๐ค Where we're taking keymail next, and how far along each piece is. Milestones is the story of what's already shipped; this is the honest plan for the road to V1 โ the release where secure email feels like email, not like a science project. Updated as the tracks move, in plain language: what you'll feel, not how the boxes are run.
Toward the V1 release ยท reviewed 8 August 2026
V1 isn't a feature list โ it's a bar. Five things have to be true before we'd call it finished.
The work that gets us over the bar, grouped by what it's for.
The core promise, working today.
End-to-end encrypted mail โ subject, body, and attachments sealed in your browser before they leave it. First contact is gated by proof of work, so spamming a stranger costs the sender real compute. Rich text, drafts, undo send, trash, contacts, mobile โ the everyday things are in.
Passkeys and an encrypted key vault instead of passwords.
Sign in with a passkey; your sealed key vault follows you to a new browser without your keys ever touching a server in the clear. The V1 work is breadth โ more authenticator types handled gracefully โ and making recovery foolproof.
"Sign in with keymail", and a place for app mail that isn't your inbox.
Websites can offer sign-in with your keymail address, and approved apps and newsletters can write to you โ every message still sealed to your key, filed under their own Apps and Newsletters tabs, revocable with one click in Settings. Approving an app always asks for your passkey, so a stranger at your unlocked laptop can't say yes as you. The developer docs are public.
The bridge to the rest of the world โ open both ways.
Ordinary email can't be end-to-end secure, so we don't pretend: mail from the old world is screened and sealed at the door, and your replies now travel back out as plain email โ fully authenticated, so they land in inboxes rather than spam โ while your own copy stays sealed to your key. Every mailbox carries its own sending reputation, so one person's bad day can't dent anyone else's deliverability.
Twenty years of Gmail, sealed into your keymail box.
A Gmail Takeout file already imports in your browser, every message sealed to your key before it's stored; huge mailboxes can opt to let the server do the fetching, with a consent screen that's honest about the trade โ and now the import keeps going: opt in and new Gmail arrives every few minutes, receipts intact. The inbox stays fast at half a million messages, and search answers as you type โ the index lives in your browser, so the server still can't read a word. What's left: opening it up beyond the first hundred testers.
From "I've heard of this" to "I have an address" in minutes.
Self-serve signup exists; V1 makes the first five minutes the product โ claiming an address, meeting the inbox, and inviting the people who aren't here yet, with no dead ends and no jargon.
The promises kept in the open โ this site is part of it.
The carbon tally, the contributor index and the prompt ledger publish what most products hide, including how the AI that writes this app is used. That stays a principle, not a phase.
Real plans, deliberately held until the core is finished โ named here because we'd rather be honest about the direction than quiet.
Real native apps โ no webviews โ with the same passkey-only, keys-in-your-hands model as the web. The groundwork (shared passkeys, universal links) is already wired into the domain.
keymail is one static binary with no dependencies by design; the after-V1 work is the honest guide and polish that make self-hosting a first-class, documented path rather than a trick for the brave.
Two keymail servers already speak to each other over a public, documented protocol. The next step is other people's servers โ many small instances, no single operator anyone has to trust.