Security

Bezpieczeństwo

Last updated: July 2026

Infrastructure providers

uff.email runs on proven infrastructure. Below is the full service stack:

Cloudflare
DNS, DDoS protection, and edge routing. Domain management and mail delivery go through Cloudflare's network.
OVH
European VPS hosting. Hosts the Mailu mail server and assistant containers. Each instance runs in an isolated environment, with no shared memory and no shared disk between users.
OpenRouter
LLM API provider. Tasks are routed to models appropriate for the work type and processed according to model providers' terms.

Isolation

Assistant instances on OVH are separated from each other. Each user gets their own container with dedicated RAM and storage. There is no shared state and no shared database for assistant memory. In practice, each assistant operates as its own silo.

We don't browse your data

As the service operator, we do not read, analyze, monitor, or browse the contents of user instances. We do not do this for debugging, model training, or "product improvement." Assistant memory, prompts, and email content belong to the user.

Administrative permissions

As the service operator, we limit administrative actions to the infrastructure level. We may:

  • suspend or start an instance,
  • stop or restart an instance,
  • archive an instance after cancellation,
  • delete an instance after the archiving period.

We do not use the admin panel to read prompts, browse assistant memory, open messages, or analyze user data.

Encryption

Mail transport runs with enforced TLS through Mailu. Assistant storage on OVH is encrypted at rest. API connections to OpenRouter go over HTTPS.

Reporting issues

If you find a security vulnerability or have questions, write to support@uff.email.