Neruna Join the beta

Security & privacy

Your data belongs to you. We mean that technically.

Here's what Neruna stores where – and what it doesn't. The legal privacy policy of this website is a separate page.

Neruna Desktopon your computer · local offline copy
Mail, events, contactsdirect, encrypted (TLS)
Your serveryour provider's or company's mail server
configuration onlyoptional
Neruna CloudConfiguration, encrypted certificates – no mail, events, contacts
Mail, events and contacts flow directly between Neruna Desktop and your server. Neruna Cloud is optional and only gets configuration.

01 What lives where

An honest table.

WhatWhereCan Neruna read it?
Mail, events, contactsYour server – and as an offline copy on your computerNo – it never passes through us
Passwords, sign-in tokensYour system keychainNo
S/MIME keys and account passwords from Neruna CloudNeruna Cloud, encrypted per deviceNo – zero knowledge
Personal backup (vault)Neruna Cloud, encrypted with your vault passwordNo – zero knowledge
Organisation, profiles, groups, devices, signatures, templatesNeruna CloudYes – that's the configuration
Chat messagesNeruna Cloud, only if your organisation uses the chatYes, unencrypted, 1 day to 3 months
Crash reportsNeruna Cloud, only with your consentYes, cleaned, 90 days

The only exception: the chat – and only with Neruna Cloud. Without Neruna Cloud there is no chat, and so no user data with us. If you use it: chat messages are kept unencrypted in the cloud (in Switzerland), only as long as the organisation decides. For anything confidential: email with S/MIME.

Security of Neruna Cloud
02

End-to-end via S/MIME

For anything confidential: email with S/MIME. Neruna signs automatically and encrypts as soon as all recipients have a certificate.

03

Encrypted in transit

To your servers and to Neruna Cloud via TLS. For Microsoft accounts you sign in directly with Microsoft – Neruna never sees the password.

04

Devices with their own key

Connect with a one-time code and a separate PIN; an intercepted email alone is never enough. Lost devices are blocked by admins in the portal.

05

No spies in mail

Remote images – often tracking pixels – stay blocked until you allow them for a message or a sender.

06

No telemetry

The app sends us no usage data. Crash reports only if you agree – you see exactly what is sent beforehand; addresses, names, servers and paths are removed.

07

Verifiable

The source of Neruna Desktop is open. Anyone can read how the app talks to your server and to the cloud.

Found a vulnerability?

Please report it confidentially – SECURITY.md explains how. Thank you!