How it works
Security and transparency
How koalo keeps your messages private, and the honest limits of what is possible. Defined terms are set out below.
How your mail stays private.
Your keys are created on your device
When you sign up, your browser generates your keypair locally and derives everything from your master password with PBKDF2-SHA256. Nothing secret is ever sent to us.
Messages encrypt before they leave
Every message between koalo users is sealed with AES-256-GCM on your device. Recipients are reached with ECDH P-256 key exchange - a shared secret that only exists on your two devices.
Your mail is stored as ciphertext
Your messages, attachments and vault are encrypted blobs our servers have no way to read. That is zero-knowledge: nothing in your mail to leak, sell or hand over. Three things are not ciphertext, and you should know which: your profile picture is stored as an ordinary image, sign-in records keep a truncated network address for 90 days, and mail from outside koalo reaches us in the clear before we encrypt it to you.
Under the hood. The exact primitives koalo runs on. No proprietary crypto - only standards trusted across the industry.
- Message encryption
- AES-256-GCM
- Key exchange
- ECDH P-256
- Key derivation
- PBKDF2-SHA256 · 310k
- Trust model
- Zero-knowledge
- AES-256-GCM
- Authenticated symmetric encryption that locks each message subject and body. 256-bit keys with built-in tamper detection - the same standard governments use for classified data.
- ECDH on P-256
- Elliptic-Curve Diffie-Hellman lets two koalo users compute a shared secret without ever sending a private key over the wire. The secret only exists on your two devices.
- PBKDF2-SHA256
- Your master password is stretched through 310,000 rounds of hashing to derive your keys. This makes brute-forcing your password punishingly slow for an attacker.
- Zero-knowledge
- Your password and private keys are only ever processed on your own device. Our servers hold your mail as ciphertext they have no way to read, so there is nothing in it to leak, sell or surrender. It does not mean we hold nothing at all: your username, public key, profile picture and 90 days of truncated sign-in records exist in readable form.
What we hold, and for how long.
A real, permanent inbox - not a temp mail
koalo is not a disposable or throwaway service. Your @koalo.cc address is yours to keep, your messages stay until you delete them, and you can send and receive for as long as you have an account. We built koalo to replace your inbox - not to burn one.
No personal data
Your identity is your business. Registration requires no phone number, no backup email, and no real name, and we do not track your location. Sign-ins are recorded so we can warn you about suspicious activity, and those records keep only a truncated network address: the first three blocks of an IPv4 address, the first three groups of an IPv6 one. The full address is never written down, and the records are deleted after 90 days.
Remote images, and what they cost
Mail from outside koalo is shown with its images loaded, and sender logos are fetched from a public icon service, so external mail looks the way it was sent. That has a real cost, and you should know it. A remote image can act as a tracking pixel, so opening an external message can tell the sender that you opened it, roughly when, and the IP address you opened it from. Fetching a sender logo tells the icon provider which domain wrote to you. koalo adds no tracking of its own, and mail between koalo users is unaffected: those avatars come from koalo or are drawn on your device.
Active protection, around the clock.
Encryption protects your messages; layered defenses protect your account. Every sign-in attempt is rate limited and checked against a lockout before your data is touched.
Instant alerts
Repeated failed sign-ins trigger a security mail to your inbox - you know before anything happens.
Brute-force defense
Escalating rate limits and temporary locks stop password guessing automatically.
Privacy dashboard
A live view inside your inbox: what we store, recent security activity, and one-click data export.
What koalo cannot protect you from.
Encryption protects your messages on our servers and in transit. It does not protect a device that is already compromised.
A compromised device
If malware is running on your computer or phone, it is inside the place where koalo decrypts everything. It can read your session token, capture your master password as you type it, and open your vault. No web application can prevent this, and koalo is a web application. Encryption happens on your device, which means your device is the last line of defence, and if it falls there is nothing behind it.
Anyone who has your master password
Your password is the only thing standing between an attacker and your mail. We cannot reset it, we cannot detect that someone else is using it, and we cannot tell a stranger who types it correctly apart from you. If you reuse it anywhere, a breach somewhere else becomes a breach here.
Someone with access to your unlocked browser
A signed-in session lives in your browser. Anyone sitting at your unlocked machine can read your mail without knowing your password. Your vault asks for the password again, but your inbox does not. Sign out when you leave a device you do not control, and use Sign out everywhere in Settings if you think a session is no longer yours.
Mail with people who are not on koalo
A message to a Gmail or Outlook address cannot be end-to-end encrypted, because the other side has no koalo key. Incoming external mail also reaches our servers in the clear before we encrypt it to you. That is a limit of how email works everywhere, not something we can engineer around, and we will not claim otherwise.
Who's behind koalo.
koalo is built and operated from Germany by a small independent team - no investors, no ads, no data resale. We're real people who think private email shouldn't be a luxury.
- Operated from Germany
- koalo falls under German and EU data-protection law (GDPR) - among the strictest privacy regimes in the world. You always know which rules we answer to.
- The team
- An independent two-person project, self-funded and built in our own time. We started koalo because we were tired of email that monetizes attention and metadata. No growth investors to please, no ad network to feed - just an inbox that respects you.
A note on external email
Email to outside providers (Gmail, Outlook, and others) cannot be end-to-end encrypted - that's a limit of how email works everywhere, not just here. Those messages are protected in transit, but once they reach an external inbox they follow that provider's standards. koalo to koalo messages are always fully private.
Free · No personal data required
koalo.cc