Okay, but then the receiver has to know how to decrypt. Kind of narrows down who I can realistically send files to.
If paranoia is this high, why would a security policy text on a web page make any difference? They could claim anything they want, but you wouldn't have any idea if any actual encryption was happening, so best to do it yourself.