At privymail.eu, your device proves that it knows the password without sending it to the server. A second factor adds protection for the account, and it does not take a phone number.
What matters
Your password stays with you. Even when you sign in.
privymail.eu checks the password with the OPAQUE protocol (RFC 9807): your device computes with the password and only proves that it is correct. The password itself does not reach the server; the server stores a verification record that contains neither the password nor an ordinary hash.
A second factor. No SMS, no phone number.
The second factor is a one-time code (RFC 6238) generated by an app on your device, or a passkey. There are no SMS codes, and a phone number is not required.
One password per device. Each revocable on its own.
Mail apps have to store a secret and send it every time they sign in. For this, privymail.eu generates separate app passwords: one per device, each individually revocable, so that your main password is not stored in any mail app.
How signing in works
- Password. Your device carries out the proof with OPAQUE. The password is not sent in the process.
- Second factor. If one is set up, the service then asks for a one-time code, a passkey or a recovery code.
- Session. Only then is the session created. Changes to the account, such as a new password or a new app password, also require that all factors you have set up were verified shortly beforehand; a stolen session cookie alone is not enough for that.
Everything at a glance
- Password proof: OPAQUE (RFC 9807); the password does not reach the server.
- Second factor: voluntary. If one is set up, every sign-in to the account requires it.
- One-time codes: RFC 6238, generated by an app on your device. A code that has been accepted does not work a second time.
- Passkeys: a second factor, not a replacement for the password.
- Recovery codes: you receive them when the account is set up. Each code works once and replaces exactly one factor.
- App passwords: for mail, calendar and address book apps. The service generates them, shows them once and, on revocation, also deletes the associated key copy.
- No SMS, no mandatory phone number: neither for the account nor for the second factor.
- Protection against automatically created accounts: a puzzle that your browser solves (ALTCHA). Puzzle and verification run on our own service; no third-party CAPTCHA service is involved.
- Sessions: you see your sessions and end each one individually. For a session, the service stores neither an IP address nor a browser identifier.
If you forget your password
With a recovery code you set a new password, and your stored mail remains readable. If a second factor is set up, you also need that factor or a second code, because one code replaces exactly one factor. Your mail apps keep working with their app passwords.
Without a recovery code there is no way to the stored content. We do not know your password and have no master key. The service therefore asks whether you have saved the codes, and allows a second factor only after that.
Limits
- The second factor protects access, not the key. It decides whether a session is created and whether someone may change the account. It plays no part in the encryption of your mail.
- App passwords work without a second factor. A mail app signs in with its app password alone. The protection lies in the service generating it at random and in your being able to revoke each one individually.
- The password proof protects the password, not the content. In the default mode, Compatible, the server processes your mail in plain text while you are signed in. For changes to the account, your device also sends a secret that it obtains during the password proof; even then it does not send the password itself.
- One-time codes can be phished in real time. A passkey cannot, because it is bound to the address of the genuine site.
- In the browser, the delivered code counts. A manipulated server could deliver code that captures the password.
Questions about signing in
Do I need a phone number?
No. Neither the account nor the second factor requires a phone number, and there are no SMS codes.
Is the second factor mandatory?
No. It is voluntary. If one is set up, every sign-in to the account requires it.
Does a passkey replace the password?
No. A passkey is a second factor. The password remains necessary because access to your mailbox key is derived from it.
Can you reset my password?
No. We do not know it and have no master key. You set a new password yourself, with a recovery code.
Does the second factor also protect my mail app?
No. A mail app signs in with its app password, without a second factor. If a device is lost, you revoke its app password.
Related pages
- Compatible and Sealed: what the server can see, and when.
- The mailbox: webmail, mail apps and filters.
- Mail apps and open standards: signing in from mail apps.
- Security: principles and encryption.
- Privacy: what data arises and how long it is kept.
- Roadmap: building blocks and their order.