Security & transparency

How koalo keeps your messages private - and the honest limits of what's possible. Hover any highlighted term for the details.

How your mail stays private

01

Your keys are created on your device

When you sign up, your browser generates your keypair locally and derives everything from your master password with PBKDF2-SHA256. Nothing secret is ever sent to us.

02

Messages encrypt before they leave

Every message between koalo users is sealed with AES-256-GCM on your device. Recipients are reached with ECDH P-256 key exchange - a shared secret that only exists on your two devices.

03

We store ciphertext, nothing more

Our servers hold encrypted blobs they have no way to read. That's zero-knowledge: nothing to leak, nothing to sell, nothing to hand over.

A real, permanent inbox - not a temp mail

koalo is not a disposable or throwaway service. Your @koalo.cc address is yours to keep, your messages stay until you delete them, and you can send and receive for as long as you have an account. We built koalo to replace your inbox - not to burn one.

No personal data

Your identity is your business. Registration requires no phone number, no backup email, and no real name. We don't log IP addresses or track your location.

No tracking pixels

Remote images and sender logos are never loaded from the open web. Avatars are generated locally on your device, so opening a message never pings a third party - there are no read-receipts or tracking pixels.

Active protection, around the clock

Encryption protects your messages; layered defenses protect your account. Every sign-in attempt is checked at the edge before it ever reaches your data.

Instant alerts
Repeated failed sign-ins trigger a security mail to your inbox - you know before anything happens.
Brute-force defense
Escalating rate limits and temporary locks stop password guessing at the edge, automatically.
Privacy dashboard
A live view inside your inbox: what we store, recent security activity, and one-click data export.

Under the hood

The exact primitives koalo runs on. No proprietary crypto - only standards trusted across the industry.

Message encryption
AES-256-GCM
Key exchange
ECDH P-256
Key derivation
PBKDF2-SHA256 · 310k
Trust model
Zero-knowledge

Who's behind koalo

koalo is built and operated from Germany by a small independent team - no investors, no ads, no data resale. We're real people who think private email shouldn't be a luxury.

A note on external email

Email to outside providers (Gmail, Outlook, and others) cannot be end-to-end encrypted - that's a limit of how email works everywhere, not just here. Those messages are protected in transit, but once they reach an external inbox they follow that provider's standards. koalo ↔ koalo messages are always fully private.

Create your account

Free · No personal data required