Letterlock The most secure AI assistant for Gmail

Frequently asked questions

What is a TEE and why does it matter for email privacy?

A TEE (Trusted Execution Environment) is a locked compartment inside of a web server that no-one can read data or monitor processes on. Email is the property of you and your sender, not an AI company. The TEE provides a verifiable guarantee that no-one else will read your data.

Does Letterlock train on my emails?

No. This would be impossible, as neither Letterlock nor the model provider store or look at your emails.

Which AI models are available?

All open-weight models with published weights. You choose in Settings:

  • DeepSeek (standard) — Drafts go straight to DeepSeek. Identifiers are replaced with tags before the text leaves this server, but DeepSeek can read what remains.
  • GLM 5.2 in an enclave (confidential) — Drafts are read by a model running in a hardware enclave whose measurement this server checks before every session. NEAR AI operates the machine and cannot read what runs inside it. Served as FP8. Masking still applies.
  • gpt-oss-120b in an enclave (confidential) — A smaller open-weight model in the same attested enclave setup, cheaper and quicker than GLM 5.2. Served as FP4, with a 131k context rather than 1M. Masking still applies.

The confidential options run on NEAR AI, on Intel TDX machines with NVIDIA confidential computing. Before each session this server fetches that enclave's attestation, checks the hardware signature back to Intel, and ensures the measurement is one of a list of images Letterlock reviewed and committed to our repository.

Can a malicious email manipulate the assistant?

No. Email content and tool results are untrusted data rather than instructions. Letterlock also never sends emails: every draft waits in your Drafts folder until you read it and press send.

How do I get Telegram notifications?

Open Settings and follow the linking steps.

How does the PII masking work?

Before any message leaves the enclave, Letterlock scans it for personally identifying information (provider API keys, names, email addresses, phone numbers, government IDs, etc); and replaces each value with a numbered placeholder. Only the placeholder text reaches the AI model. When the response comes back, the placeholders are swapped back to your real values before you see anything. The AI provider never sees your actual data.

  Your mailbox              Letterlock enclave      AI model
  ────────────              ──────────────────      ────────
  "Hi, I'm Alice      ──►  scan & replace    ──►  "Hi, I'm [NAME_1].
   Johnson. SSN:            PII with placeholder       SSN [SSN_1]."
   123-45-6789."            text
      
        
        
                                                        
  "OK Alice Johnson,  ◀──  restore PII    ◀──    "OK [NAME_1],
   your SSN                                          your SSN
   123-45-6789 is                                    [SSN_1] is
   on file."                                         on file."

Values that match common patterns (email addresses, phone numbers, card numbers) are given placeholder text of their type, so they are never sent in the clear.

Edit the sample message below to see redaction live:

▶ Your message (sent to the model)
Redacted — what the model sees
▼ mock model response (using tokens throughout) ▼
▶ Model responds (tokens only)
What you see (tokens restored)
What does it cost?

€25 a month. You look at Pricing to compare this against the alternatives.

Is the code open source?

Yes.


» Connect your Gmail