Email that belongs to you.
End-to-end encrypted mail with zero-access architecture. Your inbox, your data, nobody else's. Not advertisers, not data brokers, not us.
Enter your invite code to claim your @nomasend.com address.
Join the waitlist and we'll write to you when NomaSend opens to the public.
No credit card. No phone number. No name on the account.
Why it's different
Free email isn't free. You pay for it with the contents of your inbox.
Every major provider scans mail to build a profile: what you buy, who you talk to, where you travel, what you're planning. The profile is the product. NomaSend is built so that there is nothing to scan, because we cannot read what you send.
No identity at the door
Signing up takes a passphrase and nothing else. No phone verification, no recovery email, no legal name, no address book upload. You get an account, not a profile.
Sealed before it leaves you
Message bodies, subject lines, attachments, contacts and calendar entries are encrypted on your device with a key we never hold. What sits on our servers is ciphertext.
Trackers stripped on arrival
Remote images and tracking pixels are blocked before they load, so senders can't see when you opened a message, how often you reread it, or where you were.
Under the hood
Three things happen when you hit send.
The security model matters more than the marketing. Here is the actual sequence, so you can check it against the source when the clients are published.
Your key never leaves the device
Your passphrase runs through Argon2id in the client to derive a vault key. That key unlocks a per-mailbox keypair. Our servers only ever see the public half.
The message is sealed locally
Body, subject and attachments are encrypted with XChaCha20-Poly1305 before upload. NomaSend to NomaSend stays sealed the whole way. Mail to outside addresses goes over enforced TLS, or PGP where the recipient publishes a key.
We forget the delivery
Connection IPs are dropped at the edge rather than written to disk. Header metadata is stored encrypted alongside the body, so the server cannot assemble a social graph out of who you write to.
What a warrant gets
We can't hand over what we can't read.
Plenty of providers promise they won't read your mail. That's a policy, and policies change with ownership, jurisdiction and pressure. Zero-access is different: the server has no key, so the promise holds even when we'd rather break it.
Anything we do hold is on this list. That list is the whole list, and we'd rather you judge us on it than on an adjective.
The part everyone dreads
Bring fifteen years of Gmail with you.
Connect your old account once. NomaSend pulls every message, folder, label, contact and calendar event across in the background, keeps forwarding new mail while you settle in, and rebuilds your filters on the other side.
Leaving is meant to be just as easy. IMAP, SMTP, CardDAV and CalDAV, plus a full mailbox export to plain MBOX whenever you want it. No lock-in is a feature, not a favor.
Who it's for
Built for people with a concrete reason.
Journalists
Source contact that doesn't sit in an ad-tech pipeline, and a mailbox whose contents survive a change of ownership at the provider.
Lawyers and doctors
Correspondence that carries a duty of confidentiality, held somewhere the duty is technically enforced rather than contractually promised.
People in transit
Moving countries, changing banks, between residencies. A mailbox that doesn't need a local phone number to stay alive.
Anyone tired of it
No reason required. Reading your mail to sell you things was never a fair trade, and you're allowed to simply opt out of it.
Straight answers
The questions people actually ask.
If I forget my passphrase, is my mail gone?
Yes, and that is the trade. We hold no copy of your key, so we cannot reset it. At signup you get a recovery phrase; write it down and keep it somewhere physical. With it you can restore the mailbox on any device. Without it, and without your passphrase, the ciphertext stays ciphertext. Any provider that can reset your password for you can also read your mail.
How is search fast if everything is encrypted?
The index is built on your device rather than ours. When mail arrives the client decrypts it locally, updates an encrypted index held in your own storage, and re-seals it. Searching queries that local index, so it returns quickly and never tells our servers what you looked for.
Is my mail encrypted when I write to someone on Gmail?
Not end to end, and nobody can honestly claim otherwise. Mail leaving for an outside provider is encrypted in transit over enforced TLS, but it arrives readable on their servers because that is how ordinary email works. If your recipient publishes a PGP key, we use it. NomaSend to NomaSend is sealed the whole way.
Why an invite code? Why not just open signups?
The beta is capped while we work through migration edge cases and load. Invites go out in batches to the waitlist, in order. Joining the list costs you an email address and nothing else, and we don't use it for anything but the invite.
What can you be compelled to hand over?
Whatever we hold, which is the plaintext list above: an account identifier and how much storage it uses. Message contents, subjects, attachments, contacts and calendar are encrypted with a key we don't have. We intend to publish a transparency report covering every request received and what was produced.
Can I use my own email client?
Yes, through a local bridge that holds your keys and speaks ordinary IMAP and SMTP to your client over localhost, so decryption happens on your machine. Apple Mail, Thunderbird and Outlook all work that way. Web and mobile clients are first-party.
When does the public launch happen?
When migration is boring and the clients are published for review, not before a date we picked for a press cycle. Waitlist members hear first, and we'd rather write to you late than ship something that loses mail.
Private beta
Your inbox should not be a dossier.
Join the waitlist and we'll send an invite as soon as the next batch opens. One email, no marketing, unsubscribe in a click.