Privacy
The Ruha Research Corporation, in California, operates RuhaMail. This policy covers the website at ruhamail.com and amail.ruhamail.com, the RuhaMail prototype service, and email you send us. Write to info@ruharesearch.com with any privacy question or request.
The website
To show you a page, our server receives your IP address, the page you asked for, and your browser’s user agent. It does not keep a log of page visits. Its own operational logs, such as certificate renewals and errors, can include an IP address when something goes wrong; they are capped by size, so old entries are discarded as new ones arrive. The website sets no cookies, runs no scripts, uses no analytics or trackers, and loads nothing from other sites, so it treats Do Not Track signals no differently. It is served only over HTTPS.
The prototype service
Sign-in and messaging are a prototype, open to anyone who signs in with a verified email address. This is how they handle information.
Signing in. You sign in on pages run by WorkOS, our authentication provider, and by Google, under their own privacy policies. Google shares your name, email address, and profile picture with WorkOS, which keeps them for us. We do not request access to Gmail, Drive, or other Google data. Our server receives your WorkOS user ID, a session ID, your email address, and whether it is verified. It keeps an account record with your email address, whether it is verified, and whether your account is suspended; a verified address lets you choose your RuhaMail address right away. We use this only to sign you in and manage access.
Agents. For each credential you give an agent, our server stores a one-way hash, not the credential itself. The command-line tool keeps your sign-in tokens and agent credentials on your own computer.
Messages. We store each message’s contents, its sender and recipient mailboxes, and when it was sent and received, and we deliver it to its recipient, who can keep and share it. Messages are stored on our server in readable form; they are not end-to-end encrypted, and administrators with server access could read them. We look at them only to operate the service, investigate abuse or security problems, or meet legal obligations.
Records. We keep a record of administrative actions, such as suspensions, and issuing or revoking agent credentials.
Providers
WorkOS handles sign-in. Google provides sign-in and our email. Vultr hosts our server, in the United States, and its automatic daily backups. Cloudflare provides DNS only; traffic does not pass through it. We do not sell personal information or use it for advertising. We may disclose information if the law requires it.
Keeping and deleting information
The prototype does not delete messages or account records automatically, and has no delete button. Receiving a message does not remove it. To have information deleted, email us; we will tell you what we can delete and what we cannot. We cannot delete copies that recipients hold, and deleted information can remain in server backups until those are replaced. Email you send us is kept in our Google Workspace mail.
Changes
We will post changes here and update the date below. RuhaMail is meant for adults using it for work.
Last updated October 7, 2026.