KeyGuarded was built on a simple idea: nobody should have to trade privacy for a working inbox. This document walks through what we collect, why we collect it, and the limits we've put on ourselves around your data.
We can't read your emails. Our architecture is set up so that message content and attachments are encrypted before they ever touch our servers, and we hold no key to unlock them.
Encryption blocks us from your inbox itself, but a small set of operational details still passes through our systems:
None of this data sits idle. It goes toward:
AES-256 encryption locks down your messages on your own device, before transmission even starts. Combined with our zero-knowledge model, that means decryption isn't something we're capable of, regardless of who's asking. Our servers themselves are hosted in jurisdictions known for tight data protection law.
Your data isn't for sale, and we don't lease it out either. The narrow exceptions where anything gets shared:
Nothing here is locked in on your end. You can request a copy of your data, correct what's wrong, delete your account outright, push back on processing you disagree with, or export everything in a portable format.
We keep this minimal. Cookies here exist for security and basic functionality, not tracking or advertising. Your browser settings give you full control over them.
Servers run out of Switzerland, chosen deliberately for its privacy framework. If you're logging in from outside that region, your data may briefly pass through these systems, all of which sit under solid protection law.
This service is built for users 16 and older. We don't set out to collect data from anyone younger, and if we learn that's happened, that data gets removed.
Expect this page to evolve. Whenever it does, the date at the top changes, and meaningful updates get flagged here directly.