Encrypted at rest
Message bodies, subjects, previews and the Google credentials for each mailbox are AES-256-GCM ciphertext in our database. A copied disk or a stolen backup contains nothing readable.
Duva stores your mail encrypted, one key per mailbox, and keeps the keys somewhere it can’t copy them from. Here is exactly what that means.
Message bodies, subjects, previews and the Google credentials for each mailbox are AES-256-GCM ciphertext in our database. A copied disk or a stolen backup contains nothing readable.
Each mailbox is sealed with its own key. That key is wrapped by AWS KMS and only exists unwrapped in memory, briefly, while Duva is working on your mail.
Disconnect a mailbox and its key is destroyed. Every copy of that mail, in every backup we have ever taken, becomes unreadable at that moment. No retention period to wait out.
Each time a key is unwrapped, AWS records which mailbox it was for. That log lives outside Duva's servers and can't be edited from them.
Duva reads your mail to sync it, search it and draft replies. That happens on our servers, with the key in memory. It isn’t end-to-end encryption, and we won’t call it that.
Delete your account in Settings and it all goes at once: mail, attachments, keys. Duva’s access to your Google account is revoked in the same step. Nothing is kept for a grace period, and nothing is sold, ever.
Duva’s use of information from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.