Privacy-first inbox protection that never holds your money — or your email.
"Non-custodial" is a word the Bitcoin world invented to describe a simple idea: nobody in the middle holding anything. Applied to an email product, it means no email content stored on our servers, no Cashu tokens held between payments, and no balance for anyone to hack.
Most email security tools are custodial by default — they route your mail through their servers, read the content, store it, train models on it. Rythm takes the opposite approach. We scan for one thing (a valid cover-charge payment proof), discard the rest, and never sit in the middle of the payment itself.
We never hold your money. We never store your email.
How the options compare on custody and content
| Rythm | Proofpoint | Mimecast | SaneBox | |
|---|---|---|---|---|
| Holds user funds | No — payment settles directly to your wallet | N/A | N/A | N/A |
| Stores email content | No — in-memory scan, then discarded | Yes — quarantine logs | Yes — quarantine + archiving | Partial — for AI training |
| In-memory processing | Milliseconds, never persisted | Server-side analysis + storage | Server-side analysis + storage | Server-side AI analysis |
| Audit trail | CASA Tier-2 security audit completed (39 of 39 test cases passed) | SOC 2, ISO 27001 | SOC 2, ISO 27001 | Limited public disclosure |
| Setup | Self-service OAuth, ~12 minutes | Requires IT team | Requires IT team | Self-service |
| Price | $1.65 / month | $36–82 per user / year | $60–180 per user / year | $7–36 / month |
| Consumer-friendly | Yes | No — enterprise only | No — enterprise only | Yes |
Why Rythm is worth considering
- CASA Tier-2 security audit completed (39 of 39 test cases passed).
- If anything breaks on our end, email delivers normally. The filter fails open, never closed.
- Payments use an open protocol so your money doesn’t depend on a single vendor staying in business.
- Nothing to lock you in. No migration cost to leave. We earn the subscription every month.
Frequently asked
What does "we never hold your money" actually mean?
When a stranger pays the cover charge, it flows from them to the recipient wallet you connected. We verify a proof-of-payment in memory and pass it along — there’s no Rythm-controlled balance sitting anywhere.
What about email content?
We scan incoming messages from unknown senders for one thing — a valid cover-charge payment. The scan runs in memory for a few milliseconds and the content is discarded immediately. We never store it, share it, or train on it.
What data does Rythm actually keep?
Your guest list, your subscription details, and the encrypted connection token that lets us attach to your Gmail or Outlook. That’s it — no email bodies, no contacts, no message archives.
What happens if Rythm gets breached?
There are no funds to steal and no email content to leak. The OAuth connection tokens are encrypted at rest; we would rotate keys and force re-authentication across the board.
How is this different from enterprise SEGs like Proofpoint?
Enterprise email security gateways route all mail through their own infrastructure, scan it, store it, and log it. That’s the right model for some use cases — and the wrong model if you care about minimizing what a third party sees.
Try Rythm. Your inbox, your rules.
$1.65 a month. Cancel anytime.
Secure My Inbox