I use mailbox.org personally. Disroot is probably fine. Do they have 2FA? That would be the most essential thing you want here if you're worried about being hacked by an outside party. 2FA would even mitigate a password leak in most cases, since they'd only have 1 of the authentication factors.
If you're worried about hacking, you can do some things to mitigate the damage that would cause. Download important old emails and delete them from the server, this is pretty easy to do in a desktop client (like thunderbird or outlook) where you'd just move them to a local folder. That way if someone gains access, or they sell to someone that processes the data, they won't have the old emails (unless they for some reason retained a separate copy, which seems doubtful).
Sign your email up for https://haveibeenpwned.com/. Then you'll get notifications if there's any data leaks, including of your email provider. Obviously this is only useful if nobody has stolen your account before the leak is reported, but that's more likely than not (unless you're a particularly valuable target for some reason).
Tangential fun fact:
Snake oil is a real thing, that actually helps with the some very specific problems. But it has to be made a specific way from a specific snake. We associate the term with scams because of the large number of scammers that advertised fake snake oils, or advertised it being useful for tons if things it wasn't.
My point is, many of the most effective scams rely on something that has a kernel of truth.