Our position
You own your data. Not Big Tech. Not us.
Most email providers' business model depends on holding you. Ours doesn't — and we've built the product so you can check that claim, not just read it.
01
Clean exit, any time
A standards-based export of all your mail is a server-side feature we control — not a favour granted by a platform that profits from keeping you. You can leave tomorrow, and it costs nothing.
02
One-button wipe with a deletion certificate
When you leave (or delete a mailbox), deletion is an operation we run, not a promise. You receive a signed deletion certificate and post-wipe verification. No silent retention.
03
Local-only AI by default
In the default local-only mode there is no third party in the mail path at all. We don't need a policy saying your mail isn't used for training — there is no model outside your server to train.
04
Any cloud AI is a named, logged exception
If you opt into a provider API, it is per-tenant, quota-capped, logged in an AI audit trail, and never a silent fallback. You can switch it off with one toggle.
05
Your mail trains nothing that leaves your server
Pepper learns structure and business logic, never content. Style tuning happens on your own sent mail, inside your own host.
06
Exit is a v1 obligation, not a roadmap item
We ship an exit drill with the product — exercised, documented, and repeatable — before we take your first paying mailbox.
What everyone else does
- • Bolt an assistant onto a mailbox hosted elsewhere, thinking with a cloud model.
- • Two suppliers, two bills — and your mail read in someone else's datacentre.
- • Export throttled, exit friction engineered, retention “for safety”.
What we do
- • We own both halves — the mailbox and the model.
- • Pepper runs where your mail lives: a sub-10 MB runtime inside your mail host.
- • Leaving is a feature: export, wipe, certificate, verification.