# Has anybody tried Epistles mail?

**URL:** https://discuss.privacyguides.net/t/has-anybody-tried-epistles-mail/39055
**Category:** General
**Tags:** software
**Created:** 2026-07-09T00:34:40Z
**Posts:** 6

## Post 1 by @PrivadoQ — 2026-07-09T00:34:40Z

I recently discovered on a search for email apps Epistles mail, at [https://epistles.com/](https://epistles.com/) . It claims that it can be used with Proton mail and they don’t have any access to emails or account information. I’ve never been a fan of Proton’s iOS/ipad apps, and tried Epistles with an email account that I don’t use and liked it enough that I’m considering using it as my regular email apps. Does anyone have an experience with them?

---

## Post 2 by @Shampoo — 2026-07-09T00:49:50Z

No source code available. I wouldn’t use it. Use Thunderbird and proton bridge.

---

## Post 3 by @FranklyFlawless — 2026-07-09T03:24:49Z

> [@PrivadoQ](#):
>
> Does anyone have an experience with them?

No, but reading through their website, they are generally honest about their limitations:

> **[FAQ · Epistles Mail](https://epistles.com/faq/)**
>
> Plain answers about Epistles Mail. Providers, platforms, pricing, privacy, telemetry, Proton without Bridge, Newton Mail and Thunderbird comparisons.

> [@](#):
>
> ## Is Epistles Mail open source?
> 
> No. Epistles Mail is proprietary closed-source software.
> 
> The trust mechanisms it offers instead are: zero analytics SDKs, no third-party crash reporter, AES-256-GCM client-side encryption of the Cloud Vault under a key derived from your password, a published subprocessor list, and native protocols rather than a server-side proxy.
> 
> If source-availability is a hard requirement, Thunderbird is a strong open-source alternative.

They are at least lying with one claim:

> [@](#):
>
> ## Does Epistles Mail collect telemetry?
> 
> No. Epistles Mail ships with no analytics SDK, no third-party crash reporter, and no usage metrics.
> 
> The only network calls the app makes to Epistles servers are functional: Cloud Vault sync (ciphertext only), push registration, server-mediated OAuth refresh, optional image proxy, and opt-in outbound link tracking. Diagnostic logs stay on the device until you choose to export a bundle.

The website itself has Google Tag embedded (`https://epistles.com/assets/gtag-init.js`) along with Cloudflare Insights enabled, and their Privacy Policy neglects to mention either:

> **[Privacy Policy · Epistles Mail](https://epistles.com/privacy/)**
>
> How Epistles Mail handles your email and account data. Local-first, zero-knowledge vault, no telemetry.

Whether one lie exposed from a casual analysis is a dealbreaker or not is now your problem to address.

---

## Post 4 by @epistlesmail — 2026-08-19T00:04:26Z

Epistles Mail ([https://epistles.net](https://epistles.net)) has been through an extensive security audit by Google and their partner TAC Security, who granted us the CASA Tier 2 certification after reviewing our system and source code. We are also constantly audited by Apple and Microsoft. Our app is available in all app stores.

---

## Post 5 by @Ganther — 2026-08-19T18:35:40Z

“Hmm. We’re having trouble finding that site.”

Did you switch from a .com to a .net domain?

---

## Post 6 by @Expert4870 — 2026-08-20T02:17:27Z

I prefer a link to a GitHub at the bottom of a website, rather than a LinkedIn :melting_face:

[Security & encryption · Epistles Mail](https://epistles.net/security/) Claude wrote an extensive thing here and it seems good I can’t lie.

> [@Real talk: Do you actually know your threat model?](https://discuss.privacyguides.net/t/real-talk-do-you-actually-know-your-threat-model/39989/9):
>
> play_button Summary

> Thunderbird is a genuinely good open-source email client and we recommend it without irony.
