Mailbox modes
Smart and Private, in full.
Ruber does not decide how much privacy your mailbox should have. Smart is standards-first and gives you everything email can do; Private reveals as little as possible. Both are deliberate. This page is the whole trade-off, including the parts that go against us.
Smart never sacrifices functionality to imitate Private. Private never sacrifices privacy to imitate Smart.
Smart
Everything email can do.
- IMAP + SMTP
- Any mail client
- Full-text search
- REST API
- Integrations
- Server-side filters
- Spam learning
- AI features
The mail plane can process message contents, so standard protocols, search, automation and integrations work normally.
Private
As little access as possible.
- Zero-access storage
- Ruber ↔ Ruber E2EE
- Encrypted subjects
- Encrypted bodies
- Encrypted attachments
- Client-side decryption
- Recovery key
- Verified sender
Message contents are encrypted for the user instead of being available to the mail plane.
What actually differs
- Fully available
- Limited
- Not available
- Same in both
| Capability | Smart | Private |
|---|---|---|
Protocols and clients | ||
| IMAP and SMTP | Fully availableDirect | Fully availableDirect |
| Third-party mail clientThe mailbox is reachable either way. What differs is whether what comes back is readable. | Fully availableReads everything normally | LimitedReaches the mailbox, cannot decrypt content |
| Ruber client | Fully availableOptional | Fully availableThe primary experience |
Search, filters and automation | ||
| Full-text search | Fully availableServer-side, across the whole mailbox | Not availableNot available — the server cannot read the message |
| Client-side search | Fully availableAlso available | Fully availableIn the Ruber client, after decryption |
| Server-side filtersEnvelope means sender, recipient and routing headers — the parts SMTP leaves in the clear. | Fully availableContent and headers | LimitedEnvelope rules only |
| AI features | Fully availableAvailable | Not availableNot available on message contents |
| Integrations | Fully availableCan read message contents | LimitedReceive events and metadata, not contents |
| REST API | Fully availableFull message access | LimitedMetadata and ciphertext |
| Spam and phishing scoringInbound scoring happens on arrival, before anything is stored, so it is identical in both modes. What differs is learning from mail already in the mailbox. | Fully availableScored on arrival; learns from stored content | LimitedScored on arrival; no learning from stored content |
Encryption | ||
| Storage | Not availableStored unencrypted; readable by Ruber | Fully availableZero-access — keys are yours |
| Subject, body, attachments | Not availableReadable by the mail plane | Fully availableEncrypted |
| Ruber to Ruber | LimitedTLS in transit, readable at rest | Fully availableEnd-to-end |
| Mail from outside RuberThis is the row people misread. A message from Gmail travelled as plaintext SMTP before it arrived; encrypting it on receipt protects it from that point on, and is not end-to-end. | Not availablePlaintext when it arrives, and plaintext once stored | LimitedPlaintext until it arrives, then encrypted to your key |
| Key custody | Not availableRuber holds them | Fully availableYou hold them; a recovery key is issued at setup |
What encryption does not hide | ||
| Sender and recipientSMTP needs these to route a message. No mailbox design removes them, and any product implying otherwise is describing something other than email. | Same in both modesVisible | Same in both modesVisible |
| Date and time | Same in both modesVisible | Same in both modesVisible |
| Approximate message size | Same in both modesVisible | Same in both modesVisible |
Mail from outside Ruber cannot be end-to-end encrypted.
This is the part most often got wrong, so it is drawn rather than asserted. A message from Gmail crosses the internet as ordinary SMTP before it reaches us. Private encrypts it on receipt, which protects it from that point onward — it does not reach back and change what already happened.
- 01GmailComposes and sends
- 02The internetPlaintext SMTP, TLS between hops
- 03Ruber mail planeScored, then stored
- 04Your mailboxSmart: stored readable · Private: encrypted to your key
End-to-end means neither end's provider can read it. That is only possible when both ends are Ruber mailboxes, which is what Ruber ↔ Ruber E2EE covers.
Same domain. Different needs.
Mode is set per mailbox, not per account and not per domain. One company runs both, because the addresses do different jobs.
acme.com
4 mailboxes
support@acme.comShared, searchable, routed by filtersSmartsales@acme.comFeeds the CRM through the APISmartceo@acme.comRead in the Ruber client onlyPrivatelegal@acme.comContracts and privileged correspondencePrivate
Which one for which mailbox
Smart
- Several people need to read the same inbox.
- You search old mail often, from more than one device.
- Something automated reads the mailbox — a CRM, a helpdesk, your own code.
- You want it to work in the client you already have open.
Private
- The mailbox carries contracts, health, legal or board material.
- You would rather the provider could not read it, even under compulsion.
- You are willing to give up server-side search and integrations for that.
- You are content to read it in the Ruber client.
True in both modes
- The domain is yours, and the MX record is what moves mail — in either mode.
- MX, SPF, DKIM and DMARC are written and verified for you either way.
- Every inbound message is scored before delivery in both modes.
- The mailbox is reachable over IMAP in both modes.
- Leaving is the same in both: point the MX elsewhere and take the mail with you.
What Private cannot do yet.
Both modes run today and mode is a per-mailbox setting, so nothing you choose now forecloses the other. Private mail is read in the Ruber client because nothing else holds the keys to decrypt it — that is the trade the mode is for, not a gap. Three other things are genuinely unfinished.
There is still no date on the three below, for the reason there was never one on Private itself: a date is a promise about work that is not written yet.
Runs today
- Real mailboxes on a domain you own
- IMAP and SMTP, in the mail client you already use
- MX, SPF, DKIM and DMARC written and verified for you
- Every inbound message scored before it is delivered
- Mail stored in the EU, under row-level security on the control plane
- Zero-access storage, with the keys yours rather than ours
- Subjects, bodies and attachments encrypted before they reach us
- End-to-end encryption between Ruber mailboxes
- A recovery key issued at setup
Still being built
- Search inside a Private mailbox, which has to run after decryption in the client
- Sealed reading in custom folders, and in the Starred and Drafts views
- Private mail on the mobile app, which still shows a sealed pane