Mailo vs Tuta

Compare Mailo and Tuta on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Gmail, Microsoft 365, Outlook.com

Logo: Mailo

Mailo

France· Email Services

Needs review

Shortlist Mailo when you want French-entity freemium webmail with classic IMAP/EAS clients, integrated calendar/cloud, supervised Mailo Junior for kids, or Pro custom domains for SMEs—without US Big Tech accounts. Skip when you need default zero-knowledge E2EE, open-source/self-host, or a full Workspace-class suite; consider Tuta, Proton Mail, or Infomaniak kMail instead.

France-hosted (claimed)Freemium webmailMailo JuniorIMAP / ActiveSyncPro custom domainsOptional PGP (server-side)
Logo: Tuta

Tuta

Germany· Email Services

Needs review

Shortlist when you need default end-to-end encrypted mail, calendar, and contacts under German law with post-quantum TutaCrypt and official multi-platform apps. Skip when teams must keep Outlook/Thunderbird via IMAP or need a full M365/Workspace suite—consider Proton Mail (Bridge) or mailbox.org instead.

Default mailbox E2EETutaCrypt post-quantumEU-operated (Germany)Open-source clientsDE data centers (claimed)No IMAP (by design)
Mailo vs Tuta: Snapshot
FeatureLogo: MailoMailoLogo: TutaTuta
Country of originFranceGermany
CategoryEmail ServicesEmail Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersFranceGermany
Legal entityMAILO SAS (capital €75,000; RCS Créteil 851585547; VAT FR44851585547)Tutao GmbH (HRB 208014, Hanover)
Governing lawFrench law (terms of use)German law / GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyVendor states user personal data and content are stored/processed on servers in France; specialised French host centre (who-we-are); website hosted by Ecritel, Arradon, France. Named third parties: Verifone/Paybox (payment email), PayPal option, Gandi/Netim (domains), Sirdata + ad agencies (free-tier ads), optional Rainbow video and OnlyOffice. Full mail DC/backup subprocessor list not published.Vendor states mailbox data is stored end-to-end encrypted on Tutao-operated servers in ISO 27001-certified data centers in Germany. No AWS/GCP/Azure primary hosting named on official security/privacy pages. Privacy statement discloses payment processing via PayPal (Europe) and banks for card/SEPA; no comprehensive public subprocessor list found for ops tools.
Summary

French freemium webmail and Mail&Cloud suite (MAILO SAS): email, calendar, cloud disk, Mailo Junior for children, and Pro custom domains—hosted in France, proprietary SaaS.

German end-to-end encrypted email, calendar, and contacts from Tutao GmbH in Hanover—with post-quantum TutaCrypt, open-source clients, and freemium personal plus business plans.

Tags
At a glance: Mailo vs Tuta
At a glanceLogo: MailoMailoLogo: TutaTuta
HQ / entityMAILO SAS, France (RCS Créteil 851585547)Not listed
Hosting (claimed)Servers in France; website host Ecritel (FR)Not listed
ModelFreemium SaaS (Free / Premium / Pro / Junior / Edu)Not listed
Open sourceNo (proprietary MailObject®)Clients GPLv3 on GitHub; no productized self-host
Self-hostNoNot listed
Encryption defaultTLS + optional server-side PGP (not ZK E2EE)Not listed
HQNot listedHanover, Germany (Tutao GmbH)
ProductNot listedEncrypted email, calendar, contacts (SaaS)
HostingNot listedOwn servers in ISO 27001 data centers in Germany (vendor claim)
ProtocolsNot listedNo IMAP/SMTP client access; official apps only
CryptoNot listedTutaCrypt hybrid (Kyber-1024 + X25519 + AES-256) for new accounts
Commercial modelNot listedFreemium personal + paid personal/business (no ads)
Key capabilities: Mailo vs Tuta
Key capabilitiesLogo: MailoMailoLogo: TutaTuta
France-hosted (claimed)YesNot listed
Freemium webmailYesNot listed
Mailo JuniorYesNot listed
IMAP / ActiveSyncYesNot listed
Pro custom domainsYesNot listed
Optional PGP (server-side)YesNot listed
Default mailbox E2EENot listedYes
TutaCrypt post-quantumNot listedYes
EU-operated (Germany)Not listedYes
Open-source clientsNot listedYes
DE data centers (claimed)Not listedYes
No IMAP (by design)Not listedYes

Mailo

  • French-hosted webmail with IMAP, EAS, and classic protocols

    Webmail plus IMAP4 for clients, Exchange ActiveSync for mobile sync, and POP3 on paid tiers; SMTP relay with account credentials. Vendor states mail and content stay on servers in France. Free tier is ad-supported with lower quotas; Premium unlocks POP3, more aliases, and larger mail/cloud caps. Suits teams that need standard desktop/mobile clients rather than a closed proprietary app only.

  • Mailo Junior supervised email for children

    Child accounts (about ages 6–14) only exchange mail with contacts a parent or teacher validates. Age-adapted mini/junior UIs, no ads on Junior, optional promotion to a standard account while keeping the address. Separate Junior mobile apps. Unique fit for families and schools versus generic consumer mail.

  • Calendar, virtual disk, and open sync protocols

    Shared calendars and tasks, address book, photo albums, and a virtual disk for files with WebDAV/FTP access. CalDAV and CardDAV for external clients. Premium+ can unlock OnlyOffice in-browser editing. Better as an all-in-one Mail&Cloud for SMEs/families than bare IMAP-only privacy mail.

  • Mailo Pro spaces: custom domains and mutualised storage

    Pro Start/5/Modulo style plans share mail+cloud quota across accounts, support custom domains (register, transfer, or declare external), distribution lists, mailbox sharing, resource calendars, and manager tooling. Priority Pro hotline with documented acknowledgement and restoration targets for Pro subscriptions. Aimed at TPE/PME, associations, and municipalities—not a full Google Workspace clone.

  • Optional server-side PGP and account security controls

    Built-in PGP/MIME encrypt and sign in the webmail as a trusted third party (keys managed on Mailo for multi-device convenience). Two-factor authentication, application passwords, connection history, and guardianship-style access options. Not zero-knowledge E2EE by default—use external client crypto if the provider must never hold keys.

Tuta

  • Default E2EE for mail, subjects, and attachments

    Between Tuta users, messages encrypt automatically including subject lines, bodies, and attachments. External recipients can use a shared password for end-to-end threads without installing software. Contacts and calendars use the same zero-access model; only delivery metadata (addresses, timestamps) stays readable by design.

  • TutaCrypt post-quantum hybrid cryptography

    New accounts use TutaCrypt: Kyber-1024 KEM plus X25519 ECDH with AES-256, targeting harvest-now-decrypt-later risks. Protocol details are published; existing accounts migrate as key rotation rolls out. Tuta intentionally avoids PGP so subjects and non-mail features can stay encrypted and algorithms can be upgraded in-product.

  • Zero-knowledge calendar with private reminders

    Calendar events—including times, titles, locations, and attendees—are end-to-end encrypted. Reminders are pushed as encrypted payloads and fired locally so servers are not told when an event starts. Sharing stays encrypted; invites can go out via mail, optionally password-protected for externals.

  • Open-source multi-platform clients (no IMAP)

    Web, Android (Play and F-Droid), iOS, Windows, macOS, and Linux clients are published under GPLv3 on GitHub. Desktop builds are signed for verification. There is no IMAP/SMTP bridge: third-party mail apps cannot connect, which preserves encryption at rest but forces a client switch for Outlook/Thunderbird holdouts.

  • Business domains, admin console, and whitelabel

    Paid business plans add custom domains, aliases, shared mailboxes, multi-admin roles, password/2FA resets, catch-all, templates, and optional branding/login on your own site. Vendor-stated uptime SLA and a GDPR order-processing agreement support B2B procurement—confirm current plan matrix on tuta.com.

Assurance & compliance: Mailo vs Tuta
Assurance & complianceLogo: MailoMailoLogo: TutaTuta
Independent security / no-logs audit
Not found

Charter claims no commercial reading of messages; automated AV/spam scanning on servers. No public third-party audit PDF found.

Vendor claimed

Vendor states SySS GmbH penetration testing before public release; not a continuously published annual no-logs audit PDF on the marketing site.

ISO 27001
Not found

No ISO 27001 claim found on legal/security/primary pages researched.

Partial

Official pages claim data centers are ISO 27001 certified; does not clearly establish a public Tutao GmbH organizational ISO 27001 certificate.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced on public product pages.

Not found

No SOC 2/3 report located on security, business, or privacy pages.

GDPR / EU data protection
Vendor claimed

French controller; privacy rules cite GDPR and French correspondence secrecy; DPO at dpo@mailo.com; France storage claim.

Vendor claimed

German controller Tutao GmbH; privacy statement cites GDPR; DPO published; DE storage claimed.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent / France-claimed mail hosting, but Verifone and PayPal (US-group) on payment path; full infra subprocessors unpublished. Assessment only—not legal advice.

Partial

EU entity, no known US parent, primary mailbox hosting claimed as own DE servers—not AWS/GCP/Azure. Payment may use PayPal (Europe). Assessment is low exposure for content with residual billing/processor unknowns; not a vendor 'safe' claim. Not legal advice.

Data processing agreement (B2B)
Not found

Privacy rules and terms cover processing; no standalone public B2B DPA download found—request via DPO or Pro channel.

Vendor claimed

Security/business materials state an Order Processing Agreement (Auftragsverarbeitung) is provided for GDPR; obtain signed version via sales—no public self-serve DPA URL confirmed.

EU AI Act
Not applicable

Traditional email/cloud suite; not marketed as an AI system product.

Not applicable

Encrypted email/calendar product; vendor states it does not plan AI that processes user communications for model training.

Considerations & known limitations: Mailo vs Tuta
Considerations & known limitationsLogo: MailoMailoLogo: TutaTuta
PGP is server-side trusted third party
Medium

Webmail PGP holds keys on Mailo for multi-device use. Provider-access risk differs from zero-knowledge E2EE defaults at Tuta/Proton. Use external crypto if that is a hard requirement.

Not listed
Incomplete public subprocessor inventory
Medium

Privacy rules name payments, domains, and free-tier ads, but not a full list of mail storage, backup, or anti-spam infrastructure vendors. Request annex for B2B risk review.

Not listed
US-group payment processors
Low

Checkout shares email with Verifone/Paybox; PayPal is also offered. Limited to billing path per privacy rules, but relevant to CLOUD Act diligence.

Not listed
Free tier third-party advertising
Low

Mailo Free shows ad banners via agencies under IAB TCF consent (Sirdata CMP). Premium removes ads. Ad cookies stated as not tied to Mailo profile.

Not listed
No public ISO/SOC or independent security audit
Medium

Security posture relies on first-party statements and internal measures. Procurement teams may need questionnaires or NDA evidence.

Not listed
Free accounts deleted after inactivity
Low

Mailo Free unused for 365 days can be deleted with content loss. Premium/Pro have different retention rules—plan backups and renewals.

Not listed
No IMAP/SMTP third-party clientsNot listed
High

Desktop and mobile holdouts cannot stay on Outlook/Thunderbird/Apple Mail. Plan full client migration or pick a standards-based alternative.

Weaker protection to non-Tuta recipientsNot listed
Medium

Without a shared password, external mail is ordinary SMTP (TLS in transit). Only Tuta-to-Tuta and password-protected external threads are true E2EE.

Hosted service, not on-prem mailNot listed
Medium

Open-source clients help inspectability, but mailboxes still depend on Tutao's German SaaS backend, uptime, and German legal process.

Data-center ISO vs company ISMSNot listed
Low

ISO 27001 wording refers to data centers. Do not tick 'vendor ISO 27001 certified' on questionnaires without the actual Tutao certificate.

Limited public subprocessor inventoryNot listed
Medium

Privacy policy covers payments (e.g. PayPal Europe) but lacks a detailed live subprocessor register. Request the DPA annex for DPIA completeness.

German court orders on accessible dataNot listed
Low

Transparency reports show regular German requests. Stored E2EE content stays undecryptable by Tutao; real-time monitoring can expose newly arriving unencrypted SMTP mail. Align expectations with counsel.

Fit

Mailo

Best fit when

  • EU individuals and families wanting French-hosted mail with calendar and cloud disk in one account
  • Parents/schools needing supervised child email (Mailo Junior) with contact allow-lists
  • French SMEs, associations, and municipalities needing custom domains and mutualised Pro storage
  • Teams that depend on IMAP, EAS, CalDAV, CardDAV, or WebDAV rather than a locked-in app
  • Buyers who accept freemium ads on free tier or low-cost Premium rather than pure prepaid anonymity mail

Poor fit when

  • Orgs that require default end-to-end encryption with zero-access provider architecture
  • Buyers that need open-source server code or official self-hosting
  • Enterprises needing SOC 2 / ISO 27001 evidence already published on a trust centre
  • Heavy Google Workspace / Microsoft 365 collaboration suites (docs/drive ecosystem depth)

Consider instead when

  • When: You need zero-knowledge / default E2EE webmail

    Consider: Tuta or Proton Mail

    Mailo PGP is optional and server-side trusted third party

  • When: You want German privacy mail with different encryption/product posture

    Consider: Posteo or mailbox.org

    Compare protocols, storage bundles, and business features side by side

  • When: You need Swiss multi-product cloud with mail plus broader suite

    Consider: Infomaniak kMail

    Different country stack and product breadth

  • When: You need US Big Tech ecosystem integration at any cost

    Consider: Gmail or Microsoft 365 / Outlook.com

    Trade EU entity and France residency claims for ecosystem depth

Tuta

Best fit when

  • Teams that will standardize on Tuta's official web/mobile/desktop clients for default zero-access email
  • Orgs prioritizing subject-line encryption, encrypted calendar, and post-quantum hybrid crypto under German jurisdiction
  • SMEs needing custom domains, aliases, shared mailboxes, and multi-admin controls without running their own mail servers
  • Journalists, NGOs, and privacy-led departments that value F-Droid builds, no Google Push dependency, and ad-free operation
  • Buyers who want open-source client auditability plus a freemium path for personal trial before business seats

Poor fit when

  • Hard requirement for IMAP/SMTP in Outlook, Thunderbird, Apple Mail, or third-party automation
  • On-prem / customer-operated mail server mandates (no productized self-host for the backend)
  • Workflows that depend on first-class PGP or S/MIME interoperability with external partners
  • Primary need is full Google Workspace or Microsoft 365 collaboration (Drive, Meet, deep Outlook) rather than encrypted mail first

Consider instead when

  • When: Users must keep desktop IMAP clients or need Bridge-style Outlook integration

    Consider: Proton Mail (Bridge on paid plans) or mailbox.org / Posteo / Soverin

    Those options trade Tuta's automatic subject E2EE model for standards-based access

  • When: You need a broader German digital workplace (Drive, Office, video) with optional PGP

    Consider: mailbox.org

    Stronger suite breadth; different default encryption depth than Tuta's full zero-access mailbox

  • When: Swiss jurisdiction and multi-product privacy suite (VPN, drive, pass) matter more than German HQ

    Consider: Proton Mail

    Compare Bridge, ecosystem lock-in, and published cert posture side by side

  • When: Belgian OpenPGP-centric suite with browser crypto and classic protocols is preferred

    Consider: Mailfence

    Different encryption UX (PGP-oriented) versus Tuta's automatic proprietary stack

Open questions for due diligence

Mailo

  • Will Mailo sign a GDPR Article 28 DPA with a full subprocessor and transfer annex for Pro customers?
  • What is the named primary data-centre operator and backup/DR location beyond the France and Ecritel website-host statements?
  • Is there an independent penetration test, ISO 27001 roadmap, or customer-available security whitepaper?
  • Where is Rainbow (video) and OnlyOffice data processed relative to the France mail claim?
  • Current UGAP / public procurement listing status for French public buyers?

Tuta

  • Will Tutao provide a current signed AVV/DPA with a full subprocessor list (DNS, billing, support, CDN if any)?
  • Is there a current organizational ISO 27001 or SOC 2 report for Tutao GmbH, or only facility-level data-center certification?
  • What is the documented status of TutaCrypt key rotation for all legacy accounts in your tenant?
  • Are any US-group cloud services used for backups, DNS, or support tooling beyond payment processors named in the privacy statement?
  • For business rollout: migration tooling limits (EML/MBOX import on desktop) and dual-running period with legacy IMAP hosts?