Now in private beta

Email that belongs to you.

End-to-end encrypted mail with zero-access architecture. Your inbox, your data, nobody else's. Not advertisers, not data brokers, not us.

Have an invite?

Enter your invite code to claim your @nomasend.com address.

No invite yet?

Join the waitlist and we'll write to you when NomaSend opens to the public.

No credit card. No phone number. No name on the account.

Encryption
End-to-end, always on
Access
Zero-access by design
Jurisdiction
Swiss privacy law
Source
Open source clients

Why it's different

Free email isn't free. You pay for it with the contents of your inbox.

Every major provider scans mail to build a profile: what you buy, who you talk to, where you travel, what you're planning. The profile is the product. NomaSend is built so that there is nothing to scan, because we cannot read what you send.

01 / IDENTITY

No identity at the door

Signing up takes a passphrase and nothing else. No phone verification, no recovery email, no legal name, no address book upload. You get an account, not a profile.

02 / CONTENT

Sealed before it leaves you

Message bodies, subject lines, attachments, contacts and calendar entries are encrypted on your device with a key we never hold. What sits on our servers is ciphertext.

03 / TRACKING

Trackers stripped on arrival

Remote images and tracking pixels are blocked before they load, so senders can't see when you opened a message, how often you reread it, or where you were.

Under the hood

Three things happen when you hit send.

The security model matters more than the marketing. Here is the actual sequence, so you can check it against the source when the clients are published.

STEP 1

Your key never leaves the device

Your passphrase runs through Argon2id in the client to derive a vault key. That key unlocks a per-mailbox keypair. Our servers only ever see the public half.

STEP 2

The message is sealed locally

Body, subject and attachments are encrypted with XChaCha20-Poly1305 before upload. NomaSend to NomaSend stays sealed the whole way. Mail to outside addresses goes over enforced TLS, or PGP where the recipient publishes a key.

STEP 3

We forget the delivery

Connection IPs are dropped at the edge rather than written to disk. Header metadata is stored encrypted alongside the body, so the server cannot assemble a social graph out of who you write to.

What a warrant gets

We can't hand over what we can't read.

Plenty of providers promise they won't read your mail. That's a policy, and policies change with ownership, jurisdiction and pressure. Zero-access is different: the server has no key, so the promise holds even when we'd rather break it.

Anything we do hold is on this list. That list is the whole list, and we'd rather you judge us on it than on an adjective.

Message bodies encrypted
Subject lines encrypted
Attachments encrypted
Contacts and calendar encrypted
Account identifier plaintext
Storage used plaintext
Connection IP not stored

The part everyone dreads

Bring fifteen years of Gmail with you.

Connect your old account once. NomaSend pulls every message, folder, label, contact and calendar event across in the background, keeps forwarding new mail while you settle in, and rebuilds your filters on the other side.

Leaving is meant to be just as easy. IMAP, SMTP, CardDAV and CalDAV, plus a full mailbox export to plain MBOX whenever you want it. No lock-in is a feature, not a favor.

Instant encrypted search
Snooze and send later
Unlimited aliases
Custom domains
Rules and filters
Offline drafts
Shared calendars
Large attachments
Threaded conversations
Keyboard shortcuts
PGP for outside contacts
Hardware key two-factor

Who it's for

Built for people with a concrete reason.

Journalists

Source contact that doesn't sit in an ad-tech pipeline, and a mailbox whose contents survive a change of ownership at the provider.

Lawyers and doctors

Correspondence that carries a duty of confidentiality, held somewhere the duty is technically enforced rather than contractually promised.

People in transit

Moving countries, changing banks, between residencies. A mailbox that doesn't need a local phone number to stay alive.

Anyone tired of it

No reason required. Reading your mail to sell you things was never a fair trade, and you're allowed to simply opt out of it.

Straight answers

The questions people actually ask.

If I forget my passphrase, is my mail gone?

Yes, and that is the trade. We hold no copy of your key, so we cannot reset it. At signup you get a recovery phrase; write it down and keep it somewhere physical. With it you can restore the mailbox on any device. Without it, and without your passphrase, the ciphertext stays ciphertext. Any provider that can reset your password for you can also read your mail.

How is search fast if everything is encrypted?

The index is built on your device rather than ours. When mail arrives the client decrypts it locally, updates an encrypted index held in your own storage, and re-seals it. Searching queries that local index, so it returns quickly and never tells our servers what you looked for.

Is my mail encrypted when I write to someone on Gmail?

Not end to end, and nobody can honestly claim otherwise. Mail leaving for an outside provider is encrypted in transit over enforced TLS, but it arrives readable on their servers because that is how ordinary email works. If your recipient publishes a PGP key, we use it. NomaSend to NomaSend is sealed the whole way.

Why an invite code? Why not just open signups?

The beta is capped while we work through migration edge cases and load. Invites go out in batches to the waitlist, in order. Joining the list costs you an email address and nothing else, and we don't use it for anything but the invite.

What can you be compelled to hand over?

Whatever we hold, which is the plaintext list above: an account identifier and how much storage it uses. Message contents, subjects, attachments, contacts and calendar are encrypted with a key we don't have. We intend to publish a transparency report covering every request received and what was produced.

Can I use my own email client?

Yes, through a local bridge that holds your keys and speaks ordinary IMAP and SMTP to your client over localhost, so decryption happens on your machine. Apple Mail, Thunderbird and Outlook all work that way. Web and mobile clients are first-party.

When does the public launch happen?

When migration is boring and the clients are published for review, not before a date we picked for a press cycle. Waitlist members hear first, and we'd rather write to you late than ship something that loses mail.

Private beta

Your inbox should not be a dossier.

Join the waitlist and we'll send an invite as soon as the next batch opens. One email, no marketing, unsubscribe in a click.