My Privacy Software Recommendations, 2026 Edition

In 2023, I shared my personal recommendations on good privacy-preserving services to use. Things haven’t changed all that much in 3 years. I still use most of them today and, with perhaps one exception, I expect I will happily continue to use them for the foreseeable future.

Now, I said things haven’t changed much since my last post, and that is mostly true, but I have warmed up quite a bit to self-hosting as an alternative to consuming services from a third party, and privacy has been one of those reasons.

In this post I want to re-examine my current privacy-conscious stack of services, with the addition of a new category I neglected to mention last time: password managers. Then, I will dedicate a few lines to my journey into self-hosting so far, why I’m ditching SaaS for it in some (not all) cases, and where I think I’ll go from here.

But first, let’s not break tradition. Here’s my 2026 privacy services stack in one short table for the busy bods:

CategoryProduct
EmailTuta
Email MaskingFirefox Relay
Cloud File StorageProton Drive
VPNMozilla/Mullvad VPN
BrowserFirefox
Password ManagerBitwarden
Instant MessagingSignal
Operating SystemGNU/Linux (Fedora)

As I mentioned last time, I read Privacy Guides periodically to stay on top of their latest recommendations, and I sometimes pick my favourites from there. Shout out to the Privacy Guides team and the great work they’re doing to educate people on these matters.

Email: Tuta

Tuta (rebranded from Tutanota since my previous post) remain my personal email provider. The biggest privacy and security improvement to their email service since 2023 was the rollout of post-quantum (PQ) cryptography to protect customer data at rest. More providers like Proton Mail are now rolling out their own PQ encryption but Tuta were one of the first to prioritise it.

Tuta have also released improvements to their email client UX, including secure on-device search, and a more effective spam filter system. Spam is a problem I flagged all the way back in 2023. I still get more spam in my inbox than I would like but it is good to see Tuta taking steps to address this problem in recent times.

Email Masking: Firefox Relay

Not much to say on this one that I didn’t cover last time. Mozilla haven’t really shipped any new features that I know of, outside of phone number masking, which is only available in some territories in North America. There is only so much you can do with an email aliasing service, I guess. And perhaps that is a good thing.

All in all, along with their VPN service, I stick to this product as much to support Mozilla financially as it is about privacy. The revenue they generate from products like this is dwarfed by their Google search engine deal, but maybe one day they’ll find the way and the will to turn things around and stand on their own two feet.

Cloud File Storage: Proton Drive

Proton Drive has matured and evolved significantly since I first wrote about them. Proton have continued to invest in this product, offering a few more options to purchase additional storage; they have made mobile media syncing smoother and more reliable, and enhanced how users can access and organise their uploaded videos and photos. They’ve also shipped an online office suite, the privacy-minded version of Office365 if you will.

Besides Proton, Tuta are currently expanding their existing services catalogue (Mail, Calendar and Contacts) with a cloud file storage option called Tuta Drive, which is currently in closed beta. I’m looking forward to trying out this product in the coming months and seeing how it improves in the next few years. I’m not sure it will overtake Proton Drive but it may be a very welcome addition to my set of cloud file hosting services.

VPN: Mozilla/Mullvad VPN

With the proliferation of online content age verification laws in Australia, the UK, California, and soon the EU, VPN usage to circumvent blocks on some websites (even imgur ffs!) has increased dramatically. Thus, picking a trustworthy VPN provider has become more important than ever, to ensure we’re able to browse safely and privately.

Mullvad, and Mozilla VPN as a reseller of their services, continues to be my choice here. Mozilla VPN specifically finally released official support for Flatpaks and RPM distribution of their Linux VPN client, which has made me very happy, as the process of setting up an authenticated Wireguard connection in non-Debian distributions was a bit inconvenient and hacky before.

Web Browsing: Firefox

In my previous post, I named Tor Browser as my private browser recommendation. While it is true that it’s hard to think of a more hardened and private browser than that, I expressed this in a misleading way. I don’t actually use Tor Browser for average internet browsing. I want to correct and clarify this point in this instalment.

As a matter of fact, at the time of that writing, I was still using Google Chrome (yikes) as my default web browser. I switched to Firefox and have been happy with it ever since. It offers me a good balance between convenience, web compatibility and privacy. It is true that Mozilla have added some rather questionable features to it of late, like AI (which can be turned off), but all in all I still think it’s a functional, fast and private browser.

Having said that, I recognise there are solid Firefox forks available that are even more privacy-minded, like LibreWolf. LibreWolf is awesome and if you find it comfortably enables your average browsing habits, I wouldn’t hesitate to recommend it over vanilla Firefox. Nonetheless, perhaps by design, I find LibreWolf introduces certain constraints and compatibility issues to my browsing that I cannot work around, and this is the main reason why I don’t run it. I could see myself revisiting this choice in the future though, so maybe you will see it featured on my next post (how does 2030 sound? ;) ).

Instant Messaging: Signal

Signal continue to live up to their reputation as a trustworthy messaging services operator and advocate for citizens’ privacy rights. Meredith Whittaker, President of the Signal Foundation, signed an open letter to the German government last year, pushing back against the Child Sexual Abuse Regulation (CSAR), aka Chat Control, that is currently being pushed by a significant number of EU legislators.

In the features department, they’ve played it slow but steady, releasing a trickle of important capabilities that have nudged them even closer to becoming a fully private and secure IM platform. These included the early rollout of their own PQ encryption from late 2023, paid secure cloud chat backups, and replacing phone numbers with usernames on users’ public profiles to increase their privacy. Signal have very recently taken this a step further by launching numberless accounts on the Signal Android app beta channel.

I still believe Signal offers the best mix of user friendliness and convenience, privacy and security, and I will continue using it and recommending it for the foreseeable future.

Operating System: Fedora Linux

Similarly to my web browser recommendation, I want to be clearer about the distinction between the best option I know in this category, and what I actually use. Last time I mentioned Tails as the most secure and private way to run Linux, which remains true. However, even though I am a staunch Linux user, I don’t run Tails. I have used Fedora Linux for the better part of a decade now. I even wrote a post hinting at it in this blog 9 years ago.

While Fedora’s design and packaging philosophy is not privacy-centric, Red Hat have followed a more trustworthy and sensible strategy to its stewardship than competitors like Canonical have. Their approach to the ongoing development of Fedora has remained transparent, malleable by community feedback, and they haven’t tried to sneak in any anti-user features on it yet, as far as I know.

My Fedora pick is mostly a matter of preference. GNU/Linux is the best way to make a computer useful these days, if you care about freedom and privacy. There are some distros that do it better than others, but even the worst Linux distro you can find is still going to be superior to the proprietary alternatives.

Password Manager: Bitwarden

Bitwarden is a reputable, America-based open source password manager. You can pay Bitwarden a fee to host your vault for you and your family, or self-host it entirely for free, either using Bitwarden’s official server stack or the much leaner Vaultwarden Rust implementation, which is what the community recommends. If you use Bitwarden Cloud, as I do, you have the option to host your vault on their US or EU servers.

Over the years, Bitwarden have built a strong reputation for being trustworthy, secure (they have passed many third party security audits and obtained various certifications) and respectful of your privacy. UX or performance have never been their strongest suit —their .NET stack is a bit clunky— although they have improved significantly on these fronts over the years. Either way, their users have always accepted a somewhat janky experience as they knew they were getting a robust, accessible, transparent and secure password manager. It was a good deal.

Unfortunately, Bitwarden Inc. have had a string of suspicious and highly questionable decisions over the past year that people are starting to feel alarmed about, myself included. Here are some examples:

Individually, none of these moves necessarily point to the bleak future some people have predicted, but it’s hard not to see the pattern and feel a level of skepticism. Some people are starting to worry that all of this may signal the company’s intent to prepare for a private equity exit in the not so distant future. And we all know how that went for LastPass, right? This is also not helped by the fact that Bitwarden have been pivoting harder to cater to the infinitely more profitable enterprise sector, which may lead to them deprioritising development of their individual plans or even raising their prices further.

Bitwarden received investment from a growth-equity firm called PSG Equity in 2022, so they have already started walking this path. The million-dollar question is, how much further will they go and how much will they sacrifice their users’ needs and the quality of their product in the process? The optimist in me wants to think they’ll find the way to fuel their growth and remain a profitable business in the long term without joining the disgusting wave of enshittification that has plagued the tech industry of late.

This is why I issue my recommendation for Bitwarden with more caution than the services above and why I don’t feel as confident about sticking with them in the long haul. If you’re an existing Bitwarden user like me, you can stay put. I don’t think there’s enough evidence to shop for alternatives yet. The cost of switching is not justified, as all of this is based on speculation. However, if you are not currently using Bitwarden and are considering using them, make this decision with care. Would you be able to accept it if Bitwarden sold out to private equity or another company and the quality and trustworthiness of their product started degrading as a result?

Currently, Bitwarden offer several ways to export your password vault, so a migration to a self-hosted alternative or a different provider altogether may not be too painful. Either way, some people would rather not deal with all this potential hassle. In that case, you are welcome to consider alternatives like Proton Pass, as Proton continue to reaffirm their commitment to putting users over profits, or those suggested by Privacy Guides outside of Bitwarden.

Is self-hosting the final frontier to ultimate privacy?

As I mentioned at the beginning of this post, I have started self-hosting some services, such as my personal Forgejo code hosting instance, or my own Lemmy instance. Privacy hasn’t been the reason that’s pushed me to deploy these services in particular, but the benefits this brings to your privacy are evident: hosting in your own infrastructure better protects your privacy, especially if the technology is open source, which tends to be the case. You can inspect and modify the code and configure the running platform to meet your needs. It runs in your own infrastructure, either a cloud VPS or your own physical hardware (I salute those of you who do the latter), so no-one can store, inspect, analyse, sell or train AI models on your data, activity, and usage patterns.

However, self-hosting is not accessible or cost effective for everyone in all cases. It greatly depends on what you’re trying to self-host, your skill level, access to infrastructure and how much and how frequently you use the service. Self-hosting can sometimes be the overall cheaper alternative, but not always. For example, you may naively think Tuta’s monthly €3 fee to give you 20GB of storage to run and host your emails is a rip-off and that you can do better if you just set up your own mail server. Let’s think through the list of things you’d need here…

Firstly, you would need to provision an SMTP/IMAP server at home for this to be the case, because even the smallest VPS you can find won’t cost you less than €5 a month, especially when you add in cloud server storage, a reserved IPv4 address, taxes, and so on. Assuming you can add your email domain to an existing DNS zone you manage, that should be it for infrastructure costs. But what about the configuration of the mail server itself? What about the spam filters? Even Tuta themselves have been unable to crack this one — what makes you think you’ll be more successful than them?

Oh, and how bothered are you that all the emails you send out may end up straight in people’s junk folder? Have fun setting up DMARC, DKIM and SPF, and slowly building a good reputation! Not to mention ongoing maintenance, patching, and all the activities you’ll need to do regularly to keep your email servers functional and secure. Especially for such a critical service we depend on so much these days, you really have to know what you’re doing and be really confident before committing to something like that.

My email example here is an extreme case, granted. No-one in their right mind thinks running your own mail server is simple and cheap, all things considered, but you could extend this example to other services, such as your password manager, VPN, etc., without that much squinting. Operating a service on your own shouldn’t be done out of dogma. It is not something you can really set up in a weekend and forget about, not if you depend on that server being up and functional at all times, at least. To be fair though, there are genuine scenarios where self-hosting is a no-brainer, where the benefits you get from it outweigh the costs. And this is what I’ve been finding of late.

So where do I stand with self-hosting these days? I have enjoyed the process so far of setting up and maintaining a few of my own VPS’s to take over various tasks I used to outsource to SaaS providers. I used to be much more reluctant to do this in the past, thinking it would be hard, cumbersome, and expensive, but for the services I’ve rolled out so far, that hasn’t been the case. I won’t rule out expanding my stack of self-hosted services in the future but I will be doing so with care and by really exploring the pros and cons of doing so versus just going with a fully managed solution.

Conclusion

On the whole, my list of privacy-aware service recommendations has barely changed since my last update. I was a bit unclear about a couple of them and I hope this new publication fixes that. Other alternatives have appeared alongside my picks too, but none of them have provided anything fresh or important enough to tempt me to switch.

All of these services I use now have matured and receded into the background, getting out of the way as I go about my day, without feeling as watchful and paranoid as I do when I’m forced to use their compromised counterparts.

Becoming more experienced and confident in self-hosting has opened a new legitimate option to me, in those cases where my current provider breaches my trust, as could happen with Bitwarden, and I am unable to find a worthy replacement. It will remain an option, not a new default though, as it doesn’t come without its costs.

Wouldn’t it be nice to live in a world where privacy can be taken for granted and it’s something we can stop fighting tooth and nail for, every single day? One can only dream, but some of these services do let me savour that dream for a little while at least.

Back to top ↑

Do you have any questions, comments or feedback about this article to share with me or the world?

You can message me on Mastodon. You can also reach out to me in a couple of other ways, if you'd prefer. I would love to hear your thoughts either way!

Articles from friends and people I find interesting

Making Suites

Hello, loves! Going in, the plan is to work on separate suites of connected rooms. I expect some issues. Some design thinking, no new code. You may recall the BuildStepper, an object that holds a list of dungeon-creating actions and exe…

via ronjeffries.com September 3, 2026

AI in Linux

The role of AI tools (LLMs, mainly) in Linux is under discussion, or it was, until Linus Torvalds “put his foot down” in support of the use of AI in Linux kernel development.I can identify two major ways in which AI is used for Linux kernel deve…

via Drew DeVault's blog July 23, 2026

Concurrent, atomic MSI hash tables

Readers will be familiar with Mask-Step-Index (MSI) hash tables, a technique for building fast, open-addressed hash tables in a dozen lines of code. If multiple threads or processes access an MSI table with at least one still inserting elements, care m…

via null program May 6, 2026

Generated by openring