Connect Your Gmail
Securely connect your Gmail account with OAuth authentication. We only access what we need.



The only privacy-first AI email assistant where you own the intelligence. Your keys, your provider, your control. Zero-knowledge architecture means we cannot read your emails.
Sovereign privacy. 95% cheaper than Superhuman.
Privacy-first architecture with hardware-backed security — your emails never leave your device, and we never see them.
Your emails never touch our servers. We mathematically cannot read them — true privacy by design.
Use your own Gemini, OpenAI, or Anthropic API key. Pay as little as $0.50/month instead of $30.
Master keys stored in Secure Enclave (macOS/iOS) or StrongBox (Android). AES-256 + Secure Enclave encryption.
Works without internet. Your emails stay on your device where they belong.
Encrypted 'Dark Blobs' sync across devices — the server sees only random noise.
AI categorization, priority scoring, one-tap summaries, and draft replies — powered by your own AI provider.
Your keys. Your provider. Your control. Emails classified and enriched through AI you choose — never through ours.
To Respond. FYI. Notification. Meeting Update. Actioned. Marketing. Trunk. Newsletter. Every email, categorized before you open the app.
Private notes extracted from your emails. End-to-end encrypted. Only you hold the key.
Smart action cards with deadlines, tasks, and meetings — surfaced automatically from your email content.
Digest view. Headline extraction. Topic tracking. Your newsletters, distilled.
Get started in minutes with Xiftly's intuitive setup process and watch AI transform your email experience.
Securely connect your Gmail account with OAuth authentication. We only access what we need.

Enter your Gemini, OpenAI, or Anthropic API key. Stored in Secure Enclave — never on our servers.

Done. Your emails are classified into 8 categories using your AI provider. Zero data sent to Xiftly.

Get detailed analytics about your email patterns, processing summaries, and productivity metrics.
What happens when you connect Xiftly.
No web version by design — native apps enable hardware-backed security (Secure Enclave/StrongBox) that browsers cannot access.
We don't just promise privacy — we architect it. Your emails never touch our servers,
and our zero-knowledge design means a breach of our systems reveals nothing.
.png)
Monitor your network traffic. Check our architecture docs. Our privacy isn't a promise — it's an engineering constraint.
Free is genuinely free. Bring your own API keys and pay your AI provider directly — typically under $0.50/month.
Your keys, your compute
Full sovereign experience
| Service | Monthly Cost | Your Data | AI Provider |
|---|---|---|---|
| Xiftly Free | $0 | On your device | Your choice |
| Xiftly Pro | $4.99 | On your device | Your choice + SRIN |
| Superhuman | $30 | Their servers | Unknown |
| Shortwave | $19 | Their servers | Unknown |
| HEY | $12 | Their servers | No AI |
We believe in radical transparency about how we protect your privacy.
Mathematically impossible. Your emails are stored only on your device, and AI classification runs through your own API keys — we never see your content. When syncing across devices, only encrypted blobs touch our servers — and we don't have the keys to decrypt them. Our zero-knowledge architecture means we cannot access your email content.
There's nothing to hack. We don't store your emails, API keys, or encryption keys. A breach of our servers would reveal... encrypted noise. Your master key is hardware-bound to your device's Secure Enclave, not stored on our servers.
Your master key is hardware-bound to that specific device and cannot be extracted. For new devices, you'll re-enter your master password once to decrypt your sync seed and regenerate your keys. Your encrypted sync data remains safe — it's useless without your master password.
We cannot provide what we don't have. Your emails never touch our servers, so there's nothing to subpoena. Even if ordered to hand over data, we only have encrypted blobs that are mathematically impossible to decrypt without your master key.
Our architecture is fully documented and auditable. The core Rust cryptography code will be open-sourced for independent security verification. We use industry-standard encryption (AES-256-GCM) with OWASP-recommended key derivation (Argon2id).
We use a BYOK (Bring Your Own Key) model. You provide your own AI API key from Gemini, OpenAI, or Anthropic. You pay them directly based on actual usage — typically $0.50-$1.00/month. No expensive subscriptions, no middleman markup.
Still have questions? Our architecture documentation is public and our security core will be open-sourced for independent verification.
Unlike Superhuman ($30/mo) or Shortwave ($19/mo), Xiftly gives you better privacy, more control, and 95% cost savings with your own AI.
