All posts

Privacy

Why we don't want your data, even if you'd let us have it

· 5 min · STAMP team

Why we don't want your data, even if you'd let us have it

People sometimes assume our privacy stance is a marketing position we adopted because it tests well. It is not. It is a business decision, made for business reasons, that happens to also be the right thing to do. This post explains the actual reasoning.

Data is only an asset if you can monetize it

For a company whose revenue comes from advertising or data resale, user data is the product. More data, more granular data, more retained data: all of that directly increases revenue. The incentive to collect more is structural, not a choice any individual person at the company makes.

STAMP has one revenue line: subscriptions. Monthly $9, Yearly $79, Lifetime $199. No ads, no data partnerships, no free tier subsidized by anything else. Every dollar we make comes from someone deciding STAMP is worth paying for directly. Holding a copy of your email content does not increase that number. It only sits there as risk.

What holding your data would actually cost us

If we stored a searchable copy of your inbox on our servers, here is what that would create, immediately:

  • A breach target. Every server holding sensitive data is a target. The bigger and more valuable the dataset, the more attractive the target. A server-side index of thousands of users' email is a far more interesting target than any individual inbox.
  • A subpoena target. A company holding user email content can be legally compelled to hand it over. A company that never holds it cannot comply with a request for data it does not have. This is not a hypothetical: it is the entire logic behind why we built classification to run on-device instead of server-side, as we cover in on-device email classification, explained.
  • An engineering and compliance burden. Storing sensitive personal data at scale requires encryption at rest, access controls, audit logging, retention policies, breach-notification procedures, and ongoing security review. All of that is expensive, all of it is easy to get subtly wrong, and none of it directly builds a better triage experience for you.
  • A trust liability the moment anything goes wrong. One breach, one leaked dataset, one story about how we used data in a way users did not expect, and every claim we have made about privacy becomes worthless overnight. For a subscription product where trust is the entire sale, that is an existential risk, not a bad news cycle.

Weighed against that, the case for holding your data is: it would make some product decisions marginally easier. That is not a good trade.

The counterargument, and why it does not change our mind

The obvious counterargument: couldn't we build better AI features with more data? Bigger cloud models, trained on real usage, would likely outperform a small on-device model on some tasks like summarization or draft generation. That is true, and we said so plainly in on-device email classification, explained: the gap is real for some features, which is why we do not ship a one-click summary.

We picked the privacy bet anyway. A narrower, faster, on-device model that never sees your data leave your Mac is worth more to us than a marginally smarter model built by centralizing everyone's inbox. That is not a claim that privacy always wins every product tradeoff for every company. It is a claim about what kind of company we are trying to be, and what kind of trust a primary email client needs to earn to be worth using at all.

What this looks like in practice, not just in principle

  • Classification runs on-device. We never see the content.
  • Credentials live in the macOS Keychain, not in our infrastructure.
  • We do not train models on user email, with or without your permission, unless it is an explicit, paid, opt-in program we have no plans to build.
  • There is no server-side search index of your mail sitting on our infrastructure.
  • No ads, no data brokers, no “anonymized” data resale. Ever.

None of this is a feature we can turn off later if it becomes convenient. It is the architecture. Removing it would mean rebuilding the product.

The honest version of this argument

We are not claiming to be uniquely virtuous. We are a small company that would genuinely struggle to survive a data breach or a trust-eroding story, in a way a larger company with deeper reserves and more product surface area might not. Not wanting your data is partly principle and partly self-preservation. We think that is a fine reason. A business model that only works if a company stays trustworthy is a business model with the right incentives built in.

Where to go from here

For the architectural details behind the on-device promise, on-device email classification, explained. For how free alternatives typically fund themselves instead, the real privacy cost of free email clients.


Built to never need your data. hello@stamp.email

Email, finally finished.

A paid macOS email client from $9 a month, locked for life if you join the founding window.

Get early access