Earlier quoted context omitted.
"Better safeguards around privacy"? How is Google or Cloudflare or NSA or whoever peeking at your incoming emails to determine what gets through good for "privacy"? That is upside down and backwards. Please explain.
Html enabled email can easily contain tracking. Even without JavaScript, you could insert an img tag pointing at a uniquely generated address and log the query... It becomes a question of who you trust more: the service you've chosen for handling your email (and spam protection), or the people sending spam emails. If you don't trust your provider, you should find another provider.
I set my client to not autoload, it is easy enough to click to load an image if I think I want to see it. In most cases I do not!