We encrypt everything to disk, and everything on the wire that is practical (connecting to other providers still falls back to plaintext if they don't support STARTTLS, because encrypted-only isn't practical yet)
But client connections are ONLY secured now, we don't allow any plaintext channels where you could accidentally send your password.
https://www.fastmail.com/help/technical/ssltlsstarttls.html
So you're stuck trusting us, but only us. The only sane alternative that I can see is to run your own server, on your own hardware, preferably hosted inside your own home for maximum legal protection. Of course, unless you really know your stuff then your data could well be at greater risk from both legal and illegal intercept.
(and that's nice if you're providing it just for yourself - as soon as it's for anyone else, even just family, you become on-call tech support)
Bron.