Privacy and encryption in Mail
How zero-access encryption works in TACENZA Mail, what it doesn't protect, why remote images stay off, and how reporting and suspension work.
TACENZA Mail is built to know as little about you as it can. This page explains zero-access encryption and its limits, why images from the internet stay hidden, and how reporting works. The web app loads no analytics, fonts or scripts from third parties.
Zero-access encryption
With encryption on, new mail is stored encrypted with a key only you have. Sign-up accounts are encrypted from the start; anyone else can turn it on.
Turn it on
- Select Encryption in the sidebar.
- Enter the password you sign in with and select Turn on encryption.
- Your browser makes a key pair. The mail server gets only the public half. The private half is locked with your password.
- A recovery key is shown once. Copy it, store it away from this computer, tick I’ve saved my recovery key somewhere safe and select Done.
After a reload, encrypted mail asks for your password again to unlock it on that device.
Your recovery key is the only way to open encrypted mail if you forget your password or an admin resets it. We don’t keep a copy. Lose both your password and the recovery key, and that mail can’t be read by anyone, us included.
What’s encrypted
- Encrypted: the text and files of new mail you receive, and your copy of mail you send.
- Not encrypted: who a message is from and to, the subject and the date. The server needs those to deliver and sort mail. Assignments and read state in shared inboxes stay readable too.
- Mail from before encryption stays as it was.
- Drafts aren’t encrypted.
With encryption on, we can’t read your stored mail. That still isn’t end-to-end.
- Mail from Gmail, Outlook and others arrives unencrypted, because that’s how email works. It’s encrypted with your key the moment it’s stored. Spam filtering runs before that.
- The provider on the other side can read what you send them.
- Your password unlocks your key, and it passes our server when you sign in. We don’t keep it, but for now that’s a promise, not something you can check. Signing in without the server ever seeing your password is on the roadmap.
- Mail apps like Outlook or Apple Mail see encrypted messages as encrypted. Exporting your key isn’t built yet.
If a conversation must stay between two people, use TACENZA Chat, which is end-to-end encrypted. See How encryption works.
Shared addresses
Anyone on a shared address can turn on its encryption under Encryption, once their own encryption is on and unlocked. The address gets its own key, given to everyone on it who has encryption on.
- Mail to a shared address is encrypted by our server a few seconds after it arrives. For those seconds, a new message is stored unencrypted.
- People on the address without encryption can’t read its encrypted mail. Encryption lists them.
- When someone leaves the address, new mail gets a new key they don’t have.
Images from the internet stay off
Loading an image from the internet tells the sender that you opened the mail, and roughly where you are. So these stay hidden until you select Show images. Images sent inside the mail show right away.
Reporting a message
Every message you received has Report (not in Sent or Drafts).
- Open the message and select Report.
- Choose Spam, Phishing or a scam, Harassment or threats or Something else, and add a note if you like.
- Select Report.
Spam and phishing are moved to Spam. The abuse team sees who sent it, the subject, the start of the message and that you reported it. If the message didn’t come from a TACENZA Mail account, nothing is stored.
Suspension
A sign-up account is suspended automatically when three different people report it within a week. Reporters whose own account is less than a day old don’t count. The abuse team then keeps or lifts it, and can suspend accounts itself. Company accounts are never suspended automatically.
A suspended account can’t send, but can still sign in and read mail, and sees the reason. See Reporting abuse.