Our amanah to you
In Islam, amanah means trust and responsibility. When you give us your email, you are trusting us with your private communication. We take that seriously.
This page tells you exactly what we protect, what we don't, and what you can do to protect yourself further. No marketing language. No vague promises. Just the truth.
Encryption in transit
All connections between your device and our server are encrypted with TLS, secured by Let's Encrypt certificates. Nobody between you and our server can read your email in transit.
Encryption at rest
Today your mail is not encrypted at rest. It is stored on our mail server in a form our systems can read. That is what makes delivery, spam filtering and search work, and it is true of almost every email provider including the large ones. We would rather tell you than let you assume otherwise.
What that means in practice: whoever holds the disk, or root on that server, can read stored mail. That is us, and it is the company whose hardware the server runs on. We are not going to describe this as encrypted until it actually is.
If you need mail we cannot read, use OpenPGP in your client (below). Until then, treat the server as a trusted-but-not-zero-knowledge custodian.
Who can access your email
Full access via IMAP, webmail, or any email client.
UMG security operators have root access to the mail server. We have the technical ability to access stored email, but will not do so except: (a) when required by law, or (b) to diagnose a technical issue you have reported. This is our amanah.
Hetzner (Germany) has physical access to the hardware. They operate under EU law and GDPR, which provides stronger legal protections than US-based providers. They do not access customer data without a valid legal order.
No advertisers. No data brokers. No AI training. No third parties. Your email is not a product.
End-to-end encryption (optional, today)
If you need absolute privacy where even we cannot read your messages, enable OpenPGP encryption in your email client. When you encrypt a message with PGP before sending, it is stored as an opaque blob on our server. We cannot decrypt it. Only the intended recipient with the matching private key can.
PGP is supported in:
- Webmail (webmail.ummah.email) with built-in PGP support
- Thunderbird with native OpenPGP support
- Apple Mail via GPG Suite
- K-9 Mail / FairEmail on Android with OpenKeychain
When PGP is active, your email is end-to-end encrypted. The server stores ciphertext it cannot read. This is the strongest protection available today.
Email authentication
Every email sent from ummah.email is signed with DKIM (DomainKeys Identified Mail). This means recipients can verify that the email actually came from our server and was not tampered with in transit.
We also publish SPF and DMARC records to prevent others from sending email that appears to come from @ummah.email.
What we will never do
- Scan your email to show you ads
- Sell or share your data with third parties
- Use your email content to train AI models
- Insert tracking pixels into your messages
- Read your email without your knowledge or a legal obligation
- Hand over data to any government without a valid legal order
Newsletter (product updates)
The "ummah.email news" signup in the footer is a separate, optional list — not your inbox and not the Screen Name reservation flow above. If you sign up, we collect your email, how often you asked for (occasional digest or every announcement), and where you signed up. This is double opt-in: signing up sends a confirmation link, and nothing else sends until you click it. Every newsletter email carries an unsubscribe link (one click, no login). We do not track whether you open or click these emails — no tracking pixels, same as the "never" list above. If you unsubscribe, we keep your address on file only to remember not to email you again (suppression), or delete it entirely on request via salaam@ummah.email.
Infrastructure
Our mail server handles IMAP, SMTP, JMAP, CalDAV, CardDAV, spam filtering, and DKIM signing. It is a single-component stack with no external databases, no analytics, and no third-party integrations touching your mail.
Reporting a security issue
If you discover a vulnerability in our systems, please contact salaam@ummah.email. We will acknowledge your report within 48 hours and work to resolve it promptly.
We do not currently offer a bug bounty program, but we deeply appreciate responsible disclosure.
"Indeed, Allah commands you to render trusts to whom they are due."
Quran 4:58