Duva
Security

Your mail, encrypted with a key that’s yours.

Duva stores your mail encrypted, one key per mailbox, and keeps the keys somewhere it can’t copy them from. Here is exactly what that means.

Encrypted at rest

Message bodies, subjects, previews and the Google credentials for each mailbox are AES-256-GCM ciphertext in our database. A copied disk or a stolen backup contains nothing readable.

One key per mailbox

Each mailbox is sealed with its own key. That key is wrapped by AWS KMS and only exists unwrapped in memory, briefly, while Duva is working on your mail.

Delete means delete

Disconnect a mailbox and its key is destroyed. Every copy of that mail, in every backup we have ever taken, becomes unreadable at that moment. No retention period to wait out.

Every read leaves a trace

Each time a key is unwrapped, AWS records which mailbox it was for. That log lives outside Duva's servers and can't be edited from them.

What Duva can see

Duva reads your mail to sync it, search it and draft replies. That happens on our servers, with the key in memory. It isn’t end-to-end encryption, and we won’t call it that.

  • Sender addresses, recipients and dates stay readable, so the inbox can sort and filter them.
  • The search index holds message text, on the same server as the database, behind its own credentials.
  • When you ask for a draft or a summary, the messages it needs go to OpenAI to produce it. They aren't used to train models.

Leaving takes everything with you

Delete your account in Settings and it all goes at once: mail, attachments, keys. Duva’s access to your Google account is revoked in the same step. Nothing is kept for a grace period, and nothing is sold, ever.

One plan, $29.99 a month

Duva’s use of information from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.