I'd rather have my data in Google's hands, where I basically know who can access it and when (US government with a warrant or NSL, Google employee with a specific business need, no foreign governments, no hackers) than in the hands of some company that for all I know exposes their production DB to the public internet with default username and password enabled.
I guess there's always E2E encryption, but I'd like to be able to recover my emails if I lose my password.