I wouldn’t trust mozilla with my data. Once the google funding runs out they quickly need to find new money sources and with their recent actions, I already know where they will look for them.
No. It’s an inherit compromice you have to deal with. At least with email hosting. There are services where you can proof that no one was listening in but with email thats not possible.
Yeah, thats the issue. At some point you have to trust the provider or host yourself. I know from friends who worked at my email provider that they actually encrypt and not save it but thats a luxury not everyone has.
If they still hold the private key, your mails aren’t encrypted. And even if it’s the case you still have to trust them that they don’t save the plaintext email somewhere else before they run tbeir encryption.
One of the design goals is that they don’t have a user database, so governments etc can’t knock down their door demanding anything.
By using phone numbers your “contacts” are not on their servers but local on your phone.
Pretty easy. It’s called a tar pit.