They could already have access to your emails, because… you’re running their OS. They can slip in any code they want and run it with NT AUTHORITY\SYSTEM
-level privileges (comparable to root
-level privileges on Linux systems).
If you run any other OS you’ll also have to trivially trust the makers of that OS with root
-level privileges (or comparable).
(Personally I don’t believe that MS is scanning all your local emails, but they certainly have the technical possibilities to do so very trivially.)
IIRC all plugins you can get via the offical plugin directory are GPL-3