Gradients light

Fully encrypted email on every device

Your entire mailbox — messages, attachments, subject lines, and metadata — is encrypted on your device. A modern email experience with all expected features, protected by real end-to-end encryption.

Google play store Apple store
Fully encrypted email on every device

Privacy isn’t a feature. It’s the foundation.

Our email system is built on end-to-end encryption, PGP at rest, AES-GCM protection, metadata minimization, and zero-access architecture — security embedded at every layer.

Fully end-to-end encrypted webmail

Private.Ki encrypts every email directly on your device before it ever leaves it. The encryption happens client-side, using keys that only you control, so the server never sees plaintext at any point. Your messages remain encrypted in transit and at rest, and only the recipient's device can decrypt them. This ensures that neither Private.Ki nor any intermediary can access the content of your communications.

Mails encrypted with PGP

All emails use OpenPGP with asymmetric key pairs, providing battle-tested, widely verified cryptographic security. Messages are encrypted with the recipient's public key and can only be decrypted using their private key. This model ensures that even if someone intercepts the message or compromises infrastructure, they cannot read the content. PGP also provides integrity protection, ensuring messages cannot be altered without detection.

Subject line & metadata fully encrypted

Unlike most encrypted email services, Private.Ki also encrypts subject lines and email metadata. Sender, recipient identifiers, timestamps, routing information, and conversation graphs are not visible to the server. This prevents profiling, social-graph reconstruction, and traffic monitoring based on metadata. Even high-level patterns — who communicates with whom and when — remain private.

Drafts and signatures encrypted with AES

Drafts, signatures, and contact data are encrypted locally using AES-GCM, a modern authenticated encryption standard. AES-GCM not only protects confidentiality but also prevents tampering by verifying the integrity of the encrypted data. This ensures that even temporary or unsent content never appears in plaintext on the server or in local storage. Your email drafts remain protected even during the writing process.

Double-layer PGP encryption

When an email arrives already encrypted with the sender's PGP key, Private.Ki adds an additional layer of PGP encryption before storing it. This "encrypt-on-arrival" approach ensures that encrypted messages sent by others remain doubly protected on server storage. Even if storage were compromised, an attacker would face two independent cryptographic layers. This design upholds the zero-access model for both inbound and outbound mail.

Traffic-pattern obfuscation

Private.Ki reduces observable patterns in how and when your device communicates with our servers. This includes obscuring message timing, request characteristics, and packet sizes when possible. Such obfuscation makes it significantly harder for an external observer to analyze behavior, infer relationships, or identify message flow. Even without reading content, traffic analysis becomes far less effective.

Keys stored on your device

Your private keys are generated and stored exclusively on your device, never transmitted to Private.Ki's servers. All cryptographic operations — encrypting, decrypting, signing — happen locally, ensuring full user control over the keys. Even in the hypothetical case of a server breach, your private keys remain inaccessible. This model forms the foundation of true end-to-end encryption.

Automatic key management

Private.Ki handles key generation, rotation, publishing, and retrieval automatically, reducing complexity for users. The system securely manages everything required for PGP to work without exposing sensitive material or requiring technical expertise. Keys are protected by your passphrase and used only within the device's trusted environment. Users get strong cryptography without having to manage it manually.

No tracking, no logging

Private.Ki does not keep identifying logs such as IP address history, login metadata, device fingerprints, or behavior analytics. There is no server-side data that could reconstruct your communication patterns or be correlated back to you. This means there is no traceable record of how, when, or from where you use the service. Combined with encrypted metadata, this forms a zero-knowledge communication environment.

Works with VPN & Tor

Private.Ki fully supports VPN and Tor without any functional limitations or reduced capabilities. You can create an account, send mail, and sync devices entirely over anonymizing networks. This allows fully pseudonymous use without revealing your actual network identity. Private.Ki's architecture is designed to remain secure and functional even under network obfuscation layers.

A complete, modern email experience

Everything you expect from full-featured webmail — composing, search, attachments, folders, filters — delivered in a fast, clean interface fully protected by encryption.

Compose & send email

Emails sent between Private.Ki users are end-to-end encrypted by default, using your own device-side keys.

All content — including subject lines and attachments — is encrypted locally before sending, ensuring that only you and the intended recipient can decrypt it.

The interface works like familiar modern webmail, but with real cryptographic protection underneath.

Compose send email

Manage attachments

Attach images, documents, and files of any type, all encrypted on your device before upload.

Attachments remain encrypted at rest and in transit, with no plaintext ever reaching Private.Ki servers.

You can safely share files without relying on external services or exposure points.

Manage attachments

Organize and manage your inbox

Folders, filters, and full-text search give you complete control over your inbox, all operating on encrypted data.

Search runs on encrypted indexes, ensuring privacy without reducing usability.

Everything expected from modern webmail works seamlessly inside a fully encrypted system.

Organize

Delivery & message handling

Messages are routed, delivered, and synchronized securely across devices, with encryption maintained at every step.

Our delivery system ensures reliability without exposing your communication patterns or metadata.

Read status, thread handling, and message updates all function normally, protected by the same encryption model.

Delivery

Privacy that follows you across devices

Your mailbox stays encrypted and synchronized across all your devices. All keys remain on your side, and only your devices can decrypt your data.

Multi-device secure sync

Your mailbox is synchronized across all your devices using fully encrypted data.

No plaintext is ever transmitted or stored — only encrypted blobs that your devices decrypt locally.

Keys stay on your devices

All encryption and decryption happen on your device using keys that never leave it.

Private.Ki servers store only encrypted data, so the system works the same everywhere without exposing your private keys.

Private-by-default behavior

All communication is encrypted before it leaves your device, and no identifiable metadata is stored.

Privacy is built into every operation — not a toggle — so the system remains protected regardless of how or where you access it.

Ready to start communicating privately?

Join Private.Ki — the encrypted communication SuperApp. Your messages, emails, and chats — protected by default.