They are not malicious at all. They are like saints compared to the likes of Alphabet (Google) and NSO Group. The issue is the legal framework they are operating on. It is either they give up customer data to authorities or they get lawsuits and shut down. The best thing to do is look for alternatives that cannot be taken over by legal authorities.
https://getsession.org
https://telegram.org
https://briarproject.org
https://signal.org
Are all well reviewed projects that can be way more private and secure than E-mail (regardless of encryption). !PIZZA