Ruber

Mailbox modes

Smart and Private, in full.

Ruber does not decide how much privacy your mailbox should have. Smart is standards-first and gives you everything email can do; Private reveals as little as possible. Both are deliberate. This page is the whole trade-off, including the parts that go against us.

Smart never sacrifices functionality to imitate Private. Private never sacrifices privacy to imitate Smart.

Smart

Everything email can do.

  • IMAP + SMTP
  • Any mail client
  • Full-text search
  • REST API
  • Integrations
  • Server-side filters
  • Spam learning
  • AI features

The mail plane can process message contents, so standard protocols, search, automation and integrations work normally.

Private

As little access as possible.

  • Zero-access storage
  • Ruber ↔ Ruber E2EE
  • Encrypted subjects
  • Encrypted bodies
  • Encrypted attachments
  • Client-side decryption
  • Recovery key
  • Verified sender

Message contents are encrypted for the user instead of being available to the mail plane.

What actually differs

  • Fully available
  • Limited
  • Not available
  • Same in both
CapabilitySmartPrivate
Protocols and clients
IMAP and SMTPFully availableDirectFully availableDirect
Third-party mail clientThe mailbox is reachable either way. What differs is whether what comes back is readable.Fully availableReads everything normallyLimitedReaches the mailbox, cannot decrypt content
Ruber clientFully availableOptionalFully availableThe primary experience
Search, filters and automation
Full-text searchFully availableServer-side, across the whole mailboxNot availableNot available — the server cannot read the message
Client-side searchFully availableAlso availableFully availableIn the Ruber client, after decryption
Server-side filtersEnvelope means sender, recipient and routing headers — the parts SMTP leaves in the clear.Fully availableContent and headersLimitedEnvelope rules only
AI featuresFully availableAvailableNot availableNot available on message contents
IntegrationsFully availableCan read message contentsLimitedReceive events and metadata, not contents
REST APIFully availableFull message accessLimitedMetadata and ciphertext
Spam and phishing scoringInbound scoring happens on arrival, before anything is stored, so it is identical in both modes. What differs is learning from mail already in the mailbox.Fully availableScored on arrival; learns from stored contentLimitedScored on arrival; no learning from stored content
Encryption
StorageNot availableStored unencrypted; readable by RuberFully availableZero-access — keys are yours
Subject, body, attachmentsNot availableReadable by the mail planeFully availableEncrypted
Ruber to RuberLimitedTLS in transit, readable at restFully availableEnd-to-end
Mail from outside RuberThis is the row people misread. A message from Gmail travelled as plaintext SMTP before it arrived; encrypting it on receipt protects it from that point on, and is not end-to-end.Not availablePlaintext when it arrives, and plaintext once storedLimitedPlaintext until it arrives, then encrypted to your key
Key custodyNot availableRuber holds themFully availableYou hold them; a recovery key is issued at setup
What encryption does not hide
Sender and recipientSMTP needs these to route a message. No mailbox design removes them, and any product implying otherwise is describing something other than email.Same in both modesVisibleSame in both modesVisible
Date and timeSame in both modesVisibleSame in both modesVisible
Approximate message sizeSame in both modesVisibleSame in both modesVisible

Mail from outside Ruber cannot be end-to-end encrypted.

This is the part most often got wrong, so it is drawn rather than asserted. A message from Gmail crosses the internet as ordinary SMTP before it reaches us. Private encrypts it on receipt, which protects it from that point onward — it does not reach back and change what already happened.

  1. 01GmailComposes and sends
  2. 02The internetPlaintext SMTP, TLS between hops
  3. 03Ruber mail planeScored, then stored
  4. 04Your mailboxSmart: stored readable · Private: encrypted to your key

End-to-end means neither end's provider can read it. That is only possible when both ends are Ruber mailboxes, which is what Ruber ↔ Ruber E2EE covers.

Same domain. Different needs.

Mode is set per mailbox, not per account and not per domain. One company runs both, because the addresses do different jobs.

acme.com

4 mailboxes

  • support@acme.comShared, searchable, routed by filtersSmart
  • sales@acme.comFeeds the CRM through the APISmart
  • ceo@acme.comRead in the Ruber client onlyPrivate
  • legal@acme.comContracts and privileged correspondencePrivate

Which one for which mailbox

Smart

  • Several people need to read the same inbox.
  • You search old mail often, from more than one device.
  • Something automated reads the mailbox — a CRM, a helpdesk, your own code.
  • You want it to work in the client you already have open.

Private

  • The mailbox carries contracts, health, legal or board material.
  • You would rather the provider could not read it, even under compulsion.
  • You are willing to give up server-side search and integrations for that.
  • You are content to read it in the Ruber client.

True in both modes

  • The domain is yours, and the MX record is what moves mail — in either mode.
  • MX, SPF, DKIM and DMARC are written and verified for you either way.
  • Every inbound message is scored before delivery in both modes.
  • The mailbox is reachable over IMAP in both modes.
  • Leaving is the same in both: point the MX elsewhere and take the mail with you.

What Private cannot do yet.

Both modes run today and mode is a per-mailbox setting, so nothing you choose now forecloses the other. Private mail is read in the Ruber client because nothing else holds the keys to decrypt it — that is the trade the mode is for, not a gap. Three other things are genuinely unfinished.

There is still no date on the three below, for the reason there was never one on Private itself: a date is a promise about work that is not written yet.

Runs today

  • Real mailboxes on a domain you own
  • IMAP and SMTP, in the mail client you already use
  • MX, SPF, DKIM and DMARC written and verified for you
  • Every inbound message scored before it is delivered
  • Mail stored in the EU, under row-level security on the control plane
  • Zero-access storage, with the keys yours rather than ours
  • Subjects, bodies and attachments encrypted before they reach us
  • End-to-end encryption between Ruber mailboxes
  • A recovery key issued at setup

Still being built

  • Search inside a Private mailbox, which has to run after decryption in the client
  • Sealed reading in custom folders, and in the Starred and Drafts views
  • Private mail on the mobile app, which still shows a sealed pane