Just signed up to offer some additional results after my testing, cheers to op for the post was very helpful.
So being forced to upgrade my phone as my now 4 year old phone has had its last drop I'm using the latest version of Cyanogen for my device.
I was initially going to test 3 apps listed in here: K9, Aquamail and boxer (as i've read its now the default for cm firmware); But after seeing the wall of permissions for Aqua and reading
@Hadron 's post above about a new takeover, i decided too drop that one;
I set up a new email account on my server specifically for this test so no tarring the results etc and installed and setup k9 and boxer to this account using pop; I used the privacy email tester, mentioned above I believe (or
here), and then ran a packet capture app on my device.
So i found that K9 is (generally) privacy safe in terms of opening the email & boxer only red flagged on link prefetch, which then changed when downloading remote content / showing pictures! Both had several red flags from the privacy checker, K9 having the most this time?? (listed below)
In both cases the IP shown was the one for my device meaning remote data doesn't go via any "external company" servers. I cant say the same for fetching of the email as i have been unable to get hold of the email access logs, I will post back if my hosting company gets back to me.
I then ran the packet capture app on my device whilst checking and sending emails. Looking at the logs tells me that K9 only ever connected to my servers IP and nowhere else which is great imo. Unfortunately not for boxer: I had more than one extra IP address in the logs. They resolved to: amazonaws.com, sl-reverse.com & a blank entry;
So far i've decided to stick with K9 & see how the interface goes. Apologies for the length of the post, i didn't have time to write a shorter one.
------------------------
RED FLAGS ON REMOTE CONTENT LOAD
K9:
Object tag - data
CSS background-image
CSS content
Audio tag
Object tag - Flash
Video MP4
Video tag
Video poster
Image Submit Button
Link Prefetch
Image tag
CSS link tag
Iframe tag
BOXER:
CSS content
Image tag
Object tag - data
Image Submit Button
CSS background-image
---EDIT---
I realise K9 has more Red Flags on remote loading but this to me is a secondary issue after the ip issue. I rarely click on show remote content within emails, let alone open spam; So i am the one who controls this privacy whereas i have no control over what is sent to the ips logged in the packets;