Your inbox should end up with you.
PlugMail combines a standalone Outlook-class desktop client with an optional @plugmail.net address. Messages are committed to an encrypted local vault before the active server copy is removed.
___.-^^-.___
_.-' _ _ '-._
/__ (_)____(_) __\\
\\___/ PLUG \\___/mail.received 1 raw.sha256 verified local.vault committed device.ack signed server.active deleted recovery.expires 71:59:58
The custody handoff
Deletion follows proof, not a timer guess.
- 01receive
PlugMail accepts the full message into the temporary delivery queue.
- 02commit
The primary device verifies the MIME hash and commits it into the encrypted local vault.
- 03acknowledge
The device signs a nonce-bound local-commit acknowledgement.
- 04purge
The active server copy is removed; an encrypted recovery copy expires within 72 hours.
All accounts
One desktop, standards first.
Add PlugMail, generic IMAP/SMTP and provider presets. Third-party mail remains upstream unless you explicitly export or delete it there.
100 on cloud, not forever
Free mailbox boundary.
Free stores at most 100 live unsynchronized PlugMail messages. Local storage is limited by your device, not by a cloud upsell.
Receipts, not vibes
See custody state per message.
Local hash, signed acknowledgement, active-copy deletion and recovery expiry are represented as explicit states.
Keep your old addresses. Stop living inside their client.
PlugMail is designed as the smooth migration path away from Outlook-style cloud dependence: add your existing accounts, build your local archive, then claim a PlugMail address when you are ready.
read the exact custody model