

I’m guessing his/her point involves the location of its incorporation. Any company in the “five eyes” zone can be forced to release details about its users to any member state. One must evaluate whether NordVPN keeps anything more than a few hours - days tops - to decide if it is “safe enough”. I was worried enough about this particular point that I chose a VPN that is not in any way beholden to five eyes or the fourteen eyes, which is a similar agreement.
Proton caught heat because of its release of information to the local law enforcement recently. While Switzerland is not part of the five eyes, it does have its own laws requiring a reveal in certain circumstances. I forgot the details, but I think they had an IP address that had not yet been wiped from cache, and that was enough to pinpoint the hackers being sought.
In truth, there’s no sure way to be sure. One still must trust the organization is both honest and competent enough to properly wipe any residual information. No matter who it is, some amount of information has to be in cache for some time in order to be able to deliver the service, and there also needs something tracking the workings of the system to ensure it isn’t overloaded or to find opportunities to improve it.
Tutonota is German, which is part of the already full on surveilance state.