Self-hosting vs trusting a provider
I run some of my own infrastructure out of a couple of servers in my apartment in Singapore, and I pay other companies to run the rest. Both setups are normal. The real question isn’t which one is “more private,” it’s who’s holding the bag when something breaks, and what they can see about you while everything’s working fine. That’s the whole self-hosting vs trusting a provider decision, and almost nobody thinks about it until a company they relied on gets acquired, shuts down, or gets breached.
Every tool you use for email, file storage, passwords, or messaging is really a choice between two setups: you run the software yourself, on hardware you control, or someone else runs it and you log in. Most people default to the second option without ever weighing it against the first. If you’ve read my piece on building a threat model, this is the practical version of that question applied to one specific decision.
what it is
self-hosting means installing, configuring, and running a piece of software yourself, usually on a VPS you rent from a company like Hetzner or a machine sitting in a closet. You own the root password. You own the uptime. You own the backups.
Trusting a provider means signing up for a hosted version of the same function and letting someone else carry all of that. Gmail instead of running your own mail server. Dropbox instead of a self-hosted Nextcloud instance. A hosted password manager instead of running Vaultwarden yourself on a $5-a-month box.
Take email specifically. Proton Mail and Tutanota are both “trust a provider” choices, they just differ in who the provider is and how much they can technically see. Running your own mail server on a static IP is the self-hosted alternative, and it’s one I’d talk most people out of. More on why below.
how it works
On the self-hosted side, the mechanism is straightforward: you install the software, point a domain at it, get a TLS certificate (most people use Let’s Encrypt now, it’s free and automated), and then you’re responsible for every patch, every port you leave open, and every backup that has to actually restore correctly, not just run without erroring out. If you get hacked, it’s your server logs, your incident, your 2am.
On the provider side, the mechanism flips. You’re trusting their access controls, their encryption model, and their legal jurisdiction instead of your own firewall rules. Some of that is verifiable, look at whether a provider publishes how their encryption actually works, whether it’s end-to-end or just encrypted-at-rest with the provider holding the keys. Some of it you’re taking on faith.
Jurisdiction matters more than most people assume. A US-based provider can be compelled to hand over data under laws like the CLOUD Act, even for data stored outside the US. That’s part of why providers based in Switzerland or Germany market themselves the way they do.
The same tradeoff shows up outside privacy tools too. People running Llama or Mistral models locally instead of calling an API are making an identical bet: more control and no third party seeing their prompts, in exchange for owning the GPU, the uptime, and the security patches themselves. AI Tool Gazette has covered that side of it if you want the same framework applied to AI instead of email. Start from your own threat model either way, because the right answer depends entirely on who you’re actually worried about.
why it matters
This isn’t an abstract debate. It shows up in four ways that actually cost people time, money, or data.
- a provider you trust can disappear. Google killed Google Reader, Stadia, and a long list of other products most users assumed were permanent. If your files, backups, or messages live only in their system, you’re exposed the day they decide to sunset it, sometimes with as little as 30 or 60 days notice. I wrote about what to actually do when that happens in getting your data out of a company that’s closing.
- a provider is a bigger target than you are. LastPass got breached in 2022, and attackers eventually cracked into stolen encrypted vault backups. One company holding millions of accounts is a better payoff for an attacker than your one self-hosted box nobody’s heard of, which cuts both ways: providers get attacked more, but they also usually have better security teams than you do.
- self-hosting has a real maintenance cost, and it’s not small. I let a self-hosted Nextcloud instance go unpatched for about three months in 2023 because I was busy with other things. Nothing happened, but I got lucky, not smart. If you’re not going to actually apply security updates, a well-run provider beats a neglected self-hosted box every time.
- jurisdiction and legal exposure differ by provider and by country, and that’s before you factor in whether you trust your own government more or less than a foreign one. This part is genuinely personal to your situation, not a one-size answer.
common misconceptions
A few wrong ideas keep showing up in comments and DMs.
- self-hosting means total privacy. wrong, your ISP still sees your traffic if it’s not encrypted, and a self-hosted server with a misconfigured firewall is easier to find than you’d think. Security researchers scan the whole internet with tools like Shodan looking for exposed databases and admin panels people forgot to lock down.
- providers can never be trusted. also wrong. A provider that publishes its encryption model, gets audited, and has a track record beats a self-hosted box you never patch. Trust isn’t binary, it’s a spectrum you evaluate case by case.
- self-hosting requires you to be a sysadmin. less true than it used to be. Tools like Nextcloud’s all-in-one installer or Proxmox make the initial setup fairly approachable. What doesn’t get easier is owning the failure when something breaks at 2am.
- if I self-host, nobody can subpoena my data. also wrong. If you’re the one running the server, you’re also the one who gets the subpoena or the search warrant directly, instead of a provider fighting it (or not) on your behalf. That’s not automatically better.
where to go from here
A few places to go next, depending on which side of this you’re leaning toward.
- if you’re leaning toward trusting a provider for email, compare the two most-recommended options in Proton Mail vs Tutanota in 2026.
- if you’re leaning toward self-hosting, start with the thing that has the least room for error: setting up a password manager the right way, whether you run it yourself or pay for a hosted vault.
- before you pick either side, sort out what you’re actually defending against in threat model for normal people.
- if you’re weighing a self-run VPN against a paid one, it’s the same question wearing a different hat, see VPN myths that cost money.
For everything else I’ve written, the full archive is at the blog.
Written by Xavier Fok
disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-16.