Encrypted mail and messenger for the whole organisation
Every message your organisation sends inside Private.Ki — every mail, every chat, every group — is fully encrypted on the sender's device, and nobody can read it: not us, not the hosting provider, not anyone. There is no way to send an unencrypted message inside Private.Ki. One address per person, mail and messenger in one app, keys that never leave the device.
Encryption first. Everything between colleagues — mail with its subject and attachments, one‑to‑one chats, groups, reactions, voice messages — is encrypted on the device before it leaves and can be read only on the recipient's device. No one else can read it, including us. Mail to outside providers is encrypted when the recipient has a key and clearly flagged when it is not. How the encryption works →
Every device holds its own key. The server holds ciphertext and a delivery log.
Each colleague signs up once and gets an address. Their key pair is created on their laptop or phone during signup; additional devices are paired by QR code and receive the key directly, not via us. Mail and chat between colleagues is encrypted to each recipient's key before it leaves the sender's device.
- Inside the company — mail, chat and groups fully encrypted, subject included. Every group message is encrypted once per member, to that member's own key.
- Partners on Private.Ki — the same encryption. People without an account come in by single‑use link or QR code.
- Partners on other providers — encrypted when you have imported their PGP key; otherwise sent as ordinary mail and marked so.
- On our side — ciphertext, public keys, and the routing metadata any mail provider needs: who wrote to whom, when, how large.
Green lines carry ciphertext that only the recipient's device can open. The amber line is ordinary internet mail, and the app says so on the message.
A verdict on every message, so nobody has to guess
Internal mail is encrypted end to end, subject line included, and signed. Each message shows on its face whether it was encrypted to the reader's key and whether the signature verified — a padlock and a shield, checked on the device, not a policy page.
Settings → Keys) and mail you send them is encrypted with it, even though they use another provider. Your own public key can be exported and sent to them.
Chat and groups in the same app, encrypted once per person
One‑to‑one chats and groups, fully encrypted, in the same account as the mail. Every group message is encrypted separately to each member's key, which is why a group can only hold people who already have one — and why nobody added later can read what was said before.
Messages with a timer are removed from both devices when it runs out — not hidden on one. A shared policy that sets defaults for the whole organisation is part of the planned Teams tier; today each conversation is set by its participants.



Bring outside people into an encrypted chat with a single‑use link
A colleague creates an invitation — as a link or as a QR code — with a validity they choose. It works for one person, once. The guest creates an account and a key on their own device, and the chat with the colleague opens encrypted. Nothing about the invitation lets us read what follows.
Passwords that never reach us, a second factor, and devices that vouch for each other
At sign‑in the password itself is never transmitted: the device proves it knows the password without sending it, so we never receive it. A time‑based code from any authenticator app can be required on top. New devices are brought in by QR code from one that is already unlocked, and both screens show the same short code before anyone presses approve.
The second factor is a TOTP code. New devices are added by QR pairing from a device that is already unlocked, not by typing the password again somewhere new.
- Password never sent — it is used on the device to prove itself; it is not transmitted, not even hashed.
- TOTP two‑factor — any authenticator app. Asked for at every sign‑in once switched on.
- QR device pairing — a phone scans the desktop; both show the same code; the desktop approves. The dialog says plainly that approving hands over the mailbox.
- QR sign‑in — a device on the sign‑in screen shows a single‑use code that expires in seconds; a signed‑in device scans it.
- Lock screen — lock from the account menu at any moment. Unlock with the passphrase, or with a PIN or fingerprint / face recognition on iOS and Android.



The ordinary parts of office mail, kept ordinary
Undo send with a window each person sets. Signatures with a default. Attachments to 25 MB, encrypted like the message. Search across every folder for senders, subjects and addresses — never message bodies, because they are not indexed anywhere. Archive, Trash, and swipe actions on phones.




[email protected], with the keys still on your devices Coming soon
Today every account has an address on private.ki. Own‑domain addresses are planned for the Plus and Teams tiers: your domain's mail records would point at Private.Ki, mail to [email protected] would be delivered to the same encrypted mailbox, and nothing would change about where keys live. This is not available yet; the diagram shows the intended design.
Planned for Plus (up to 10 addresses and aliases on one account) and Teams (per seat). Outbound mail from your domain would follow the same rules as today: PGP when the recipient has a key, flagged when not. Not available yet; details may change before it ships.
Until own domains ship, teams use one address per person on private.ki. Nothing described in the sections above depends on the domain. See the planned tiers →
One roster, one bill, shared policies Coming soon
Everything above is in the free account today, per person. Teams is the planned tier for organisations that need to manage seats centrally. Every item below is planned, not shipped; the free product is what exists now.
Teams includes everything planned for Plus (from $5 a month, planned), for every seat. Paid tiers will never gate encryption, two‑factor or timers behind a price. Compare the plans →
Talk to usWhat our server can and cannot see — the short version
Identical for every account and every plan. The full list, kept in sync with the backend, is on its own page.
Cannot see
- Message bodies, mail and chat
- Attachments, including voice messages
- Private keys and passphrases
- Passwords — never sent to us
- Subject lines of internal mail
- Recovery addresses — a hash only
Can see
- Who messaged whom, and when
- Message sizes and attachment counts
- Public keys, group membership and size
- IP addresses at connection time
- Headers of external mail
If we were compelled to hand over a team's conversations, we would be handing over encrypted blobs and this delivery log. Read the full page →
Built for data minimisation — with tools, not certificates
We publish no certifications and no third‑party audit yet, and we will not claim one until it exists. What we offer a compliance review instead is a precise description of what we hold, and controls that let a team keep less of it.
How a team gets started today
No phone number, no invitation, no contract. Four steps, and the fourth is done per conversation.



Web today; iOS and Android apps are built and will be listed. The badges notify you when they are.
Start with the free account. Tell us what the Teams tier should do.
Everything on this page that is not marked coming soon is in the free account now. Everything that is, we are building — and we would rather hear what your organisation needs before it ships.
No phone number required. Keys are created on your device during signup.