Case file · Email
Disroot
A Netherlands-based, donation-funded community collective (since 2015) running a fully open-source stack. Sign up with just a username and a deletable verification email - no phone, name or ID - on GDPR soil, with 24-hour logs and Monero accepted. The trade-off is volunteer-run reliability, not privacy.
The systematized overview
The bureau vs the internet.
7.2/10 · No identity required
Disroot is a genuine, honest no-KYC collective: you register with only a username, a password and a verification email that is deleted after approval - no phone, name or ID, ever - it keeps server logs just 24 hours, runs entirely on open-source software, is based in the GDPR-protected Netherlands, and accepts Monero. Its contract is unusually clean, with no discretionary ID clause. The honest limits are the category thesis and the volunteer model: email is stored unencrypted at rest unless you use PGP, federation leaks addressing metadata, there is no independent no-logs audit, and being donation/volunteer-run means no SLA, periodically-closed registration, and cloud E2EE currently disabled. It lands at 7.2/10 - below the audited German leaders, just above Riseup.
2 recurring praises · 3 recurring gripes
Most praised: well-regarded, honest, values-aligned no-kyc collective; eu mecsa 5/5. Most cited downside: volunteer-run: no sla, registration periodically closes.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Jurisdiction, sign-up & encryption.
- Jurisdiction
- Stichting Disroot.org, Amsterdam, Netherlands (EU/GDPR)
- Sign-up needs
- Username + password + a verification email (deleted after approval); no phone, name or ID; manual anti-spam approval
- KYC trigger
- None - no ID ever demanded; manual approval is anti-spam, not identity verification
- Encryption
- Email plaintext at rest unless the user runs PGP/GnuPG; full-disk encryption on servers; webmail supports OpenPGP; some no-login services are E2E
- Provider access
- Staff do not read data except for service/abuse needs; no data sale; federation exports addressing metadata; disk-encrypted at rest
- Anon. payment
- Free tier (no payment required); optional donations/upgrades payable in Monero + BTC (and fiat rails)
- Logging
- Server logs retained 24 hours then deleted; several no-login services keep no logs
- Open source
- Yes - runs a fully open-source (FOSS) stack (Nextcloud, XMPP, RainLoop, Akkoma, etc.)
- Audited
- No independent no-logs audit; EU MECSA 5/5 (a delivery/anti-phishing assessment, not a no-logs audit)
- Custom domain
- Custom domain linking + storage upgrades (paid); aliases
- Free tier
- Yes - free, donation-funded
- Since
- 2015
The full read
Our analysis, in plain words.
Disroot is what a values-driven no-KYC email collective should look like: founded in 2015 in Amsterdam, run by a small named team under a Dutch foundation, funded by donations, and built entirely on open-source software. Signing up asks for nothing that identifies you - a username, a password, and a verification email that is deleted once your account is approved. There is no phone, no name, no ID, and - unusually for this niche - no discretionary "we may request identity" clause anywhere in the contract. It keeps server logs for just 24 hours, sits on GDPR soil, and accepts Monero for optional upgrades. The EU’s own MECSA assessment gives it 5/5 for confidential delivery.
Its limits are honest and they are exactly the category thesis plus the volunteer model. Email is stored unencrypted at rest unless you run PGP yourself, and email federation exports addressing metadata off the server - so a lawful Dutch order could reach content and metadata for a non-PGP user; content encryption does not stop metadata, and here it is not even on by default for mail. There is no independent no-logs audit and no transparency report, so the disclosure posture is trust-me rather than evidenced. And being donation/volunteer-run shows up as reliability: no SLA, registration that periodically closes when capacity is tight, and cloud end-to-end encryption currently disabled pending an upstream Nextcloud fix. None of that is a broken promise - there is no deanonymization or handover on record - it is simply the ceiling of a free, community-run, not-zero-access-by-default service. It lands at 7.2/10: genuinely no-KYC and honest, below the audited German leaders (Posteo, Tuta, Mailbox.org), just above the fellow activist collective Riseup. Tier Reviewed, not Verified - MECSA audits delivery, not a no-logs posture.
The score, broken down
How the 7.2 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
76 × 50% = 3.8 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
74 × 30% = 2.2 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
63 × 20% = 1.3 of 10
Weighted total 7.3 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
- +7No phone, name or ID; only a username, password and a verification email deleted after approval↗
- +5Server logs kept only 24 hours; Netherlands/GDPR; full-disk encryption on servers↗
- +-5Email stored unencrypted at rest unless you use PGP; federation leaks addressing metadata; no independent no-logs audit↗
The fine print, read for you
The clause they bury.
“It is not necessary to provide personal information in order to create an account. No phone number or legal name required. [+] Server logs ... are stored for a period of 24 hours after which they are deleted.”
What it meansThis is what an honest no-KYC signup looks like: a username, a password and a verification email that is deleted after your account is approved - no phone, name or ID at any point - plus a genuinely short 24-hour log retention. There is no discretionary "we may request ID" clause anywhere, so nothing blocks the no-KYC posture.
Read the source →“Email is stored unencrypted unless the user encrypts it (PGP/GnuPG); federated services require certain data to be shared. [+] end-to-end encryption is currently disabled due to a long-standing bug with the Nextcloud desktop app.”
What it meansThe category thesis in Disroot’s own words: your mail is plaintext at rest unless you run PGP, and email/XMPP federation exports addressing metadata off the server - so a lawful Dutch order could reach content and metadata for non-PGP users. And cloud end-to-end encryption is presently switched off due to an upstream bug. Content encryption doesn’t stop metadata, and here it isn’t even on by default for mail.
Read the source →“Disroot reserves the right to suspend accounts used for commercial purposes / financial gain or bulk mail without prior notice, and to remove any content found in violation of applicable law.”
What it meansA without-notice suspension channel exists - but it is scoped to commercial use, spam/bulk mail and illegal content, not to demanding identity, so it does not undercut the no-KYC rating. It is the most likely source of the occasional "Disroot suspended me" report: abuse/ToS enforcement, not deanonymization. (Confirm the exact wording on /tos before quoting.)
Read the source →No phone, name or ID at signup or ever - only a username, a password and a verification email that is deleted after approval. A manual human approval step exists, but it is anti-spam, not identity verification, and there is no discretionary "we may request ID" clause. It is level 1 (not 0) because of the persistent recovery-email/username identifier and the curated manual-approval gate.
Policy review — point by point
-
No-identity signup, no ID clause
No phone/name/ID required; verification email deleted after approval; the contract contains no discretionary "we may request ID" clause. ↗
-
24-hour logs, GDPR, open-source
Server logs kept only 24 hours, Netherlands/GDPR jurisdiction, and a fully open-source stack. ↗
-
Not zero-access; federation metadata
Email is plaintext at rest unless the user runs PGP, and federation exports addressing metadata; cloud E2EE is currently disabled (Nextcloud bug). ↗
-
Without-notice abuse suspension
Reserves suspension without prior notice for commercial/bulk-mail use and removal of illegal content - scoped to abuse, not an identity demand (confirm exact wording on /tos). ↗
Disroot is run by Stichting Disroot.org in Amsterdam under Dutch/EU law (GDPR) - a genuinely privacy-protective jurisdiction, and a real plus over US/Five-Eyes hosts. The honest caveat is technical, not legal: because mail is plaintext at rest unless the user runs PGP and federation leaks metadata, a lawful Dutch order could still reach content and metadata for a non-PGP user - the "private is not anonymous" limit. There is no transparency report to evidence how often, if ever, that has happened.
We keep watching
Incident & policy timeline.
- 2015
Founded as a privacy-services collective
Disroot was founded in 2015 in Amsterdam by a small named team (Stichting Disroot.org), offering email plus a full suite of open-source services (cloud, XMPP, pads, etc.), funded by community donations.
source ↗ - Ongoing
Independent EU MECSA 5/5; clean record
The EU’s MECSA assessment rates Disroot 5/5 for confidential delivery and anti-phishing. No documented data-handover or deanonymization incident is on record. (MECSA is a delivery/security signal, not a no-logs audit.)
source ↗ - Ongoing
Volunteer-run: no SLA, registration periodically closes
As a donation/volunteer project, Disroot has no paid SLA, periodically closes registration when capacity is tight, and cloud end-to-end encryption is currently disabled pending an upstream Nextcloud fix. Availability, not privacy, is the soft spot.
source ↗
The verdict
Where it stands.
Strengths
- No phone, name or ID; verification email deleted after approval
- Fully open-source stack; Netherlands/GDPR; 24-hour logs
- Honest, non-evasive contract with no discretionary ID clause
- Free (donation-funded); Monero + BTC accepted for upgrades
Trade-offs
- Email plaintext at rest unless you use PGP; federation leaks metadata
- No independent no-logs audit; no transparency report
- Volunteer-run: no SLA, registration periodically closed
- Cloud E2EE currently disabled (upstream Nextcloud bug); RainLoop webmail flagged
Across the internet
What reviewers report.
Consistently praised
- Well-regarded, honest, values-aligned no-KYC collective; EU MECSA 5/5
- Fully open-source; custom domain on the free tier; GDPR base
Recurring complaints
- Volunteer-run: no SLA, registration periodically closes
- Not zero-access at rest; cloud E2EE currently disabled
- No independent no-logs audit or transparency report
Strongly positive on privacy/ethos with one consistent caveat: it is "a community project you are joining, not a product you are buying" - support and uptime ride on goodwill, not an SLA. No corroborated deanonymization or handover; occasional account-suspension reports trace to abuse/ToS enforcement, not data disclosure. Synthesized from Disroot’s own policy pages, EU MECSA and PrivacyTools.
Keep exploring
Related lists & categories.
Ask the bureau
Disroot, common questions.
Is Disroot no-KYC?
Yes. Signup needs only a username, a password and a verification email that is deleted after approval - no phone, name or ID ever, and no discretionary "we may request ID" clause. We rate it KYC level 1 (a persistent recovery-email/username identifier plus a manual anti-spam approval step keep it just off level 0).
Is my Disroot email private?
Reasonably, with one big asterisk: your mail is stored unencrypted at rest unless you use PGP, and email federation leaks addressing metadata - so a lawful Dutch order could reach content and metadata for non-PGP users. It keeps only 24-hour logs on GDPR soil and holds no identity, so it is strong on identity privacy, weaker on at-rest/metadata (the category thesis: private is not anonymous).
Why 7.2 and not higher?
Because it is not audited, its mail is not zero-access by default, and it is volunteer-run (no SLA, registration periodically closes, cloud E2EE currently disabled). It is genuinely no-KYC and honest - but it sits below the audited German leaders (Posteo/Tuta/Mailbox) and just above the fellow activist collective Riseup.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.