Skip to content
Products
Encrypted Email Messenger Group Chat For teams
Security
How encryption works What our servers can and cannot see Account security Private.Ki over Tor Private.Ki and VPNs
Company
Pricing About Careers Statement Help center Contact
Language
EnglishEN DeutschDE · soon EspañolES · soon FrançaisFR · soon
Create a free account Sign in
Account security

Who can open your account.

Sign‑in, two‑factor, added devices, the lock screen and the recovery address decide who gets to your keys. What happens to your messages once the door is open is a different question — that is encryption, and it has its own page.

Sign‑in

Your password never reaches us.

Ordinary sign‑in sends your password to a server, which hashes it and compares. Ours does not. Your device and our server run a short exchange in which your device proves it knows the password — and the password itself stays on your side of the line.

What we store is a record built from that exchange. It cannot be turned back into your password, and it cannot be used to sign in as you. Someone who copies our database gets a record they can neither reverse nor replay.

Your device your password stays here and unlocks your keys, on this device a blinded request — reveals nothing about the password an answer computed from your record a proof that the password is right the password itself never sent — not at sign‑up, not at sign‑in, not as a hash Our server one record cannot be turned back into the password cannot be used to sign in as you useful only to check a proof
Sign‑in with a wrong password fails on your device before a proof exists; the server learns only that an attempt failed. Every guess costs a full round trip, which is rate‑limited — a long, unique password is still the part that is up to you.

Protocol: OPAQUE, on the web and in the apps.Sessions are bound to a key on your device (DPoP): a session token copied to another machine does not work there.Two‑factor, if on, is asked after this exchange, not instead of it.

Two‑factor

Two‑factor, in three steps.

Standard TOTP, the kind every authenticator app speaks. Set it up once; from then on a stolen password stops at the code.

Set it upSettings › Security and Privacy › Enable TOTP. Scan the QR code with any authenticator app, or copy the secret shown as text.
Sign inAfter the password, six digits from the app. The code changes every 30 seconds. Without it, the sign‑in stops here.
DoneSecurity settings show two‑factor as enabled. The setup checklist stops nagging you about it.
On a new device

Every sign‑in with a password asks for the code, on every device. A device you add by QR code takes over a session that already passed the check, so it is not asked.

Turning it off

Needs one more valid code, from a session that itself passed two‑factor. Someone who only knows your password cannot remove the second factor. Five wrong codes in a row lock code entry for 15 minutes.

Lost the phone with the app?

There are no backup codes. A device that is still signed in can turn two‑factor off — with one last code. Signed out everywhere, support verifies you through your recovery address, and never on your word alone.

Disable TOTP“Enter a code from your authenticator app to disable two‑factor authentication.” Nothing changes until a valid code is accepted.
The setup checklistSettings opens on what is still off — two‑factor, recovery address — with a button next to each.
Add a device

Add a device by scanning.

Your signed‑in computer shows a QR code. Your phone scans it. Both screens show the same six characters; you compare them and approve on the computer. The phone opens your inbox — no password, no passphrase typed on it.

  1. 1
    Computer shows the codeAccount menu › Show my QR code. Single use, valid for 30 seconds.
  2. 2
    Phone showing the pairing code 5WTKX1 and waiting for approval
    Phone scans, shows six characters“Approve on the device that showed the QR code. Only approve if this code matches.”
  3. 3
    Computer shows the same six“A phone is asking to sign in.” Compare. Codes match — approve, or Deny. You have 90 seconds.
  4. 4
    Phone unlocked after pairing, showing the inbox
    Phone opens your inboxSame mailbox, same key. In the apps you then set a six‑digit PIN.
What travels

Your unlocked private key — once, encrypted with a secret only the two devices derive from the scan. Not your password, not your passphrase, not your two‑factor secret.

What the server does

Relays ciphertext it cannot open. The meeting point is a Redis key that lives 30 seconds while the QR code is shown and 90 seconds once a phone has claimed it — then it is gone.

Why the six characters

If they differ, something sat between the two devices or the phone scanned somebody else's code. Deny, and nothing has been transferred.

Before the code, a warning“Nobody else can see my screen, and the phone I am about to use is mine.” You tick it before the QR code appears.
ApprovedThe computer confirms; the phone is signed in. Approve is the deliberate button — Deny is the plain one.
QR sign‑in

Sign in with your phone.

The other way round, for when the new device is the one with a screen and your phone is the one with a camera. On the sign‑in page choose Sign in with a QR codeShow a code here. On your signed‑in phone, open the account menu and choose Scan a code. Same six‑character comparison, same result: the new device opens your mailbox without a password.

PairingThe signed‑in device shows the code.

The new device scans it.

QR sign‑inThe new device shows the code.

Your signed‑in device scans it.

The one sentence that tells them apart: in pairing the code comes from the device that already has your keys; in QR sign‑in it comes from the device that wants them. Both hand over the key, never the password.

On the sign‑in page“Sign in with a QR code” next to the ordinary sign‑in.
Show a code hereThe device that wants in shows its single‑use code and a countdown.
Phone showing a single-use QR sign-in code with a countdown
Or the phone shows itA new phone can show its code for a signed‑in computer with a camera to scan. Every screen in the flow has a button to switch direction.
Lock screen

Locked when you walk away.

Lock account sits in the account menu; on the web, pressing Escape twice does the same. Your mail disappears and the decrypted key is wiped from memory. Locking is entirely local — nothing is sent to us, and there is no recovery link on the lock screen, because there is nothing we could send.

The account menuLock account, one click away. Log out sits next to it and ends the sign‑in altogether.
Locked“Enter your passphrase.” Nothing else is visible, and nothing is readable behind it.
Wrong passphraseIt says so and stays locked.
Web, and after any lock

The lock screen asks for your passphrase — or, if you chose Password only at sign‑up, your password unlocks the keys instead. There is no third way in.

iOS and Android, when the app starts

A six‑digit PIN, or Face ID, Touch ID or a fingerprint in its place. The PIN lives only on the phone and is a gate in front of the app, not a replacement for your password or passphrase.

Unlock methodPassword or Passphrase, switchable in Security and Privacy. Switching to a passphrase clears your other devices' sessions.
Honest footnote for Password‑only accounts. With that method the device keeps an encrypted session so Unlock does not ask for anything. Locking still clears keys and mail from memory, but anyone at your keyboard can press Unlock. Leaving a shared computer? Use Log out, or lock the computer itself. Passphrase accounts always need the passphrase.
Recovery address

Recovery address — for proving the account is yours. Not for passphrases.

You can add an address you control in Settings — any provider, or another Private.Ki address. We send a six‑digit code to it, you type the code back, and from then on the address is stored only as a salted hash. We cannot read it, cannot mail it unprompted, and could not tell you what it was. When you need it, you type it again and we compare it with the hash.

What it does: prove the account is yours if you forget your password, or when support needs to know it is you. What it cannot do: recover a passphrase. The passphrase never reaches us, so there is nothing to send back — zero ways, for us or for anyone. Why that is, on the encryption page →

Recovery address: verified once by a six-digit code, then stored only as a hash
Putting it together

What an attacker needs — and what each thing buys them.

Five things somebody might get hold of, and what each one yields. Where the answer depends on your settings, it says so.

  1. Your password, leaked or guessed
    Nothingwith two‑factor on

    Sign‑in stops at the six‑digit code. Without two‑factor, a password alone opens the account — and with Password‑only unlock, your mail. That is what two‑factor is for; turn it on.

  2. Your password and a current two‑factor code
    Sign‑independs on unlock method

    They are in. With a passphrase your messages stay locked until it is typed, and it was never on any server. With Password‑only unlock they can read your mail — revoke the session from another device (Active Sessions) and change your password.

  3. Your phone, locked
    Nothingwithout the phone's passcode

    The phone's own lock first; when the app starts, its six‑digit PIN or your face or fingerprint. Nothing in the app is readable without them.

  4. Your phone, unlocked and in the app
    Your mailboxon that phone, until you cut it off

    Password‑only accounts: on any other device, Settings › Security and Privacy › Active Sessions › Revoke — every device but the one you are holding is signed out at once; then change your password. Passphrase accounts hold no server‑side session to revoke: change your passphrase, and the lost device's copy stops working.

  5. A copy of our database
    Locked boxesnothing readable

    Encrypted messages, public keys, your private key in encrypted form, an OPAQUE record that cannot be reversed or replayed, and a hash of your recovery address. No password, no passphrase, no plaintext. The full list, item by item →

The door is yours to guard. The messages are locked either way.

Two‑factor, device pairing, QR sign‑in and the lock screen are all in the free account.