Trust & Security

A smart inbox you don't have to take on faith.

Most "private" email asks you to trust a promise. Many AI email tools quietly ship your messages to a US tech giant. Here's exactly how Mailotte's AI and privacy work — in plain language, no asterisks.

How the AI works

European AI, on infrastructure we control.

It runs on European models

The model that reads your mail to help you runs on our own servers in Europe — an open model we host ourselves. Your messages are never sent to OpenAI, Google Gemini, or Anthropic — there is no US AI provider anywhere in the path that reads your mail. (A few non-AI services, like our payment processor and anti-abuse check, are disclosed in our Privacy Policy.)

If our AI is busy, the fallback is still European

On the rare occasion our own model is unavailable, we fail over to Mistral AI — a company based in Paris, on EU infrastructure — under commercial terms that forbid training on your data. If even that's unreachable, features fall back to simple rules. Your mail never leaves Europe to get help.

Never used to train anything

Your email is never used to train a model — ours or anyone else's. No ad profiling, no data resale. You are the customer, not the product.

You're in control of every feature

AI in Mailotte is opt-in: each feature — summaries, memory, financial insights, smart sorting — has its own switch, and the inbox works completely with all of it turned off. Turn on only what you want, whenever you want.

Your data

What we store — and what we never do.

What we do

  • ✓ Store your mail on EU servers (Germany and France)
  • ✓ Encrypt it in transit and at rest
  • ✓ Keep AI results (summaries, extracted receipts) in your account, deletable by you
  • ✓ Let you export or permanently delete everything (GDPR)

What we never do

  • ✗ Scan your mail to sell ads
  • ✗ Sell or share your data with brokers
  • ✗ Train AI on your messages
  • ✗ Send your mail to a non-EU provider

Where your data lives

EU-resident by design, encrypted in transit and at rest.

EU data residency

Mailboxes, attachments and account data live exclusively on servers in the European Union (Germany and France).

Encrypted in transit & at rest

TLS on the wire, encryption at rest on disk. Optional PGP (beta) for message encryption.

Trackers blocked by default

Tracking pixels are stripped from incoming mail on every plan — no setup.

GDPR-native

Built for UK & EU GDPR. Access, export and erase your data from Account Settings.

Aliases can't log in

Every alias can send and receive, but only your real credentials — with optional two-factor auth — can sign in. Handing out an alias never hands out access to your inbox.

Plain, scoped acceptable use

Our terms ban spam, malware, phishing and illegal use — and stop there. No vague clauses policing lawful things you're allowed to say. Read them in the Terms of Service.

Being straight with you

What's solid today, and what's still coming.

Encryption in transit and at rest, EU residency, aliases, tracker blocking and custom domains are live today — anyone can sign up, no invite needed. Optional PGP message encryption is experimental. AI-written summaries and drafts are suggestions: read them before you act on them, and verify anything that matters.

Privacy you can see, not just trust.

Start free — no card, no catch.

Start free