noKYCme

Case file · Email

Disroot

A Netherlands-based, donation-funded community collective (since 2015) running a fully open-source stack. Sign up with just a username and a deletable verification email - no phone, name or ID - on GDPR soil, with 24-hour logs and Monero accepted. The trade-off is volunteer-run reliability, not privacy.

No-KYC · Level 1
Based
Stichting Disroot.org, Amsterdam, Netherlands
Price
Free (donation-funded); optional paid storage/domain upgrades; Monero + BTC accepted
Reviewed
2026-07-31
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

7.2/10 · No identity required

Disroot is a genuine, honest no-KYC collective: you register with only a username, a password and a verification email that is deleted after approval - no phone, name or ID, ever - it keeps server logs just 24 hours, runs entirely on open-source software, is based in the GDPR-protected Netherlands, and accepts Monero. Its contract is unusually clean, with no discretionary ID clause. The honest limits are the category thesis and the volunteer model: email is stored unencrypted at rest unless you use PGP, federation leaks addressing metadata, there is no independent no-logs audit, and being donation/volunteer-run means no SLA, periodically-closed registration, and cloud E2EE currently disabled. It lands at 7.2/10 - below the audited German leaders, just above Riseup.

What the internet says

2 recurring praises · 3 recurring gripes

Most praised: well-regarded, honest, values-aligned no-kyc collective; eu mecsa 5/5. Most cited downside: volunteer-run: no sla, registration periodically closes.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Jurisdiction, sign-up & encryption.

Jurisdiction
Stichting Disroot.org, Amsterdam, Netherlands (EU/GDPR)
Sign-up needs
Username + password + a verification email (deleted after approval); no phone, name or ID; manual anti-spam approval
KYC trigger
None - no ID ever demanded; manual approval is anti-spam, not identity verification
Encryption
Email plaintext at rest unless the user runs PGP/GnuPG; full-disk encryption on servers; webmail supports OpenPGP; some no-login services are E2E
Provider access
Staff do not read data except for service/abuse needs; no data sale; federation exports addressing metadata; disk-encrypted at rest
Anon. payment
Free tier (no payment required); optional donations/upgrades payable in Monero + BTC (and fiat rails)
Logging
Server logs retained 24 hours then deleted; several no-login services keep no logs
Open source
Yes - runs a fully open-source (FOSS) stack (Nextcloud, XMPP, RainLoop, Akkoma, etc.)
Audited
No independent no-logs audit; EU MECSA 5/5 (a delivery/anti-phishing assessment, not a no-logs audit)
Custom domain
Custom domain linking + storage upgrades (paid); aliases
Free tier
Yes - free, donation-funded
Since
2015

The full read

Our analysis, in plain words.

Disroot is what a values-driven no-KYC email collective should look like: founded in 2015 in Amsterdam, run by a small named team under a Dutch foundation, funded by donations, and built entirely on open-source software. Signing up asks for nothing that identifies you - a username, a password, and a verification email that is deleted once your account is approved. There is no phone, no name, no ID, and - unusually for this niche - no discretionary "we may request identity" clause anywhere in the contract. It keeps server logs for just 24 hours, sits on GDPR soil, and accepts Monero for optional upgrades. The EU’s own MECSA assessment gives it 5/5 for confidential delivery.

Its limits are honest and they are exactly the category thesis plus the volunteer model. Email is stored unencrypted at rest unless you run PGP yourself, and email federation exports addressing metadata off the server - so a lawful Dutch order could reach content and metadata for a non-PGP user; content encryption does not stop metadata, and here it is not even on by default for mail. There is no independent no-logs audit and no transparency report, so the disclosure posture is trust-me rather than evidenced. And being donation/volunteer-run shows up as reliability: no SLA, registration that periodically closes when capacity is tight, and cloud end-to-end encryption currently disabled pending an upstream Nextcloud fix. None of that is a broken promise - there is no deanonymization or handover on record - it is simply the ceiling of a free, community-run, not-zero-access-by-default service. It lands at 7.2/10: genuinely no-KYC and honest, below the audited German leaders (Posteo, Tuta, Mailbox.org), just above the fellow activist collective Riseup. Tier Reviewed, not Verified - MECSA audits delivery, not a no-logs posture.


The score, broken down

How the 7.2 is built.

Privacy 3.8Trust 2.2Reliability 1.3 Headroom 2.7

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

76/100

76 × 50% = 3.8 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

74/100

74 × 30% = 2.2 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

63/100

63 × 20% = 1.3 of 10

Weighted total 7.3 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +7No phone, name or ID; only a username, password and a verification email deleted after approval↗
  • +5Server logs kept only 24 hours; Netherlands/GDPR; full-disk encryption on servers↗
  • +-5Email stored unencrypted at rest unless you use PGP; federation leaks addressing metadata; no independent no-logs audit↗

Trust

  • +6Fully open-source (FOSS) stack; named team + Stichting foundation; clean record since 2015↗
  • +3Honest, non-evasive contract with no discretionary ID clause; EU MECSA 5/5 delivery/anti-phishing↗
  • +-3No independent no-logs audit; no transparency report / warrant canary↗

The fine print, read for you

The clause they bury.

Verbatim — the honest version
“It is not necessary to provide personal information in order to create an account. No phone number or legal name required. [+] Server logs ... are stored for a period of 24 hours after which they are deleted.”

What it meansThis is what an honest no-KYC signup looks like: a username, a password and a verification email that is deleted after your account is approved - no phone, name or ID at any point - plus a genuinely short 24-hour log retention. There is no discretionary "we may request ID" clause anywhere, so nothing blocks the no-KYC posture.

Read the source →
Verbatim — the catch
“Email is stored unencrypted unless the user encrypts it (PGP/GnuPG); federated services require certain data to be shared. [+] end-to-end encryption is currently disabled due to a long-standing bug with the Nextcloud desktop app.”

What it meansThe category thesis in Disroot’s own words: your mail is plaintext at rest unless you run PGP, and email/XMPP federation exports addressing metadata off the server - so a lawful Dutch order could reach content and metadata for non-PGP users. And cloud end-to-end encryption is presently switched off due to an upstream bug. Content encryption doesn’t stop metadata, and here it isn’t even on by default for mail.

Read the source →
Verbatim — the catch
“Disroot reserves the right to suspend accounts used for commercial purposes / financial gain or bulk mail without prior notice, and to remove any content found in violation of applicable law.”

What it meansA without-notice suspension channel exists - but it is scoped to commercial use, spam/bulk mail and illegal content, not to demanding identity, so it does not undercut the no-KYC rating. It is the most likely source of the occasional "Disroot suspended me" report: abuse/ToS enforcement, not deanonymization. (Confirm the exact wording on /tos before quoting.)

Read the source →
KYC trigger threshold

No phone, name or ID at signup or ever - only a username, a password and a verification email that is deleted after approval. A manual human approval step exists, but it is anti-spam, not identity verification, and there is no discretionary "we may request ID" clause. It is level 1 (not 0) because of the persistent recovery-email/username identifier and the curated manual-approval gate.

Policy review — point by point

  • No-identity signup, no ID clause

    No phone/name/ID required; verification email deleted after approval; the contract contains no discretionary "we may request ID" clause. ↗

  • 24-hour logs, GDPR, open-source

    Server logs kept only 24 hours, Netherlands/GDPR jurisdiction, and a fully open-source stack. ↗

  • Not zero-access; federation metadata

    Email is plaintext at rest unless the user runs PGP, and federation exports addressing metadata; cloud E2EE is currently disabled (Nextcloud bug). ↗

  • Without-notice abuse suspension

    Reserves suspension without prior notice for commercial/bulk-mail use and removal of illegal content - scoped to abuse, not an identity demand (confirm exact wording on /tos). ↗

Jurisdiction analysis

Disroot is run by Stichting Disroot.org in Amsterdam under Dutch/EU law (GDPR) - a genuinely privacy-protective jurisdiction, and a real plus over US/Five-Eyes hosts. The honest caveat is technical, not legal: because mail is plaintext at rest unless the user runs PGP and federation leaks metadata, a lawful Dutch order could still reach content and metadata for a non-PGP user - the "private is not anonymous" limit. There is no transparency report to evidence how often, if ever, that has happened.


We keep watching

Incident & policy timeline.

  1. 2015

    Founded as a privacy-services collective

    Disroot was founded in 2015 in Amsterdam by a small named team (Stichting Disroot.org), offering email plus a full suite of open-source services (cloud, XMPP, pads, etc.), funded by community donations.

    source ↗
  2. Ongoing

    Independent EU MECSA 5/5; clean record

    The EU’s MECSA assessment rates Disroot 5/5 for confidential delivery and anti-phishing. No documented data-handover or deanonymization incident is on record. (MECSA is a delivery/security signal, not a no-logs audit.)

    source ↗
  3. Ongoing

    Volunteer-run: no SLA, registration periodically closes

    As a donation/volunteer project, Disroot has no paid SLA, periodically closes registration when capacity is tight, and cloud end-to-end encryption is currently disabled pending an upstream Nextcloud fix. Availability, not privacy, is the soft spot.

    source ↗

The verdict

Where it stands.

Strengths

  • No phone, name or ID; verification email deleted after approval
  • Fully open-source stack; Netherlands/GDPR; 24-hour logs
  • Honest, non-evasive contract with no discretionary ID clause
  • Free (donation-funded); Monero + BTC accepted for upgrades

Trade-offs

  • Email plaintext at rest unless you use PGP; federation leaks metadata
  • No independent no-logs audit; no transparency report
  • Volunteer-run: no SLA, registration periodically closed
  • Cloud E2EE currently disabled (upstream Nextcloud bug); RainLoop webmail flagged
Visit Disroot No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • Well-regarded, honest, values-aligned no-KYC collective; EU MECSA 5/5
  • Fully open-source; custom domain on the free tier; GDPR base

Recurring complaints

  • Volunteer-run: no SLA, registration periodically closes
  • Not zero-access at rest; cloud E2EE currently disabled
  • No independent no-logs audit or transparency report

Strongly positive on privacy/ethos with one consistent caveat: it is "a community project you are joining, not a product you are buying" - support and uptime ride on goodwill, not an SLA. No corroborated deanonymization or handover; occasional account-suspension reports trace to abuse/ToS enforcement, not data disclosure. Synthesized from Disroot’s own policy pages, EU MECSA and PrivacyTools.


Keep exploring

Related lists & categories.


Ask the bureau

Disroot, common questions.

Is Disroot no-KYC?

Yes. Signup needs only a username, a password and a verification email that is deleted after approval - no phone, name or ID ever, and no discretionary "we may request ID" clause. We rate it KYC level 1 (a persistent recovery-email/username identifier plus a manual anti-spam approval step keep it just off level 0).

Is my Disroot email private?

Reasonably, with one big asterisk: your mail is stored unencrypted at rest unless you use PGP, and email federation leaks addressing metadata - so a lawful Dutch order could reach content and metadata for non-PGP users. It keeps only 24-hour logs on GDPR soil and holds no identity, so it is strong on identity privacy, weaker on at-rest/metadata (the category thesis: private is not anonymous).

Why 7.2 and not higher?

Because it is not audited, its mail is not zero-access by default, and it is volunteer-run (no SLA, registration periodically closes, cloud E2EE currently disabled). It is genuinely no-KYC and honest - but it sits below the audited German leaders (Posteo/Tuta/Mailbox) and just above the fellow activist collective Riseup.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.