Email content is not stored.
Scanning happens in memory in milliseconds, only on unknown-sender messages, only to verify a payment token. The body is discarded immediately.

Most email security vendors operate as custodians. Mail flows through their infrastructure, content is scanned and stored for quarantine and audit, payment balances sit on their books. The model works for some compliance use cases. It is the wrong shape for users who want to minimize what a third party sees and holds. Rythm is built non-custodial. We never hold your money. We never store your email content. The body of an unknown-sender message gets scanned in memory for a tiny fraction of a second, only to check whether the sender attached the cover charge, and then it is gone. The cover charge each unknown sender pays is a small bearer payment that lands in your own wallet, not ours. The only data we keep is what the service needs to run: your account, the encrypted connection token to your inbox, your guest list (the set of approved senders, derived from your inbox actions), and your subscription record.
The conventional email-security architecture is custodial by design. The vendor sits between the sender and the inbox. Mail-flow proxies route every message through a vendor-controlled gateway. The vendor scans, scores, quarantines, and stores. Payment processing for any bolted-on features is custodial: the vendor holds the funds, the user has a balance. The model is fine for organizations that want full audit trails and centralized control. It is not the right shape for users who want the protection layer to take custody of as little as possible.
Three things change when the protection is economic instead of probabilistic.
Scanning happens in memory in milliseconds, only on unknown-sender messages, only to verify a payment token. The body is discarded immediately.
The cover charge moves from sender to recipient on its own rails. Rythm verifies it in memory and lands it in your own wallet. We never sit on the money in between.
Only what is needed to run the service: your account, the encrypted connection token to your inbox, your guest list, and billing records. No message bodies, no contacts, no message archive.
Non-custodial does not mean private from your provider. Gmail still has access to your Gmail. Microsoft still has access to your Microsoft 365 mailbox. Rythm is a layer that minimizes what the layer itself takes custody of; it does not change what your underlying provider does. Non-custodial also does not mean encrypted at rest only. End-to-end encrypted email (Proton Mail, Tutanota) takes a different approach: the provider cannot read content because it is encrypted before it reaches them. Rythm is not end-to-end encrypted; it is non-custodial in the sense that it does not retain content or hold funds. If your threat model requires that no provider can read your mail, end-to-end encrypted email is the right shape.
Keep your existing Gmail or Outlook. Cancel anytime.
Annual on Lightning includes one bonus month. See full pricing.
For users whose threat model includes minimizing what the protection layer holds.
For users whose work depends on a third-party not retaining their inbound source mail.
A founder note on what it took to build the protection layer this way.
A plain-English explainer on the term and what it does and does not promise.
On the difference between using open payment rails and being a payment provider.

Keep your existing Gmail or Outlook. $1.65 per month. Cancel anytime.
Secure My Inbox