Lets take it a different way: You're knowingly sending your data to a 3rd party. You're not encrypting. It's not through the USPS (special protections). It seems bloody evident that, of course, your email provider can read your emails! Unless you're encrypting with GPG, then they can (and they can still read the signing keys). Yahoo, Google, and friends all scan, dedup, and all sorts of tricks to determine marketing…
What you've just said is the email equivalent to "she deserved to be raped, because she was dressed like a slut".
Yes, we should take precautions to protect ourselves. But that in no way justifies the privacy intrusions that happened here.