Knowledge base
Privacy & ownership
Privacy first is a claim every mail company makes, so here it is as a list of things you can go and check: what is stripped out of a message before you see it, what is never fetched on your behalf, and what happens to your mail when you stop paying us.
In this section
Tracking pixels strippedThe invisible image that tells a sender you opened their mail is gone before you see the message.Remote image controlStop a sender fetching anything from their own server while you read.Choose which emails we send youPer-category switches in Account → Notifications, and the ones that matter are honestly marked as unswitchable.Your mail on object storageFull message bodies and attachment bytes on R2, indexed per mailbox.Bring your old mailboxArrive with the mail you already have, whether an archive exported from wherever it lives now or the account itself, threaded as it was and filed where it belongs.Take your mail with youOne download with everything in it: every message and attachment in a format another mail app can open, plus your contacts, labels, rules, templates and calendar.Transport encryptionMail moves over TLS on the hops we run, and transport alone never turns the padlock green, because nothing on this backend can read the transport off a delivery.Encryption at restEvery field of a message sealed before it is written down (body, subject, addresses and attachment bytes), so a copy of the database is ciphertext rather than mail.End-to-end encryptionOpenPGP keys made in your browser. Mail you send to another OpenEmail address can be sealed before it leaves the tab, and sealed mail addressed to you opens in the reading pane, decrypted on your machine. The keys are never ours to hand over.