Your Privacy Is
Not Negotiable
We built SendOrchard around one principle: your emails belong to you. Every architectural decision we made starts with your privacy in mind.
End-to-End Encryption by Default
Every message sent between SendOrchard users is automatically encrypted using OpenPGP — the gold standard for email encryption. Encryption happens on your device before the message leaves, so even our servers never see the plaintext content of your emails.
For emails to non-SendOrchard recipients, we offer Transport Layer Security (TLS) encryption in transit, and we clearly indicate when a conversation is fully end-to-end encrypted vs. transport-encrypted only.
Your Data Stays in the EU
All SendOrchard servers are located in certified data centres within the European Union, operating under strict GDPR regulations. We will never transfer your data to servers outside the EU without your explicit consent.
Our infrastructure partners hold ISO 27001 and SOC 2 Type II certifications. Physical access to servers is restricted, monitored 24/7, and logged.
We Cannot Read Your Email
SendOrchard is built on a zero-knowledge architecture. This means that even if compelled by a court order, we are technically unable to decrypt and hand over the contents of your end-to-end encrypted messages. We don't hold the keys — you do.
Metadata (such as sender, recipient, and timestamp) is the minimum required to route email and is handled according to our strict data minimisation policy. We publish a regular Transparency Report detailing any legal requests we receive.
No Ads. No Tracking. No Profiling.
Our business model is simple: you pay for a great service, not with your data. We do not scan your emails for advertising purposes. We do not build a profile of your interests. We do not sell or share your data with third parties.
We use minimal, privacy-respecting analytics (no third-party trackers) solely to improve the product. You can opt out of even this at any time in your account settings.
EU data centres, built for resilience
Redundant, ISO-certified facilities — physically secured and monitored around the clock.
Compliance & Standards
We hold ourselves to the highest international privacy and security standards.
Don't take our word for it
Our privacy claims are independently checked and publicly verifiable.
Independent security audits
Our encryption and infrastructure are reviewed by external security firms. Audit summaries are published so you can read the findings yourself.
Open-source encryption
The libraries that encrypt your mail are open source. Anyone can inspect the code that protects your messages — no hidden backdoors.
Public Transparency Report
We publish every legal data request we receive — and how we responded. Because we hold no keys, there's almost never anything to hand over.
Security you can verify.
Our source code is open for audit. Our infrastructure is independently certified.