Skip to content

Security and privacy

We would rather tell you exactly what we do than make big promises. This page lists the protections that are switched on today, what is and is not encrypted, and where the limits are.

Your account

  • Passkeys

    Sign in with your fingerprint, face or device PIN. Passkeys cannot be phished or guessed, and we only keep their public keys.

  • Two-step verification

    Codes from an authenticator app, single-use backup codes, and devices you choose to trust for 30 days.

  • Sign-in alerts and history

    You are told about new sign-ins and failed attempts, can see the last 90 days of sign-ins, and can sign out any device.

  • Breached password check

    New passwords are checked against known breaches using only the first five characters of a hash, so the password itself never leaves our server.

  • Shared computer mode

    Tick "This is a shared or public device" when you sign in, and Viremail keeps no mail or keys on that computer and does not keep you signed in.

Mail

  • End-to-end encrypted email

    OpenPGP is built in. Mail to anyone with a public key is encrypted in your browser, and only they can read it. Your private key is encrypted with your password before it reaches us.

  • Shield

    Checks incoming mail for phishing, look-alike links and risky attachments, and warns you in plain words before you open them.

  • Tracking pixels blocked

    Pictures from outside an email are blocked by default, so senders cannot see when you open their mail.

  • Disposable addresses

    Keep your real address out of shop and sign-up databases, and switch an address off the moment it gets spam.

Vire and calls

  • Calls

    Calls go directly between devices where the network allows, are encrypted in transit and are never recorded.

  • You choose who reaches you

    Decide who can message you, call you, add you to groups and see your stories. Strangers wait in Requests.

Files

  • Files encrypted on our servers

    Every file in Drive, and every photo and file sent in Vire, is sealed with AES-256-GCM before it is written to disk. Each Drive file has its own key.

  • Links with limits

    Share links can carry a password and an end date, and can be replaced to switch the old one off.

How we run the service

  • No ads, no tracking

    We do not show ads, sell data or use third-party analytics. Our own dashboard keeps only totals, such as how many people are online.

  • Encrypted connections

    Connections to the app use HTTPS, with a strict content security policy that only lets our own scripts run. Mail to other providers uses TLS where their server supports it.

  • Sealed sessions

    While you are signed in, your mailbox password is held in a server-side session encrypted with AES-GCM, and the session cookie cannot be read by scripts.

  • Report a problem

    Found a weakness? Our disclosure policy and security.txt say how to reach us.

What is encrypted, and how

WhatHow it is protected
Email to someone with an OpenPGP keyEnd to end End to end with OpenPGP. Only they can read it.
Other emailIn transit In transit, where the other mail server supports TLS
Vire messagesIn transit In transit. Not end to end yet.
Photos and files in VireEncrypted at rest In transit, and stored encrypted on our servers
Voice and video callsIn transit In transit, often straight between devices. Never recorded.
Files in DriveEncrypted at rest In transit, and stored encrypted with a key for each file
Is my email end-to-end encrypted?
Email can be. Viremail has OpenPGP built in, so mail to people who have a public key is encrypted in your browser and only they can read it. Mail to people without a key is sent as normal email.
Are Vire chats end-to-end encrypted?
Not yet. Vire messages travel over encrypted connections, and photos and files are stored encrypted on our servers, but message text is not end-to-end encrypted yet.
Are calls end-to-end encrypted?
Calls are encrypted in transit. Where the network allows, they go directly between your devices without passing through our servers, and we never record them.

Our encryption notes in full

What we do not claim

  • Unless you use end-to-end encryption, your mail, chats and files are stored in a form our systems can read, so they can be searched, filtered and delivered.
  • Encrypting mail with OpenPGP protects the message and its attachments, not the subject line, and not who wrote to whom or when.
  • In a web browser you rely on the code we send each time you open the app. That is true of every web app.
  • We do not currently claim any independent security certification.
  • No online service can be perfectly secure. A unique password, a passkey and up-to-date devices make the biggest difference.

Found a problem?

If you think you have found a security weakness in Viremail, please tell us before telling anyone else. Our responsible disclosure policy explains what to include, and security.txt lists our current security contact.

Privacy Policy Your data and privacy

Try Viremail. It costs nothing.