Compatible and Sealed

Compatible and Sealed are the two levels of protection at privymail.eu: what the server can see and when, where the keys are, and what Sealed costs.

You choose per folder how far the protection goes: Compatible for everyday use with any mail app, Sealed for content that we cannot read either. This page says what each level does, where its limit is and what it costs.

What matters

Two levels. You choose per folder.

Compatible is the default for new accounts, Sealed the option for individual folders. The interface shows for every folder which level it is in.

Stored encrypted. Even while you are signed out.

In the default mode, Compatible, the server encrypts incoming mail with your account's public key; you do not have to be signed in for that. It can only be decrypted with the private key, which is protected by your secrets.

No home-made cryptography.

Compatible uses the encryption of the Dovecot server software, Sealed the OpenPGP standard (RFC 9580). We do not invent schemes of our own.

What the server can see, and when

MomentCompatible (default)Sealed
A message arrivesThe server can read it. It checks it for spam, applies your filters and then encrypts it with your account's public key.The same, if the sender sends unencrypted: the server encrypts on arrival with your public OpenPGP key. If the sender has already encrypted with OpenPGP, the server never sees the content.
The message is in the mailboxEncrypted. The private key is on the server only in locked form.Encrypted. The private key never leaves your device unencrypted.
You are signed inThe server decrypts and delivers over TLS. In doing so it processes plain text.The server delivers only encrypted data. Decryption happens on your device.

For Compatible this means: during a session, an attacker with full access to the running server could read along, and so could an operator with manipulated software. Access controls, the four-eyes principle, signed deployments and audit logs stand against that. Only Sealed protects against a compromised operator. Compatible is therefore neither zero access nor end-to-end encryption.

Where the keys are

Compatible. Every account has its own key pair. The private key is on the server, but only in locked form: with a separate copy for your password, for each app password and for each recovery code. It is unlocked in memory only during a session. If you revoke an app password, the service deletes its copy as well.

Sealed. The private OpenPGP key never leaves your device unencrypted. Decryption happens there, not on the server. We can therefore neither read nor hand over what is in a Sealed folder.

What Sealed costs

  • Ordinary mail apps stay outside. An app that only speaks IMAP does not open Sealed folders directly. Access goes through our own apps, which decrypt on your device.
  • Search on your device only. The server cannot search a Sealed folder; the search index is on your device.
  • Protection from arrival, not before. The server sees mail that was sent unencrypted before it encrypts it. It processes sender, recipient and time for delivery at either level.
  • No way back through us. Without your private key the content cannot be read, not even by us. There is no master key.

Everything at a glance

  • Choice per folder: Compatible is the default, Sealed the option; the interface shows the level of every folder.
  • Compatible, keys: a separate key pair per account; the private key is on the server only in locked form.
  • Compatible, access: any IMAP app, without extra software.
  • Sealed, method: OpenPGP (RFC 9580); decryption happens on your device.
  • Sealed, scope: attachments, contacts and calendars as well as mail.
  • Public keys: WKD publishes public OpenPGP keys, Autocrypt exchanges them.
  • Switching: your device switches a folder to Sealed. It downloads the mail, re-encrypts it and uploads it; the server then deletes the previous copy.
  • Transport: at both levels, TLS 1.3 preferred and TLS 1.2 as the minimum.
  • Plans: Compatible and Sealed folders are part of all paid plans.

Questions about the levels of protection

Is Compatible end-to-end encrypted?

No. Compatible is neither zero access nor end-to-end encryption: the server decrypts in order to deliver to your mail app. In return, any IMAP app works without extra software.

Can you read my mail?

In Compatible folders, technically yes, as long as you are signed in. In Sealed folders, no. At both levels the server sees mail that was sent unencrypted when it arrives.

Can I switch a folder to Sealed?

Yes. Your device downloads the mail, re-encrypts it and uploads it; the server then deletes the previous copy. Switching is a separate, unambiguous step with an explanation.

Does my mail app open a Sealed folder?

No, not directly. An app that only speaks IMAP receives nothing readable from the server; decryption happens on your device, in our own apps.

What happens if I forget my password?

Then a recovery code helps: with it you set a new password, and your stored mail remains readable. Without a code there is no way to the content; we have no master key. More under Signing in and your account.