Citadel reads your mail to triage it and draft your replies, then deletes what it learned on a schedule you set — and proves it’s gone. The AI runs on infrastructure you control. Nothing is sent to a US cloud. No copies are left behind.
Each one is a property of how Citadel is built — not a policy you have to trust.
Summaries, triage and draft replies are generated by a model running on infrastructure you control — today via a local Apertus model, next on a Canadian GPU host. No US clouds. No API keys. Your mail never leaves the box you run.
Citadel keeps only what the AI derived, and seals each item under its own encryption key. When your schedule says so, that key is destroyed. There is no master copy to fall back on, so the data is gone — permanently, not in a trash folder.
Every step is recorded — that a message was processed, and when it was forgotten — but never the content, the summary, or a key. You can show a regulator exactly what happened without revealing a single word of it.
Read-only Gmail today (Microsoft 365 next). Raw email stays in memory only — never written to disk.
The local AI writes a one-line summary, a priority, and a suggested reply for each message.
Only the derived data is stored — encrypted per-item with a unique key.
On schedule (1h / 24h / 7d / on logout) the key is destroyed — gone for good.
The audit log shows it happened, content-free. One click proves the data is truly unrecoverable.
Connect a real inbox for free. Upgrade when you outgrow the cap — same privacy either way.