Security

How wesecure it.

A mail client holds the keys to your mailbox. This page says where Ramosa keeps them, what our servers can and cannot see, and how to reach us if something looks wrong.

i.Your mailbox keys

  1. i

    They stay on your computer.

    Mailbox passwords and authorizations are stored in your system’s own credential store — Keychain on macOS, Credential Manager on Windows — never in a file of ours, and never on our servers.

  2. ii

    Our servers cannot open your mailbox.

    Ramosa talks to your mail provider directly from your computer. Nothing we run holds a password or token that could read your mail.

  3. iii

    Sign-in without a password.

    Your Ramosa account has no password to leak. You sign in with a code sent to your email, and each code works once — or through your Google or Microsoft account where that option is offered.

ii.On the wire

  1. i

    Everything is encrypted in transit.

    Connections to your mail provider and to us are encrypted on the wire. Ramosa refuses to send a password over an unencrypted mail connection.

  2. ii

    What the task needs, not the mailbox.

    When the AI sorts, translates or drafts, only what that task needs passes through our servers: part of a message, the text to translate, or the thread you are answering. It is not stored and not written to logs, and it goes only to approved model endpoints restricted from keeping it.

iii.What our servers hold

  1. i

    Almost nothing.

    Your account email, your plan, the devices you signed in from, and usage counts. For instant new-mail delivery on Gmail and Outlook, one opaque routing key per mailbox. No mail content, no addresses from your mail, no mailbox credentials.

  2. ii

    Logs without content.

    Our service logs record that a request happened and whether it succeeded — never what the message said.

  3. iii

    Deleted at once.

    Ask us to delete your account and we delete it and its cloud records at once. There is no waiting period. A few limited usage and security records are kept only as long as the Privacy Policy describes.

iv.Dangerous mail

  1. i

    Screened before any AI sees it.

    Mail that carries clear signs of a trap is held back from your inbox and flagged, and no AI reads it. Ramosa tells you it happened; the message waits in Archive. It won’t catch every scam.

  2. ii

    Opened safely.

    Suspicious mail opens with images hidden and every link checked against its real destination. Nothing in a message runs on its own.

v.On your computer

  1. i

    Your mail library is a file on your disk.

    Ramosa does not add its own encryption to it. Turn on your system’s disk encryption — FileVault or BitLocker — and it is protected with everything else.

  2. ii

    Leaving a shared computer.

    One action in Settings clears the local mail library, attachments, logs and stored credentials from that computer, and signs the device out of your account.

vi.Reporting a problem

Found something? Tell us first.

Write to [email protected] with “Security” in the subject. We read it within two business days and reply to you before we say anything in public. Please do not include live passwords, tokens or other people’s mail.

Good-faith research that does not touch other people’s data or disrupt the service is welcome; we do not run a bounty programme.

free to start, coming soon to macOS and Windows.

Works with QQ Mail, 163, 126, yeah.net and Feishu Mail. Gmail, Outlook and iCloud are on the way — see supported mail →