{
  "slug": "riseup",
  "category": "email-providers",
  "name": "Riseup",
  "description": "Email, mailing list and VPN service run by an autonomous tech collective in Seattle for activists and social movements. Accounts need an invite, and the service is funded by donations.",
  "website": "https://riseup.net",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 59,
  "coverage": 100,
  "summary": "Riseup scores 59 out of 100 (grade D) on the email providers criteria. It meets 9 of 19 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, encrypted mailbox storage, open protocols, sign up without personal data, IMAP support, POP3 support and SMTP submission. It partly meets open source, transparency report and security headers. It does not meet independent audit, tells users about requests, end-to-end encryption, custom domains, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
  "url": "https://privacyratings.com/email-providers/riseup/",
  "markdown": "https://privacyratings.com/email-providers/riseup/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://0xacab.org/riseuplabs",
      "note": "The service runs on free software and some of Riseup's own tools are published, but the full service setup is not public."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://riseup.net/en/about-us/policy/privacy-policy",
      "note": "No third-party cookies or tracking of any kind, and no IP addresses are kept."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://riseup.net/en/donate",
      "note": "Funded by donations. No ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://riseup.net/en/canary",
      "note": "Publishes a signed warrant canary updated four times a year, but no request counts."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=riseup.net&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=riseup.net",
      "note": "Grade B (75/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee": {
      "title": "End-to-end encryption",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "No built-in end-to-end encryption. OpenPGP only works in third-party apps."
    },
    "encrypted_storage": {
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://riseup.net/en/email",
      "note": "Mail is stored encrypted per user and can only be unlocked with the user's password. Older accounts must opt in."
    },
    "open_protocols": {
      "title": "Open protocols",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://riseup.net/en/email/clients",
      "note": "IMAP, POP3 and SMTP work with any client."
    },
    "custom_domains": {
      "title": "Custom domains",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "Not supported. Addresses use riseup.net."
    },
    "anonymous_signup": {
      "title": "Sign up without personal data",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://riseup.net/en/about-us/policy/privacy-policy",
      "note": "Sign-up needs an invite code, but no phone number or email address. A reset email is optional."
    },
    "mail_standards": {
      "title": "Email security standards",
      "weight": 2,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "imap_standards": {
      "title": "IMAP support",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "mail.riseup.net:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
    },
    "pop3_standards": {
      "title": "POP3 support",
      "weight": 1,
      "answer": "yes",
      "evidence": null,
      "note": "mail.riseup.net:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL."
    },
    "smtp_standards": {
      "title": "SMTP submission",
      "weight": 2,
      "answer": "yes",
      "evidence": null,
      "note": "mail.riseup.net:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
    },
    "transport_security": {
      "title": "Mail transport security",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Passes: SPF, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all. Missing: DMARC none."
    },
    "srs": {
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on SRS for forwarded mail."
    },
    "arc": {
      "title": "ARC sealing",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published documentation on ARC signing or validation."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T11:00:18.386Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}