One of the biggest risks is when someone knows your password. Your PGP encrypted emails that you want noone to see will be available to the attacker. Whereas if no such thing happened, the attacker wouldn't be able to decrypt the PGP encrypted emails even if the attacker gained access to your account.
Manually encrypting your stuff is better than having some random on the internet do it for you. It's really just a tradeoff. Convenience or security? It's not even hard to manually encrypt emails.
Exactly. There's no justification for them storing the private key online for "convenience". And key generation happens in the browser with JS. Which means it is possible to send backdoored JS to easily copy the private key.
You upload your private key to the cloud. Encrypted or not, this is a bad idea. No thanks. I can do the signing locally and then I'll do the decryption with my own private key locally without them storing it as well.
This is old news. Why are you posting this just now? I mean I don't really care much. I transitioned to Posteo as soon as I learned that they stored the private key. They don't even let you use your own GPG key, useless honeypot. Their recent bitcoin wallet supports this. If they cared about privacy, they wouldn't go with Bitcoin. They have been ignoring requests for monero since years.
They also are getting into the AI hype, so I can't trust my data with them.
Good to know some people still know katawa shoujo