> I'm not sure piggybacking on email is a good idea, considering the amount of metadata exposed by email headers
Yes, and also size of the messages. It's really easy to tell if you sent a suspect file at a specific time to somebody by only looking at the message size, which in addition to being archived somewhere, can probably be isolated from other outgoing traffic and matched against.
I wouldn't use it for top class comms, but it's worlds apart from WhatsApp, and by leveraging AutoCrypt it is so easy for non-geeks.
> Not to mention attachments which are likely not encrypted but just encoded in base64
PGP messages attached to emails where possible.