Any and all email providers can be subverted (and probably are). You could run your own email, but most email and all metadata is cleartext in transit. You could use encrypted email, but except for the one or two of your friends who would put up with encryption, all your comms are going out clear on the open internet.
You can secure specific communication between specific pairs, but as a practical matter you cannot secure email today because almost no one you know will cooperate with you. If you were to reverse engineer email and the internet you would have to conclude that it was designed for surveillance.
If it really matters, don't use the internet or the phone.
P.S. I use fastmail.
Metadata on a physical letter is easy to collect without evidence of tampering, and the USPS takes photos of letters to make delivery easy. They supposedly delete the images. I assume they share the images with the NSA.
The contents of a letter in an envelope are harder to spy on, because it's a manual process and you leave evidence of tampering unless you're really good and careful. But really good and careful takes even longer.
If you're a specific target, then they'll get what they want. But if you're an average unsuspected person, a letter is just too much trouble to spy on, and I think they probably don't do mass surveillance on the inside of enveloped letters.
* Prepare a metadata sheet indicating the serial number of each of those one time pads.
* Hand both over in a face to face meeting (you keep a copy of metadata and one time pads).
* Indicate the serial number of the onetime pad used in your letter and encode the rest of your letter using that onetime pad and post the letter.
* Destroy your one time pad and your corresponding party also destroys his/her copy in an irretrievable fashion.
This all assuming nobody else gets to see the onetime pad except you both.
Much simpler.
A VPS is better, but only slightly better, for the same reason.
If you really care about privacy, buy a low-end server and install Roundcube (or Mailpile when it's ready for production).
Privacy is dead, long live security!
Here's how to protect GDrive files: https://news.ycombinator.com/item?id=6644888