Trust & Security
A smart inbox you don't have to take on faith.
Most "private" email asks you to trust a promise. Many AI email tools quietly ship your messages to a US tech giant. Here's exactly how Mailotte's AI and privacy work — in plain language, no asterisks.
How the AI works
European AI, on infrastructure we control.
It runs on European models
The model that reads your mail to help you runs on our own servers in Europe — an open model we host ourselves. Your messages are never sent to OpenAI, Google Gemini, or Anthropic — there is no US AI provider anywhere in the path that reads your mail. (A few non-AI services, like our payment processor and anti-abuse check, are disclosed in our Privacy Policy.)
If our AI is busy, the fallback is still European
On the rare occasion our own model is unavailable, we fail over to Mistral AI — a company based in Paris, on EU infrastructure — under commercial terms that forbid training on your data. If even that's unreachable, features fall back to simple rules. Your mail never leaves Europe to get help.
Never used to train anything
Your email is never used to train a model — ours or anyone else's. No ad profiling, no data resale. You are the customer, not the product.
You're in control of every feature
AI in Mailotte is opt-in: each feature — summaries, memory, financial insights, smart sorting — has its own switch, and the inbox works completely with all of it turned off. Turn on only what you want, whenever you want.
Your data
What we store — and what we never do.
What we do
- ✓ Store your mail on EU servers (Germany and France)
- ✓ Encrypt it in transit, and encrypt your attachments and files at rest
- ✓ Keep AI results (summaries, extracted receipts) in your account, deletable by you
- ✓ Let you export or permanently delete everything (GDPR)
What we never do
- ✗ Scan your mail to sell ads
- ✗ Sell or share your data with brokers
- ✗ Train AI on your messages
- ✗ Send your mail to a non-EU provider
Where your data lives
EU-resident by design, encrypted in transit — and specific about what that covers.
EU data residency
Mailboxes, attachments and account data live exclusively on servers in the European Union (Germany and France).
Encrypted in transit, files at rest
TLS on the wire. Attachments and stored files are encrypted at rest with a key we hold, not our hosting provider's. Message bodies are not encrypted at rest.
Trackers blocked by default
Tracking pixels are blocked before they load, on every plan — no setup.
GDPR-native
Built for UK & EU GDPR. Access, export and erase your data from Account Settings.
Aliases can't log in
Every alias can send and receive, but only your real credentials — with optional two-factor auth — can sign in. Handing out an alias never hands out access to your inbox.
Plain, scoped acceptable use
Our terms ban spam and phishing, malware, illegal use, harassment, impersonation, and abuse of the service itself — unauthorised access, disruption, automated signups, and bypassing security. Specific conduct, enumerated: no vague clauses policing lawful things you're allowed to say. Read them in the Terms of Service.
Being straight with you
What's solid today, and what's still coming.
Encryption in transit, at-rest encryption of attachments and stored files, EU residency, aliases, tracker blocking and custom domains are live today — anyone can sign up, no invite needed. AI-written summaries and drafts are suggestions: read them before you act on them, and verify anything that matters.
Looking for the technical detail rather than the summary? The security page lists what is and is not encrypted, the mail-authentication records you can verify yourself, our subprocessors, how to report a vulnerability — and what we do not claim.