted email and calendar service built by a small German company, open source since 2014, with a paid file-storage product still in closed beta. It encrypts more than most competitors bother with, message bodies plus subject lines, attachments, calendar entries, even the search index. It also does the thing most secure-email pitches gloss over, which is that being encrypted and being a full Google Workspace replacement are two different claims, and Tuta is only the first one.

Who owns it, and why that’s the whole pitch

Tutao GmbH was founded in 2011 in Hanover by Arne Möhle and Matthias Pfau, who met studying at a technical college there. The company itself says it remains wholly owned by the two founders, with no outside investors and no acquisition since, funded by subscription revenue rather than venture money, a structure the company confirmed directly in response to funding questions from users on Reddit and again in a public statement addressing ownership rumors on the company blog. That’s a claim from the company, not something you can independently verify against a public shareholder register the way you can with a listed firm, but it lines up with what’s publicly known: no funding rounds on record, no reported acquisition, and a hiring pattern (the team passed 40 employees in June 2026) that looks like organic growth off a freemium subscription base rather than investor-fueled scaling.

The company also took a public grant along the way. The German state and the University of Wuppertal together put roughly €2 million into developing Tuta’s post-quantum cloud storage product, now called Tuta Drive. Public co-funding for a specific R&D line isn’t the same as state ownership or control, and there’s no indication it comes with strings attached to governance, but it’s worth knowing the encrypted-drive project didn’t come entirely out of subscription fees.

Which law it answers to

Tuta is registered as Tutao GmbH with the commercial register at the Amtsgericht Hannover, and it operates under German law, meaning German data protection statutes and the GDPR, not US law and not the UK’s. That’s a real, checkable fact rather than a marketing line: it’s the kind of jurisdictional anchor that determines who can compel Tuta to hand over data, and under what process, a question Gmail and Google Workspace answer very differently given Google’s exposure to the US CLOUD Act regardless of where the servers physically sit.

German jurisdiction isn’t a blank check, though, and Tuta’s own history makes that clear. In December 2020, a court in Cologne ordered Tutanota to monitor future incoming unencrypted mail on one specific account tied to an extortion investigation, a ruling reported at the time by TechDirt and by other outlets. The order didn’t touch the account’s encrypted mail or any other user’s inbox, and it required a valid domestic warrant to reach even that far, which is a meaningfully different threat model than a foreign intelligence request under a mutual legal assistance treaty, but it’s a useful corrective against reading “based in Germany” as “untouchable.” Three years later, an ex-RCMP intelligence officer on trial in Canada claimed under oath that Tutanota had been a law-enforcement “storefront” set up to lure criminals, a claim covered by CBC News and picked up widely from there. No supporting evidence was produced at the hearing, and Tuta issued a detailed denial pointing to its published client code as proof there’s no room for a hidden backdoor, a rebuttal you can read in full on the company’s own blog. The allegation exists; no evidence for it was ever produced.

Germany’s own alliance membership is the other wrinkle skeptics raise. As a Five Eyes and Fourteen Eyes-adjacent jurisdiction, German authorities do participate in intelligence-sharing arrangements that don’t apply to, say, a service based somewhere outside those networks, a point CyberNews raised directly in its review of the service. It’s a fair caveat for anyone modeling nation-state threats specifically; it doesn’t change the GDPR and German-court baseline that governs everyday requests.

Where the data sits

Tuta says it runs its own servers in ISO 27001 certified data centers located in Germany, a claim stated on its privacy policy and repeated on both its pricing and business pages. That’s the company’s own description of its infrastructure rather than something verified by a third-party audit published for public review, so treat it as self-declared, not certified fact you can check against an independent register. It’s a materially different setup from Gmail, where mail can traverse Google’s global infrastructure regardless of where the account holder is based.

On the environmental side, Tuta says it has run its own servers and offices on 100% renewable electricity since March 2019, a transition timed to employee participation in Fridays for Future protests according to its own sustainability page and confirmed independently by Wikipedia’s sourcing of the announcement. Again, self-declared, but consistent across the company’s own materials and third-party coverage over several years.

What you actually get, and what it costs

The product line is narrower than “Google Workspace alternative” implies. There’s Tuta Mail, the original encrypted inbox; Tuta Calendar, spun out as its own standalone app in October 2024; and Tuta Drive, an encrypted cloud storage product still in closed beta as of April 2026 with no public release date yet, per Wikipedia. There’s no document editor, no spreadsheet tool, no video-calling product. If your team lives in Docs and Meet, Tuta doesn’t replace that; it replaces the inbox sitting next to it.

Pricing follows the shape you’d expect from a subscription-funded privacy company: a free tier with a small storage allowance and a fixed number of aliases and labels, then two or three paid personal tiers that scale up storage, custom domains, and alias counts, and a separate set of business tiers built around per-user pricing, an admin console, and an uptime SLA. The exact euro figures on Tuta’s personal and business pricing pages move over time, so check those directly rather than trusting a number reprinted here; the shape that matters is that everything, free tier included, ships with the same end-to-end encryption, and the paid tiers are buying storage and convenience features, not a stronger security model.

How it differs from Gmail and Google Workspace, concretely

The headline difference is encryption by default. Tuta encrypts mailbox contents end-to-end so that, per the company’s own description of its architecture confirmed in Wikipedia’s technical summary, Tuta itself cannot read a user’s stored mail. Gmail encrypts data in transit and at rest, but Google’s infrastructure can and does process message content for spam filtering, and historically for ad targeting before that practice was scaled back; the mail sits in a form Google’s systems can read. That’s the practical gap between “encrypted” as a checkbox and “encrypted so the provider is locked out,” and it’s the reason Tuta shows up on privacy-focused comparison sites at all.

The second difference is the client model. Tuta’s apps across web, Android, iOS, Windows, macOS, and Linux are open source under the GPLv3, a claim you can check yourself against the published source repository rather than take on faith. Gmail’s client code is closed. Before Tuta’s public release, the company says it also had its apps put through an independent penetration test by SySS GmbH, a German firm that specializes in this kind of testing, according to Tuta’s own open source page. Open source doesn’t make a service unhackable, and one pre-launch pentest from years ago isn’t a standing audit program, but between the published code and that outside test, the encryption claims are checkable by anyone with the time to look, rather than resting entirely on the vendor’s word the way Gmail’s do.

Security-wise, the two services aim at different threats. Tuta’s security page describes a zero-knowledge design in which subject lines, calendars, and contacts are encrypted alongside message bodies, and the search index that would normally require server-side access to your plaintext is instead built and searched locally on your device. Newer accounts use TutaCrypt, a hybrid protocol combining X25519 elliptic-curve key exchange with the post-quantum Kyber-1024 algorithm, which the company rolled out in March 2024 and migrated older accounts onto by the end of that year. Gmail’s TLS-based transport encryption protects mail in transit and Google’s infrastructure is hardened against outside attackers, but it was never designed to keep Google itself from reading the mail. That’s a genuinely different design goal, aimed at a different threat than the one Tuta is built around.

The third, less flattering difference is protocol support. Tuta doesn’t offer native IMAP or CalDAV access, which is why it shipped Thunderbird add-ons in February 2026 specifically to work around those limitations, according to CyberInsider’s coverage of the release. Gmail supports IMAP natively, so you can point Outlook, Apple Mail, or any standard client at a Gmail account and it just works. With Tuta, you’re generally in Tuta’s own apps, or using an add-on built to bridge the gap, not a universal open standard. CyberNews flagged the same missing-IMAP, missing-PGP combination as a real limitation in its otherwise favorable review, and it’s a fair one: if your workflow depends on a specific desktop client or PGP interoperability with contacts outside Tuta, budget time to check whether that still works before you migrate.

Who it actually fits

Tuta’s own customer list leans toward organizations where confidentiality is the actual job: press freedom groups like the European Centre for Press and Media Freedom, human rights NGOs, and accounting and engineering firms citing GDPR compliance as the deciding factor. Individuals who want a European, ad-free, open-source inbox and don’t need it to double as a document and meeting platform are the other obvious fit; independent reviews from PCMag and TechRadar describe the free tier as genuinely usable day to day, and Tuta reports more than 10 million users as of mid-2023, a reasonable proxy for how many people found the free tier good enough to stick with.

It fits less well for teams whose real requirement is Google Workspace itself, meaning shared Docs, Sheets, and Meet alongside mail, since Tuta simply doesn’t build those tools. It’s also a weaker fit for anyone who needs IMAP access from a specific email client they’re not willing to give up, or who exchanges PGP-encrypted mail routinely with people who aren’t on Tuta. And for threat models that specifically worry about Fourteen Eyes intelligence sharing rather than commercial data mining, Germany’s alliance membership is a real, if narrow, consideration to weigh against the GDPR and open-source protections on the other side of the ledger.

A couple of housekeeping details matter for anyone actually switching. Tuta deletes free accounts after six months of inactivity, a policy the company frames as both a security measure and a way of keeping the free tier sustainable, documented in its FAQ; Gmail has no equivalent inactivity clock on that timescale. And Tuta has been blocked in Egypt since October 2019 and in Russia since February 2020, for reasons neither government has officially explained, which is worth knowing if you or your correspondents are reachable from either country.

None of this replaces checking the live evidence. The dossier above tracks exactly what’s verified against a public register versus what rests on Tuta’s own word, updated as sources change; this profile is the narrative version of that same evidence, not a substitute for it.

Sources

Profile updated 5 July 2026