If caught red handed, they will always say it depends on how you define where both "ends" begin.
Do not trust a cloud service that you have not developed and deployed yourself.
You may trust untrusted hardware with your encrypted content, but only if you have given it your content pre-encrypted by yourself, not trusted a third party to encrypt it on your behalf. Obviously, this excludes mobile devices.
Do not trust a tree of certificates if you cannot trust the root certificate because it belongs to an organization that is in a jurisdiction where people may be interested in what you have written and said in your encrypted message.
Don't trust old-school typewriters and the postal system either. Letters are routinely opened and typewriters can be matched. For example, the Stasi (secret police of the former GDR - German "Democratic" Republic) had an archive of type samples of all sold models of typewriters for re-identification of political pamphlets.
You can trust a few things: You can trust your Linux box with your self-compiled kernel (no 3rd party drivers), at least as long as it is not on a network. To build a safe environment, you could start there, taking a defensive approach. Remember, last time the paranoid turned out to be naive when Snowden revealed the real status quo in 2013 (ten years ago, when I couldn't buy a 1 TB USB stick).