When people think about email privacy, they usually think about encryption.
Encryption is important—but it’s only one piece of the puzzle.
A less discussed question is:
Who actually controls the infrastructure where your email lives?
The answer matters because, in most countries, companies that operate email services have legal obligations to respond to valid requests from courts and government agencies.
This article isn’t about criticizing those laws or suggesting they shouldn’t exist. Law enforcement agencies play an essential role in investigating crime, and every legitimate technology company must comply with applicable law.
Instead, our goal is to explain how the system works, what the numbers look like in practice, and why infrastructure ownership is an important architectural consideration.
Governments Request User Data Every Day
Google is one of the few technology companies that publicly publishes detailed statistics about government requests for user information.
According to Google’s Transparency Report, governments around the world now submit more than 300,000 legal requests every six months, covering close to 750,000 user accounts. Google publishes these statistics twice a year, country by country, together with its disclosure rate.
Some recent figures from Google’s Global Transparency Report include:
| Reporting Period | Government Requests | Accounts Affected | Google Disclosed Some Data |
|---|---|---|---|
| Jul–Dec 2024 | 245,715 | 536,413 | 83% |
| Jan–Jun 2025 | 287,014 | 664,767 | 82% |
| Jul–Dec 2025 | 304,915 | 748,475 | 84% |
Those are global totals from the report’s own downloadable dataset, summed across every country and legal process. Preservation requests are excluded, since they ask a provider to retain data rather than hand it over; the disclosure rate is weighted by the number of requests in each country.
These percentages do not mean Google automatically complies with every request. Rather, they indicate that after reviewing each request, Google disclosed at least some responsive information in roughly four out of five cases.
The trend over time is the clearer signal. Google has published this data every six months since 2009, and both the number of requests and the number of accounts they cover have risen in almost every reporting period since:
Providers Don’t Give Governments Direct Access
A common misconception is that governments have “backdoor” access to email providers.
Google explicitly states that this is not the case.
According to Google’s published legal process documentation:
- every request is reviewed by lawyers;
- requests must satisfy applicable law;
- overly broad requests may be narrowed or challenged;
- governments do not receive direct access to user accounts.
This legal review process exists to balance legitimate investigative needs with users’ privacy rights.
What Information Can Be Requested?
The answer depends on the legal authority involved.
Google explains that different legal processes permit access to different categories of information, including:
- subscriber information;
- recovery email addresses;
- phone numbers;
- IP address history;
- login timestamps;
- account metadata;
- billing information (where applicable);
- email content, when legally authorized.
Not every request authorizes access to every category of data.
Transparency Reports Matter
Transparency reports provide an unusually detailed view into how often governments seek user information.
Without them, users would have very little visibility into:
- how frequently requests occur;
- which countries issue them;
- how many accounts are involved;
- how providers respond.
Google’s Transparency Report is one of the most comprehensive public datasets available, and many other companies—including Microsoft, Apple, Meta, and GitHub—publish similar reports.
The Architecture Matters
Most people choose an email provider based on storage limits, spam filtering, or price.
A more fundamental question is:
Who operates the email server?
- You
- Email provider
- Provider-owned infrastructure
The provider owns the infrastructure, operates the mail server, stores your mailbox, and is the legal entity that receives government requests.
- You
- Your cloud account
- Your email server
The infrastructure belongs to you. cripta.to automates the deployment and management; it is not the ongoing operator of your mail server.
With a traditional hosted email service, the provider owns the infrastructure, operates the mail server, stores your mailbox, and is the legal entity that receives government requests.
With cripta.to, the model is different.
cripta.to deploys a production-ready email server into your own cloud account.
The infrastructure belongs to you—not to cripta.to.
cripta.to is the software platform that automates deployment and management; it is not the ongoing operator of your email infrastructure.
This distinction changes the operational model:
- your cloud resources remain under your control;
- your email server runs in your own environment;
- cripta.to does not host your mailbox as a centralized email provider.
Of course, operating your own infrastructure does not exempt anyone from applicable laws or valid legal orders. Every cloud provider and every jurisdiction has its own legal framework.
The difference is architectural rather than legal: you operate the infrastructure instead of delegating that responsibility to a third-party email provider.
Why We Built cripta.to
At cripta.to, we believe users should understand not only how their email is encrypted, but also where it is hosted and who controls it.
Infrastructure ownership is often overlooked in discussions about privacy.
For many organizations and individuals, controlling the environment where email is processed and stored is an important design choice—not because it places them outside the law, but because it gives them greater operational independence and transparency.
We believe informed users make better decisions.
That’s why we encourage everyone—not just cripta.to users—to read transparency reports published by major technology companies. They offer a rare and valuable window into how digital services interact with legal systems around the world.
Sources
- Google Transparency Report – Requests for User Information
- Google – Requests for User Information FAQ
- Google Transparency Report Overview
- Download Transparency Report data — the figures in the table above are computed from
google-global-user-data-requests.csvin that download.