# Remove Skiff

**URL:** https://discuss.privacyguides.net/t/remove-skiff/16228
**Category:** Tool Suggestions
**Tags:** completed
**Created:** 2024-01-15T02:33:16Z
**Posts:** 88

## Post 1 by @privacycarrot — 2024-01-15T02:33:16Z

The [original thread](https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411) gives me vibes of being controversial and Skiff representatives of being too pushy. Now, the suggestion was added, and my question is was that too premature?

People start to report [privacy issues](https://www.grepular.com/Skiff_Emails_Various_Privacy_Failures) with Skiff which their CEO is dismissive of. This is in the light of them claiming to pass [multiple security audits](https://skiff.com/transparency) while still not publishing any of them.

They misleadingly claim to be open-source while being [only source available](https://news.ycombinator.com/item?id=37230039). Also see this [GitHub issue](https://github.com/skiff-org/skiff-apps/issues/94). While I understand PG doesn’t have a requirement for listing open-source services only, I don’t understand why this didn’t raise any red flags during the review.

Even on this forum some people complain about Skiff inappropriately [using recovery details for marketing](https://discuss.privacyguides.net/t/still-receiving-spam-from-skiff-on-recovery-email-address/16083). The same issue was raised during the submission review, but they still didn’t bother to change this.

Now, a lot of people use PG as an authoritative place to find privacy-respecting services, and I hope they understand they are responsible for recommendations they make. Skiff may be a good addition to the site at some point but I think it’s not today, and situations like this negatively affect PG’s reputation.

---

## Post 2 by @exaCORE — 2024-01-15T03:08:35Z

The privacy issues linked are pretty minor imo. Also the remote content blocking would break emails for a lot of people iirc so it makes sense that its off by default. A lot of privacy focussed email providers dont have perfect defaults for that reason (eg on Mailbox, the encryption is disabled by default)

---

## Post 3 by @privacycarrot — 2024-01-15T03:21:35Z

Depends on how you define a minor issue. I don’t think IP leak is a minor issue. Leaking read receipt is depends, but this is not I expect when using a privacy-focused email. I also believe auditors should have caught and reported that.

Anyway, there’s more than just leaking the IP as you can see in the original post.

---

## Post 4 by @FlipSid — 2024-01-15T03:31:35Z

Another privacy issue:

> [@Still receiving spam from Skiff on recovery email address](https://discuss.privacyguides.net/t/still-receiving-spam-from-skiff-on-recovery-email-address/16083):
>
> I had given my gmail account as recovery mail for my skiff account months ago. I know they supposedly had fixed the issue where spams were being sent to recovery email addresses but.. I still keep receiving spam. Very disappointing. [Screenshot\_20240108-133805]

---

## Post 5 by @anon21489307 — 2024-01-15T03:35:03Z

IMO, open source or source available license is not matter much for this kind of services. Since we will have to use the services on their server regardless, forking (for commercial purpose) would be meaningless. And it would not be recommendable to use (paid) clients from third-party packagers. Therefore, having the source available should be enough to verify the security and privacy aspect of the services.

From my point of view, Skiff services are not _intentionally_ endanger users security and privacy. However, they definitely feel amateurish, combing with the stupid decision to do marketing campaigns through users’ recovery email.

If I have to complain about their services, it would be Skiff Mail. I am barely able to read my emails most of the time, either unreadable text due to text/background color rendering issues, or the background colors are totally off (emails from Steam). They have a lot of technical issues that need to be fixed.

My primary concern pertains to the inability of Skiff Mail to render properly. I don’t know anymore whether my decision to leave Gmail was correct, given that Skiff Mail, which is the core of their services, is currently in this state.

* * *

Nonetheless, I don’t think adding Skiff will negatively affect PG’s reputation, until it’s proven otherwise that Skiff is against privacy focus users. For example, I believe that Proton Calendar’s situation is much worse, which really affects users’ trust to the services/company overall.

* * *

> [@privacycarrot](#):
>
> I don’t think IP leak is a minor issue.

In the source article:

> ### Update 2023-Aug-29
> 
> They have fixed the IP address leak on iOS. No sign of users being informed of their exposure. Other issues remain.

---

## Post 6 by @privacycarrot — 2024-01-15T03:50:11Z

> [@anon21489307](#):
>
> IMO, open source or source available license is not matter much for this kind of services. Since we will have to use the services on their server regardless, forking (for commercial purpose) would be meaningless. And it would not be recommendable to use (paid) clients from third-party packagers. Therefore, having the source available should be enough to verify the security and privacy aspect of the services.

The issue is not open source vs source available, the issue is they claim something that is not true. When it comes to privacy-respecting services, trust is important, and being dishonest on the home page do not help to gain it at all. Having PG publicity approve this and recommend such services only damages its reputation.

> [@anon21489307](#):
>
> From my point of view, Skiff services are not _intentionally_ endanger users security and privacy. However, they definitely feel amateurish, combing with the stupid decision to do marketing campaigns through users’ recovery email.

I agree they may not do this intentionally, but it doesn’t make this any better. Don’t forget that users who complain about Skiff on this forum most probably started using it based on PG’s recommendation.

> [@anon21489307](#):
>
> I believe that Proton Calendar’s situation is much worse, which really affects users’ trust to the services/company overall.

Could you please elaborate?

> [@anon21489307](#):
>
> In the source article:
> 
> > ### Update 2023-Aug-29
> > 
> > They have fixed the IP address leak on iOS. No sign of users being informed of their exposure. Other issues remain.

I don’t see any postmortem nor problem acknowledgements for affected users. They just decided to sweep it under the rug. This is not the behavior I expect from a privacy-respecting service.

---

## Post 7 by @Reset0609 — 2024-01-15T03:52:54Z

> [@anon21489307](#):
>
> IMO, open source or source available license is not matter much for this kind of services. Since we will have to use the services on their server regardless, forking (for commercial purpose) would be meaningless.

Agreed. There’s the honesty and hence trustworthiness question though. Its like Vivaldi claiming their browser is 95% open source because the Chromium base, which they largely do not make, is open source and you can see the rest of the code anyway. Yeah, still not open source though, you dont do it by percentages…

---

## Post 8 by @anon21489307 — 2024-01-15T03:54:32Z

> [@privacycarrot](#):
>
> Could you please elaborate?

Proton Calendar, which used to have the source opened, now archived the source on its repo since 2021. See: [GitHub - ProtonMail/proton-calendar: Proton Calendar built with React.](https://github.com/ProtonMail/proton-calendar)

Why would they even do this is beyond my understanding, since they sell service, not the client itself.

---

## Post 9 by @privacycarrot — 2024-01-15T04:00:11Z

Calendar source code is in the monorepo: [WebClients/applications/calendar at main · ProtonMail/WebClients · GitHub](https://github.com/ProtonMail/WebClients/tree/main/applications/calendar)

---

## Post 10 by @anon21489307 — 2024-01-15T04:03:27Z

Only for the web client, doesn’t it? Where’s the source for their mobile clients?

---

## Post 11 by @privacycarrot — 2024-01-15T04:08:58Z

You have a point when it comes to mobile apps, but their web apps are all available and open source. I also believe PG recommends their web client too as they link to it and to its source code.

I don’t see how it makes Skiff’s case any better though.

---

## Post 12 by @anon21489307 — 2024-01-15T04:31:08Z

> [@privacycarrot](#):
>
> their web apps are all available and open source.

Except that most probably don’t use Proton Calendar on the web on mobile platforms.

> [@privacycarrot](#):
>
> I also believe PG recommends their web client too as they link to it and to its source code.

Not all the users who use Proton Calendar are PG readers, hence irrelevant and shouldn’t be used as an excuse for its close source mobile clients.

Moreover, you should know that there are Google Play and App Store badges for the close source calendar clients on [Proton Calendar official website](https://proton.me/calendar). I believe, Proton considers the apps to be the official way to use their services on mobile platforms.

> [@privacycarrot](#):
>
> I don’t see how it makes Skiff’s case any better though.

Skiff makes their source available for the public to see every nook of their code, nothing to hide - zero trust. Proton Calendar issue, on the other hand, is not a technical issue like most of the Skiff issues. They’ve closed the source for years for no apparent reason. If you think their issues are on the same magnitude, I have nothing more to say :sweat_smile:

---

## Post 13 by @privacycarrot — 2024-01-15T04:37:20Z

I don’t want to derail this thread into something not related to the concerns I posted in the top post, so if you think PG need to make changes to Proton Calendar recommendation, feel free to create another thread. If you want my opinion on it, you can also tag me there.

---

## Post 14 by @anon21489307 — 2024-01-15T04:47:55Z

> [@privacycarrot](#):
>
> if you think PG need to make changes to Proton Calendar recommendation, feel free to create another thread.

I don’t want to change PG’s recommendation (I have never said anything like that).

I just compared Proton Calendar’s case to Skiff’s cases that you think would affect their users’ trust, and also PG’s reputation. I picked up the case as an example that I believe it’s much worse. That’s all.

---

## Post 15 by @privacycarrot — 2024-01-15T04:59:05Z

> [@anon21489307](#):
>
> I just compared Proton Calendar’s case to Skiff’s cases that you think would affect their users’ trust, and also PG’s reputation. I picked up the case as an example that I believe it’s much worse. That’s all.

I don’t see a thread from Proton employers on this forum which push to add their services ignoring concerns made on said thread. When I open the linked source code for Proton Calendar I see it’s GPL licensed which is an open source license as Proton claims on their website. I don’t see Proton using recovery emails for marketing purposes. I also don’t see Proton hiding auditing reports. You link to an archived repo, saying they made Calendar closed source while they just moved the code to a monorepo

So I think your example is not exactly relevant.

---

## Post 16 by @anon21489307 — 2024-01-15T05:02:04Z

> [@privacycarrot](#):
>
> they just moved the code to a monorepo

Again, where’s Proton Calendar’s mobile clients source code?

If you can’t find the source, you can’t say they moved the code to another repo. That’s not true and misleading.

---

## Post 17 by @moonwriting — 2024-01-15T10:40:13Z

I agree. Also, Skiff’s marketing has [recently](https://discuss.techlore.tech/t/unraveling-proton-vs-tuta-marketing-feud/6644/2) been giving out some serious red flags as they have spread out disinformation while attacking Proton. We can’t even solely blame their marketing department for this because one of these blog posts has been written by Andrew Milich himself. I think this kind of behaviour is unacceptable, and could warrant their removal from PG.

---

## Post 18 by @OhNoes — 2024-01-15T12:17:07Z

Not sure if this is the best place to share, but I recently noticed their [transparency page](https://skiff.com/transparency) has changed as well. The “latest reports” part which was regularly updated with “no reports” has been completely removed.

See an [archived version](https://web.archive.org/web/20231229220829/https://skiff.com/transparency) here.

I actually like the service and use it with a custom domain, so I am somewhat worried what’s going on.

---

## Post 19 by @cXcRDR836XGCsggPowVD3cLpUr — 2024-01-15T15:03:59Z

Would it be possible to assume they have been served with an NSL if the transparency page has largely disappeared? I would imagine that’s their version of a warrant canary. :thinking::thinking:

---

## Post 20 by @ph00lt0 — 2024-01-15T16:45:48Z

Just to second that Skiff has never corrected their false statements about GDPR compliance. I have never deemded this provider mature enough.

We should really consider to tighten the requirements to avoid situations like this. But the question than becomes what should be the criteria? What can we objectively look at to see the difference or is this all gut feeling?

---

## Post 21 by @cXcRDR836XGCsggPowVD3cLpUr — 2024-01-15T16:59:43Z

Only a suggestion but PG could put a potential new addition on like a watch list for 6-12 months and see if they truly uphold the values of being a ‘privacy first’ product. If they fail the standards then they can be removed. Tuta and Proton get enough crap thrown at them but at least they listen and adjust their approach accordingly.

I completely agree with the GDPR sentiment.

That alone should’ve kept them off PG’s list and Skiffs attitude towards privacy first leaves a lot to be desired. I feel like a lot of the time any issue thrown at them they pretty much respond with ‘It’s not a bug but a feature’ lol

---

## Post 22 by @ph00lt0 — 2024-01-15T17:01:45Z

Well not being GDPR complaint isn’t necessary a problem for US citizens if at least privacy uphold. I jusst take issue with the false promise that could lead to trouble for smaller companies who do not know to do due diligence.

---

## Post 23 by @ph00lt0 — 2024-01-15T17:04:42Z

I like your suggestion of a new/debute label. Actually that corresponds with a different suggestion that was once made to make it clearer to see what is new. The counter argument was that this would add maintenance. I suggested back then to add an _added on_ date field. Which could be used to show the new label for a certain time that way it doesn’t need to be removed manually.

---

## Post 24 by @cXcRDR836XGCsggPowVD3cLpUr — 2024-01-15T17:30:38Z

I see hmm that would create more maintenance but I wouldn’t consider that a downside as the community has been fantastic at finding flaws in the products we use today and we can then open the discussion further.

Hmm perhaps PG could explore the label option or even do a pilot test on an extremely small number of the most popular products?

---

## Post 25 by @privacycarrot — 2024-01-16T14:18:55Z

> [@ph00lt0](#):
>
> But the question than becomes what should be the criteria? What can we objectively look at to see the difference or is this all gut feeling?

It would be a good idea to be less keen on adding recommendations which are suggested by the service representatives given the obvious conflict of interest. Some of them may just use this as a free PR opportunity to bait more users. For example: [Skiff - Private, encrypted, secure email - 10 GB free](https://skiff.com/blog/skiff-on-privacyguides).

My first thought when I read this article was “did they also buy PG?”. I’m sure I’m not the only one who’s aware of the PrivacyTools situation and feel discomfort reading articles like this.

---

## Post 26 by @ph00lt0 — 2024-01-16T14:33:03Z

Perhaps you are right. I do really appreciate them answering questions from the community and improving the service though. I see that as a very positive outcome of the discussions.

About the post on their website. I understand they are proud of it. Nothing wrong with that. They really had a long breath to get listed. Regardless of what we think I understand they were super excited to get listed.

---

## Post 27 by @anon21489307 — 2024-01-16T15:00:53Z

I would rather see them on the community forum like this than a review website. I don’t see this as a conflict of interest. The criteria for getting listed is specified by the community anyway. If being listed here is very important for them, they might even have to fix their services to meet our criteria, which would benefit a lot of users.

---

## Post 28 by @privacycarrot — 2024-01-17T01:00:29Z

I’d agree with both of you if we assume a good faith on their side, but it’s hard to given their track record so far.

---

## Post 29 by @Ex3cute — 2024-01-20T20:48:47Z

I don’t believe Skiff _for now_ because of mentioned above privacy issues and extremely unclear marketing. IMHO for now you _can_ use them but I wouldn’t recommend using them for anything important

---

## Post 30 by @Screwdriver — 2024-01-24T14:46:51Z

This seems like a major issue…If you change your password, Skiff does not log out your other sessions. Even rebooting keeps your other apps logged in.

[Thread on Reddit discussing the issue.](https://www.reddit.com/r/Skiff/comments/19e1baj/major_security_flaw_skiff_fails_to_log_out_a/)

---

## Post 31 by @anonymous127 — 2024-02-01T15:47:18Z

I’m honestly surprised there hasn’t been a team response to this. The things mentioned seem pretty bad to me, but I guess they aren’t explicitly breaking any of the criteria, just being a bit shady.

Though I think this comment from them in the above mentioned thread is interesting: [Reddit - The heart of the internet](https://www.reddit.com/r/Skiff/comments/19e1baj/comment/kjfj249/)

as they say they quite new and had to add all these technologies quickly, and so haven’t had time to implement the log out feature properly yet. I.E. it’s not mature yet.

And in my opinion they should not have passed the audit criteria if it’s true that they haven’t actually published the audits.

I’m in agreement that they probably were added too soon.

---

## Post 32 by @moonwriting — 2024-02-01T16:10:01Z

I honestly think that currently, Skiff doesn’t meet the minimum requirements **at least** when it comes to the marketing section of the Privacy Guides criteria for email providers, and thus should be removed from the recommendations.

PG requires that “The provider’s site must also comply with DNT (Do Not Track) for those who wish to opt-out.” This is listed as a minimum-to-qualify requirement, meaning that if you don’t respect this, you won’t get listed. On their [privacy policy](https://skiff.com/annotated-privacy-policy), Skiff clearly says that they do not respond or honor this.

Also, as I said in [my previous comment](https://discuss.privacyguides.net/t/adding-skiff-was-too-premature/16228/17), Skiff’s marketing has not been responsible, which is another requirement for being listed, even though spreading disinformation about your competitors hasn’t been listed as an example of irresponsible marketing.

---

## Post 33 by @pikacho — 2024-02-01T16:29:47Z

For now Skiff is not trustworthy for me. IMHO

Too much issues, nothing changes…

---

## Post 34 by @ph00lt0 — 2024-02-01T16:37:42Z

> [@anonymous127](#):
>
> Though I think this comment from them in the above mentioned thread is interesting: [https://www.reddit.com/r/Skiff/comments/19e1baj/comment/kjfj249/](https://www.reddit.com/r/Skiff/comments/19e1baj/comment/kjfj249/)

This is pretty insane TBH and a massive security issue. The fact you need contact support, and they think that that is speedy enough is even worse. Once again shows that they do not understand their own product and need for security and privacy by design

---

## Post 35 by @Bhaelros — 2024-02-02T08:39:55Z

Imagine you have a breach on your email account and they want you to contact them to kill the sessions by email again :slight_smile:

---

## Post 36 by @pikacho — 2024-02-03T12:30:32Z

> [@Bhaelros](#):
>
> they want you to contact them to kill the sessions by email again

That’s horrible. I think Skiff should be removed (IMHO)

---

## Post 37 by @ph00lt0 — 2024-02-08T11:01:14Z

Skiff also doesn’t seem to stop spreading false information on their blog posts:

“More importantly, crucial security options are locked behind more expensive subscriptions. ProtonMail doesn’t have built-in 2FA for any individual tiers, premium or not—the feature is only available to business users.” - [https://archive.is/KntXk](https://archive.is/KntXk)

Post is from last year. I was just pointed to this when talking about the other misinformation they distribute which was discussed on the forum earlier.

---

## Post 38 by @anonymous127 — 2024-02-08T12:46:04Z

At this point I think the argument can easily be made with the above evidence that Skiff was not only added prematurely, but should be removed. I’m shocked that the team STILL hasn’t responded to this, but maybe that’s because of this posts title. Not sure if titles can be changed or not, but if they can I propose that it is changed to “Remove Skiff”. Also add “Tool Suggestions” as a category.

---

## Post 39 by @privacycarrot — 2024-02-08T15:37:22Z

Looks like I can’t change the topic title. Would anyone from the team advice on whether mentioned here issues warrants Skiff removal and whether the team would be keen on discussing it?

---

## Post 40 by @pikacho — 2024-02-08T18:42:18Z

I voted for removal. Until issues will be fixed it should not be listed

---

## Post 41 by @ph00lt0 — 2024-02-08T19:00:24Z

I wanted to change it but seems someone already did.

---

## Post 42 by @FlipSid — 2024-02-09T05:30:30Z

Bump.  
Vote for removing

---

## Post 43 by @bee — 2024-02-09T06:12:32Z

Sorry for the silent change haha. I thought I’d do it quickly before hopping off this morning

---

## Post 44 by @anon66226834 — 2024-02-09T07:04:26Z

I agree for the removal of Skiff.

---

## Post 45 by @jonah — 2024-02-09T07:37:18Z

> [@privacycarrot](#):
>
> Would anyone from the team advice on whether mentioned here issues warrants Skiff removal and whether the team would be keen on discussing it?

Possibly. We are currently discussing it. Some of the issues mentioned here are not ones I experienced in my testing, so I can’t totally back this up yet without taking another look.

If we do remove Skiff Mail we’ll post a blog post about removing them to make sure people know what’s going on.

> [@moonwriting](#):
>
> PG requires that “The provider’s site must also comply with DNT (Do Not Track) for those who wish to opt-out.” This is listed as a minimum-to-qualify requirement, meaning that if you don’t respect this, you won’t get listed.

I feel like this might be an oversight (in our criteria), because I thought at one point we decided to remove this because of the fingerprintability (and overall uselessness) of DNT. I’ll try and find the discussion about that tomorrow and make a PR to change that if I do, or I’ll start a separate discussion about that change if not.

I wonder if @amilich would still care to comment.

---

## Post 46 by @ph00lt0 — 2024-02-09T09:51:53Z

We also still need to define on what grounds Skiff would not meet our criteria.  
I am surely in favour of removal (which doesn’t surprise anyone) but it is still hard to express exactly why other than the company not being mature. Several forum users myself included, have expressed pretty vocally our concerns about Skiff being a risky recommendation before and after it got listed. Still I would really like to have a formalized baseline on what we are actually assessing here. So far we collectively have not been able to make this clear enough imo.

---

## Post 47 by @TorLover9 — 2024-02-09T20:55:36Z

If you need the criteria to be adapted to fit your goal of removing Skiff, then it isn’t criteria. It’s your biases.

---

## Post 48 by @cXcRDR836XGCsggPowVD3cLpUr — 2024-02-09T21:12:11Z

Adding my vote to remove Skiff. They are nowhere near the quality standards that their competitors bring.

Their software is a buggy mess and it is clear that they do not hold the same values that privacy advocates aspire to be.

Security is a slow process not something to be rushed.

---

## Post 49 by @animeska — 2024-02-09T22:27:08Z

> [@anon66226834](#):
>
> I agree for the removal of Skiff.

+1  
At least until issues will be resolved

---

## Post 50 by @ph00lt0 — 2024-02-09T22:53:29Z

You are misunderstanding. The criteria should be improved upon to avoid mistakes like skiff being added to the website. That is something different.

---

## Post 51 by @Bhaelros — 2024-02-09T23:18:14Z

They are now migrating to something called Notion ([https://www.notion.so](https://www.notion.so)) without saying a word and they are deleting their Discord channel. How professional…

---

## Post 52 by @jonah — 2024-02-10T00:04:52Z

Obviously #approved with today’s news ([Skiff –&nbsp;Migrating your data](https://skiff.com/data-migration)) and just needs a PR to remove them from the site now. I’m out & just on my phone right now so I’ll post more about this later— because we should brainstorm a better filter for companies like Skiff in the future certainly :grimacing:

---

## Post 53 by @forwardemail — 2024-02-10T00:34:00Z

Hi there :wave: Team from Forward Email here!

We just submitted a PR to remove Skiff for you (including assets/images) at [https://github.com/privacyguides/privacyguides.org/pull/2398](https://github.com/privacyguides/privacyguides.org/pull/2398).

Separately, we have a PR open to add Forward Email at [https://github.com/privacyguides/privacyguides.org/pull/2358](https://github.com/privacyguides/privacyguides.org/pull/2358).

---

## Post 54 by @ph00lt0 — 2024-02-10T00:39:36Z

Whoa. This is super unfortunate. But also quite a problem for those who use @skiff.com or their masked emails for a lot of their accounts. w  
We should definitely warn people to start changing any possible credentials with that.

---

## Post 55 by @ph00lt0 — 2024-02-10T00:55:10Z

They have taken the blog posts down.

But all of this confirms one theory tho. Often companies that grow fast try to scale up so they can sell out at some point. It should be a red flag.

---

## Post 56 by @anon21489307 — 2024-02-10T00:57:56Z

Now, I have no reason to use Skiff anymore. Moving to Proton (already have an account).

---

## Post 57 by @jonah — 2024-02-10T01:21:43Z

yeah so… how do we want to say that in a criteria that could be followed in the future? or we could just add “no bad vibes” to the criteria lol

---

## Post 58 by @jonah — 2024-02-10T05:13:33Z

8 posts were merged into an existing topic: [Avoiding the next Skiff](/t/avoiding-the-next-skiff/16722/2)

---

## Post 60 by @LiquidDeath911 — 2024-02-10T02:23:53Z

Seems like Skiff has been purchased by Notion. Just received an email from Skiff and here is part of the email:  
“As we begin to shift focus to our shared efforts with Notion, we will be closing down Skiff’s product suite after a 6-month sunset period We are deeply appreciative of the trust users have extended to us, and we are committed to honoring that trust by ensuring that all data on Skiff is easily exportable. For the next 6 months, Skiff services will continue to operate without disruption, and users can freely duplicate, migrate, or export data. You can now also set up a forwarding address to redirect mail to any other provider.”

Probably a solid reason to remove them from PrivacyGuides.

---

## Post 61 by @anon89321548 — 2024-02-10T02:37:59Z

Damn, I figured they’d sell eventually but a 6 month timeline for shut down instead of maintaining the service is wild.

I also thought they’d pivot to some kind of 365/MS Loop offering between Skiff Pages and email.

---

## Post 62 by @dngray — 2024-02-10T05:18:38Z

> [@Screwdriver](#):
>
> This seems like a major issue…If you change your password, Skiff does not log out your other sessions. Even rebooting keeps your other apps logged in.

I’m surprised that the audit didn’t determine that to be a flaw, so between that and still sending marketing emails to people’s recovery addresses.

> [@ph00lt0](#):
>
> Skiff also doesn’t seem to stop spreading false information on their blog posts:
> 
> “More importantly, crucial security options are locked behind more expensive subscriptions. ProtonMail doesn’t have built-in 2FA for any individual tiers, premium or not—the feature is only available to business users.” - [https://archive.is/KntXk](https://archive.is/KntXk)

I really dislike these these kind of blog posts. CTemplar did that for a while and I do clearly remember pulling them up on that.

> As we begin to shift focus to our shared efforts with Notion, we will be closing down Skiff’s product suite after a 6-month sunset period We are deeply appreciative of the trust users have extended to us, and we are committed to honoring that trust by ensuring that all data on Skiff is easily exportable. For the next 6 months, Skiff services will continue to operate without disruption, and users can freely duplicate, migrate, or export data. You can now also set up a forwarding address to redirect mail to any other provider.

I wonder if their VC decided the current [model was unsustainable](https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411/23). There must be a reason in which they don’t want to just continue the product as is. I wrote this in the other thread:

> [@Skiff Mail (Email Provider)](https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411/23):
>
> The first tier of paid usage on Skiff is quite a bit more than it’s competitors. Sure, you do get more storage, but quite often a user won’t have 100GB of email or files to store. This impacts your product, because it means that a lot of people will stay on the free tier, which doesn’t make you any money. Money is needed for viability, and its important that the company remains healthy.

I suspect the other reason maybe that Notion thinks they can do a better job with marketing, which I certainly think improvements there could have been made. Unfortunately rather than having someone with that background certain people were wearing multiple hats.

---

## Post 63 by @Banter8905 — 2024-02-10T05:46:05Z

> [@dngray](#):
>
> I’m surprised that the audit didn’t determine that to be a flaw,

Did Skiff ever release a copy of there Audits? I note on reddit they would go quite when asked about Audits.

---

## Post 64 by @dngray — 2024-02-10T05:53:20Z

No, I asked repeatedly and they threw out that not all providers eg Proton release full audits and only letters of attestation.

iirc they never released anything to indicate the feedback from Trail of Bits.

> [@forwardemail](#):
>
> Separately, we have a PR open to add Forward Email at [https://github.com/privacyguides/privacyguides.org/pull/2358](https://github.com/privacyguides/privacyguides.org/pull/2358).

I haven’t forgotten about this, it’s #1 on my to-do list to check out.

---

## Post 65 by @Banter8905 — 2024-02-10T05:56:27Z

> [@dngray](#):
>
> No, I asked repeatedly and they threw out that not all providers eg Proton release full audits and only letters of attestation.
> 
> iirc they never released anything to indicate the feedback from Trail of Bits.

Thanks for confirming. I note there Audit from Cure 53 was also never posted.

---

## Post 66 by @alonewolf — 2024-02-10T06:40:40Z

i’m kinda confused about the current situation of skiff. notion acquired them (which is a company not so good for privacy) so what is going to happen to all of our data now? they did have a clause about acquisitions in their privacy policy iirc so is all of it going to be transferred to notion now? they do say that it’s gonna be e2ee but not everyone communicated with other skiff users, so will notion be able to read all of our emails now? and are they closing down their email and drive services too or is it just the pages?

---

## Post 67 by @dngray — 2024-02-10T07:21:01Z

> [@alonewolf](#):
>
> so what is going to happen to all of our data now

They seem to be wrapping up the service in order to turn it into something else, [their website](https://skiff.com/data-migration) states:

> As we begin to shift focus to our shared efforts with Notion, we will be closing down Skiff’s product suite after a 6-month sunset period We are deeply appreciative of the trust users have extended to us, and we are committed to honoring that trust by ensuring that all data on Skiff is easily exportable. For the next 6 months, Skiff services will continue to operate without disruption, and users can freely duplicate, migrate, or export data. You can now also set up a forwarding address to redirect mail to any other provider.

> [@alonewolf](#):
>
> so will notion be able to read all of our emails now?

No, it’s just that they aren’t continuing the service.

> [@alonewolf](#):
>
> their email and drive services too or is it just the pages?

They mention “the suite” so I would take that as all products.

---

## Post 68 by @gammexane — 2024-02-10T07:54:28Z

Nothing to say more than you all already said… I just wanted to share my frustration with this “ppl”. Skiff was the worst scam in the history of the open source.

---

## Post 69 by @lepras — 2024-02-10T08:46:41Z

to this entire thing:

LOL.

---

## Post 70 by @alonewolf — 2024-02-10T09:07:26Z

> [@dngray](#):
>
> No, it’s just that they aren’t continuing the service.

but their privacy policy stated that in cases of purchase of the company “your information may be sold or transferred as part of such a transaction, as permitted by law and/or contract.” and also says “If we are ever sold, the information and encrypted data stored by Skiff would be transferred to the new owner.” they do say that encrypted data but since most of the emails of users weren’t e2ee as the majority communicated with non skiff users, that would mean that notion would get access to our data won’t it?

---

## Post 71 by @Ganther — 2024-02-10T09:21:04Z

I use Notion at work and currently I’m a bit confused over how in the world they could be purchased by them, seeing as, to my knowledge. Notion doesn’t even do email. Maybe they are planning on starting, I dunno.

This is weird AF regardless.

---

## Post 72 by @dngray — 2024-02-10T09:23:06Z

> [@alonewolf](#):
>
> “If we are ever sold, the information and encrypted data stored by Skiff would be transferred to the new owner.” they do say that encrypted data but since most of the emails of users weren’t e2ee as the majority communicated with non skiff users, that would mean that notion would get access to our data won’t it?

At the point they are stored on Skiff’s servers they are E2EE (even if they were external users), the reason is these messages are not being transmitted through Skiff’s external gateway, simply stored in a database.

So I don’t think there is anything at all strange about that.

> [@Ganther](#):
>
> Notion doesn’t even do email

Skiff also did more than just email, it had the whole document/collaboration think that was E2EE. This is probably what Notion wants.

---

## Post 73 by @wojciechxtx — 2024-02-10T10:34:23Z

Not been here a week (due to hospital visit, but thats totally unrelated here), now Im back and Skiff drama is far from being over.

If Skiff telling lies about their service, than just remove them from PG and thats it. Simple really.

As of Notion, we use them at work, are happy with them. Great service. Let them live long.

---

## Post 74 by @CuriX — 2024-02-10T11:22:35Z

> [@forwardemail](#):
>
> Hi there :wave: Team from Forward Email here!

> **Off-topic**
>
> Do you guys have free plan with built in domains?

---

## Post 75 by @Tech-Trooper — 2024-02-10T11:45:42Z

> **[Notion acquires privacy-focused productivity platform Skiff | TechCrunch](https://techcrunch.com/2024/02/09/notion-acquires-privacy-focused-productivity-platform-skiff/)**
>
> Notion announced that it has acquired Skiff, a platform that offers end-to-end encrypted file storage, docs, calendar events, and email. 

I really don’t understand. Is Skiff completely shutting down its services? So what’s the point of acquisition, then?

---

## Post 78 by @landordragen — 2024-02-10T12:00:20Z

I am completely disappointed with the attitude of the team responsible for Skiff.

For the vast majority of 2023, I was a daily user of the service with my own domain. When asked, I was the first to recommend Skiff. The rapid evolution, the strong community, the fact that they took on board the advice and requests of users captivated me. The CEO himself was able to resolve issues with my account in minutes, after a few private messages via Reddit or Discord.

In December 2023, I subscribed to Proton Unlimited due to some of Skiff’s less positive points, namely the slowness of the applications, the search, the emails not being delivered to the recipient, among other details. Although I had already been a Proton user (in the free version), I never used it on a daily basis.

I decided, because there is unanimous opinion in the privacy community that Proton is currently the best encrypted email service, that I would try the paid version because I am interested in the rest of the Proton services. I’m happy to have made the transition at that point and no longer depend on Skiff today. I’m even happier to have all my online accounts set up with email from my own domain.

Although the evolution is taking place at a slow pace, it is undeniable that all Proton products are the benchmark for me.

May this serve as a learning experience for me. I’ve now deleted everything on Skiff, including the account itself.

Shame on you, Skiff.

---

## Post 79 by @anonymous127 — 2024-02-10T12:14:10Z

Might just have to be on case-by-case basis to be honest. Adding a service you can more easily take these things into account (and just not add them) because it’s at your discretion. But when removing a service it’s harder as you have to give a reason why they broke your criteria and you recommended them before but not now. Skiff just gave you a massive reason to remove them with the Notion stuff, so that’s the silver lining. But I guess what I’m saying is adding services should be done cautiously, as just because service appears to fulfill all your criteria doesn’t mean they have to be added. You guys have done a pretty good job at that for the most part.

But especially when company comes to you and pushes you to recommend on your website, I’d proceed with caution.

---

## Post 80 by @dngray — 2024-02-10T12:18:52Z

I mind add, Skiff did go through quite an [extensive review process](https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411/8) during our initial look at it. As a result we made sure to add the concept of **data liberty** from the criteria. Skiff was also open to adding export features to the mail product (which they did not have when they came to us).

Unfortunately though there is very little way to determine from the outside the health of the company. I did hint at it with my questioning about the fee structure for the [plans](https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411/8#pricing-8) that were [available to customers](https://discuss.privacyguides.net/t/skiff-mail-email-provider/11411/23).

I wish we had though about testing password reset functionality in regard to logging out existing accounts - that is a serious design flaw that we missed.

> [@anonymous127](#):
>
> Skiff just gave you a massive reason to remove them with the Notion stuff, so that’s the silver lining

It’s not so much the purchase by notion, it’s the announcement of discontinuance of the product.

---

## Post 81 by @ph00lt0 — 2024-02-10T12:28:24Z

Getting the developers.

Also Notion earlier acquired a calendar app named Cron that also shut down and now there is Notion Calendar. So perhaps Notion Mail and Notion Drive will see a light. Doubt it will care about encryption.

Notion in the past had once plans to adopt and implement e2ee for notes but afaik they never did.

---

## Post 82 by @ph00lt0 — 2024-02-10T12:30:05Z

> [@anonymous127](#):
>
> Skiff just gave you a massive reason to remove them with the Notion stuff, so that’s the silver lining.

Given the discussion before this news this probably would have happened regardless. But now this made the discussion easy.

---

## Post 83 by @dngray — 2024-02-10T12:33:00Z

> [@ph00lt0](#):
>
> Notion in the past had once plans to adopt and implement e2ee for notes but afaik they never did.

I think there is a shift towards E2EE from larger tech corporations in order to remain profitable and deal with compliance/safety issues.

TLDR there’s a lot of users on the internet a good portion of them are bad people and do bad things with a service and a company would be better off not having access than having to have a thousand moderators check everything.

---

## Post 84 by @ph00lt0 — 2024-02-10T12:40:47Z

Definitely true but Notion promised this like years ago. It’s so long ago I am unable to find it back lol.  
And given they are in the AI world of things I doubt they will ever adopt it. AI needs your data to be powerful.

---

## Post 85 by @wojciechxtx — 2024-02-10T13:53:18Z

> [@dngray](#):
>
> there is a shift towards E2EE from larger tech corporations

Have not noticed this shift, but maybe its too early to see it…

> [@ph00lt0](#):
>
> AI needs your data to be powerful.

Its exactly how these huge, privacy-disregarding, companies word things… give us our data is disguised with “we care for privacy”…

aha…

---

## Post 86 by @dngray — 2024-02-10T13:57:00Z

Why do you think law enforcement has been crying about backdoors and the children so loudly with rubbish laws like EARN IT, Online Safety Bill, Chat Control etc.

They all want to say anyone who doesn’t agree with them is a pedophile (or sympathizer).

---

## Post 88 by @ph00lt0 — 2024-02-10T18:03:29Z

> [@wojciechxtx](#):
>
> Have not noticed this shift, but maybe its too early to see it…

To give some of the news. Facebook enabling e2ee in messenger so they don’t need to monitor it. Also google who did the same thing for location history lately. They are all using it now to doge law enforcement and the costs of that.

On the other side we see all companies am wanting access to all your documents to train their AI _Microsoft_. Once the AI is trained it works well and local models can even have trained context. But they need data to improve the quality and analysis. The last part is the scary part where a lot can go wrong, goes wrong and will go wrong. And of course the fact that your data can be reproduced by AI when asked.  
I am not sure how notion’ implementation works but I doubt it runs locally.

---

## Post 89 by @jonah — 2024-02-10T19:11:51Z

Completed:

> <https://github.com/privacyguides/privacyguides.org/pull/2398>
>
> See https://skiff.com/data-migration and https://twitter.com/skiffprivacy/status…/1756093174806974831
