End-to-end via S/MIME
For anything confidential: email with S/MIME. Neruna signs automatically and encrypts as soon as all recipients have a certificate.
Security & privacy
Here's what Neruna stores where – and what it doesn't. The legal privacy policy of this website is a separate page.
01 What lives where
| What | Where | Can Neruna read it? |
|---|---|---|
| Mail, events, contacts | Your server – and as an offline copy on your computer | No – it never passes through us |
| Passwords, sign-in tokens | Your system keychain | No |
| S/MIME keys and account passwords from Neruna Cloud | Neruna Cloud, encrypted per device | No – zero knowledge |
| Personal backup (vault) | Neruna Cloud, encrypted with your vault password | No – zero knowledge |
| Organisation, profiles, groups, devices, signatures, templates | Neruna Cloud | Yes – that's the configuration |
| Chat messages | Neruna Cloud, only if your organisation uses the chat | Yes, unencrypted, 1 day to 3 months |
| Crash reports | Neruna Cloud, only with your consent | Yes, cleaned, 90 days |
The only exception: the chat – and only with Neruna Cloud. Without Neruna Cloud there is no chat, and so no user data with us. If you use it: chat messages are kept unencrypted in the cloud (in Switzerland), only as long as the organisation decides. For anything confidential: email with S/MIME.
Security of Neruna CloudFor anything confidential: email with S/MIME. Neruna signs automatically and encrypts as soon as all recipients have a certificate.
To your servers and to Neruna Cloud via TLS. For Microsoft accounts you sign in directly with Microsoft – Neruna never sees the password.
Connect with a one-time code and a separate PIN; an intercepted email alone is never enough. Lost devices are blocked by admins in the portal.
Remote images – often tracking pixels – stay blocked until you allow them for a message or a sender.
The app sends us no usage data. Crash reports only if you agree – you see exactly what is sent beforehand; addresses, names, servers and paths are removed.
The source of Neruna Desktop is open. Anyone can read how the app talks to your server and to the cloud.
Please report it confidentially – SECURITY.md explains how. Thank you!