Security at ReciteMail
Last updated: 24 July 2026
ReciteMail's security model starts from one unusual decision. The app never connects to your mailbox. This page explains the whole architecture in plain language, what we store, what we never see and how to reach us if you find a problem.
The short version. ReciteMail cannot read your inbox, cannot send email and cannot lose what it never had. Your messages live in an encrypted database on your own computer. Our servers hold your account record and usage counts, never your email content.
1. No mailbox connection
ReciteMail is import-only. It never signs into your email account, so there is no access grant to revoke, no stored mailbox password and no background synchronisation. You bring in the messages you choose, on your device, file by file. Because the app never connects, it also cannot send anything: every draft is copied into your own email client and sent by you. A tool that has no access cannot leak it.
2. Encrypted on your device
Everything you import or draft lives in a local database on your Windows machine, encrypted with AES-256. Turn on the optional strong app lock and the database key itself is sealed behind your passphrase, so the data is unreadable without it. Your identity profile, contacts, templates, banned words and signature all stay local too.
3. What leaves your machine and when
Nothing is sent for processing until you ask for it. When you request a draft, a translation, a transcription or a revision, ReciteMail sends only the specific message plus the context you chose for that action, over an encrypted connection, to the service that writes the result. The result comes back to you and that is the end of the journey.
- We send the minimum needed for the action you requested, never your wider mailbox.
- We do not store your message content or your drafts on our servers.
- The paid drafting service we use does not train on content sent through it.
- Requests pass through our server only to authenticate your subscription and meter usage. It forwards and returns, it does not retain.
4. What lives on our servers
To run accounts and billing we keep a small account record, hosted in the European Union: your email address, a securely hashed password, your subscription status and usage counts. Counts, not content. Alongside that sit security records such as timestamps of sign-in attempts, kept for abuse prevention.
5. Your account
- Every connection to our servers uses TLS, so your data is encrypted in transit.
- Passwords are stored only as a salted hash using a modern algorithm (argon2id), never in readable form.
- Sign-in uses short-lived access tokens backed by rotating refresh tokens, so a stolen token goes stale in minutes.
- One account works on up to two computers at the same time. A third sign-in signs out the oldest device, which keeps a shared password from quietly spreading.
- Payments are processed by Stripe. We never see or store your card number.
6. This website
The site you are reading sets no tracking cookies. Analytics are cookieless, aggregate and self-hosted on our own infrastructure in the European Union. The site is served with a strict Content-Security-Policy, HSTS and a policy that blocks it from being embedded in frames. No checkout happens here; payment pages run on Stripe.
7. What we never do
- Train on your content. Your messages are never used to train AI models.
- Connect to your inbox, for any reason, including support.
- Send email on your behalf. The app has nothing to send from.
- Sell, rent or share your personal data with third parties for advertising or resale.
8. What we do not have yet
We claim exactly what is true. ReciteMail does not currently hold SOC 2, ISO 27001 or HIPAA certification. We say that plainly rather than imply otherwise. What we offer instead is an architecture where the sensitive data never reaches us in the first place, which is a stronger guarantee than a certificate for most small teams. If your organisation requires formal certifications today, we would rather tell you now than after a procurement cycle.
9. Reporting a vulnerability
Found something real? Email info@recitemail.io with the steps to reproduce, the impact you believe it has and any proof of concept. A human reads every credible report. We will acknowledge yours, keep you posted and credit you if you would like that. Please give us reasonable time to fix an issue before any public disclosure. Our machine readable contact details live at /.well-known/security.txt.
We do not operate a paid bug bounty program and we do not pay for reports.
Out of scope. To keep reports meaningful, the following are not considered vulnerabilities here: missing optional DNS records (MTA-STS, CAA, BIMI, DNSSEC), security header suggestions without a demonstrated impact, raw output from automated scanners, self-XSS, clickjacking on pages with no sensitive actions, password policy opinions and social engineering of our staff. Reports consisting only of these will not receive a response.
10. Who we are
ReciteMail is operated by Velora Prima Limited, a company registered in Ireland (company number 797589), with its registered office at Workhub, 51 Bracken Road, Sandyford, Dublin D18 CV48, Ireland. The fine print lives in our Privacy Policy and Terms of Service. For anything on this page, email info@recitemail.io.