Phishing, newsletters, links, OTPs, invoices, boarding passes. Numaeel reads it all in flight — burns the spam, threads the rest into workflows, and drops only what matters into your protected inbox.
Other inboxes give you a flag and a folder. Numaeel pulls the moving parts out of every message — order numbers, OTP codes, flight times, invoice amounts, ticket priorities — so the inbox is a structured surface, not a wall of subject lines.
€49.00INV-21204visa•4242acme-pro— (paid)482 911apple.com5114-3927DHL Express1Z 999 AA1…Thu 21 MayLH 423ZRH · 14:30JFK · 17:5514F · gate A52linearcriticalNUM-412true
Bring your own domain. Catch-all routing means every address on it — receipts@,
stripe-x7p2@,
orders@
— auto-appears in your inbox the moment the first mail arrives. Each one with its own filter mode, approved-sender list, and label policy.
The browser extension stamps a fresh alias into every signup form. When stripe-x7p2@ starts receiving phishing, you know exactly which vendor leaked.
Auth codes detected on inbound, pushed via Web Push to the browser extension, autofilled into the focused login field on the matching origin.
Sandboxed JS template functions resolve against the live signal — order numbers, sender names, anything on the email — at send time.
A signal that's technically legit but you never want again (vendor newsletters, ex-client cold reach-outs) gets discarded by the rule engine, not deferred to a spam score.
New senders are held in quarantine until you allow them. Or set the disposition to silent block. Or to a hard SMTP 5xx reject. Your inbox, your rules.
Every inbound signal runs through your rule graph before it lands. Conditions are plain JavaScript expressions, evaluated in a sandbox. Actions are composable — label, quarantine, forward, auto-reply from a template, or reject at the SMTP layer.
01// Push auth codes to my browser extension 02rule('Auth code → extension', { 03 when: s => s.workflow === 'auth', 04 do: [ push_extension(s.workflowData.code), 05 label('auth') ] 06})
07// Draft a reply from the “support intake” template 08rule('Support intake → draft', { 09 when: s => s.from.domain === 'customer.com', 10 do: [ ] 11})
13// Silently discard — they think it sent fine 14rule('Unwanted: oldvendor.com', { 15 when: s => s.from.domain === 'oldvendor.com', 16 do: [ block_hidden() ] 17})
19// Hold first-time senders for one-tap review 20rule('Quarantine new senders', { 21 when: s => s.from.isNewSender, 22 do: [ quarantine() ] 23})
label:team and each forwards on that label — the rule graph would loop forever. Numaeel refuses the pit of failure.
Numaeel reads the label graph at validation time. If a forwarding target's label set overlaps the source address's label set, the rule is rejected.
No retry storms. No duplicate auto-replies bouncing off a vacation responder until everyone's mailbox is full.
Numaeel is built in the open. The backend, the Vue UI, and the browser extension live on GitHub under a permissive licence — fork them, audit them, run them yourself if you'd rather. And because the inbox speaks JMAP (RFC 8620 / 8621), any standards-compliant mail client connects directly. No proprietary SDK. No client-shaped lock-in. No surprise re-licensing email.
Converts SES into a full email backend to support the Numaeel inbox. Full DynamoDB schema, workflow classifier, JMAP server, rules engine.
# Discover the JMAP session — your client does this on connect $ curl https://api.numaeel.cloud/.well-known/jmap \ -H "Authorization: Bearer $TOKEN" { "capabilities": { "urn:ietf:params:jmap:core": { "maxConcurrentRequests": 10 }, "urn:ietf:params:jmap:mail": { "maxMailboxesPerEmail": 100 }, "urn:ietf:params:jmap:submission": {} }, "primaryAccounts": { "urn:ietf:params:jmap:mail": "A1" }, "eventSourceUrl": "https://api.numaeel.cloud/jmap/event/{types}" }
EventSource / SSE delivers state changes the moment they happen. Battery-friendly on mobile, instant on desktop.
Pro & Premium add OpenPGP over the SMTP egress path. Encrypted submission for clients that key-share.
Three repos on GitHub: backend, Vue UI, and the browser extension. Run your own, or trust ours — your call.
you.dev.
Numaeel is a privacy front-end for the mail you receive — not a replacement for the tools you already trust. Google Calendar, Apple Calendar, Outlook 365 — whatever you use, it stays where it is. Same with your existing Google, GitHub, Apple, Microsoft, Facebook, GitLab, or Authress logins. They don't change.
What changes is who sees them. Hand out a Numaeel alias instead of your real calendar address. Invites land on Numaeel, get verified, and are forwarded to your real calendar over a clean ICS link. Your accept, decline, and free/busy responses route back through the same alias — so the organiser hears from calendar-x9k2@you.dev, never from your private mailbox.
Email stored and processed inside Switzerland — under the Swiss nFADP, one of the strongest privacy frameworks globally. No third-country data transfer. We don't sell, profile, or leak what's in your inbox.
You don't tick boxes; the platform was built to the stricter standard from day one.
Every mutation — archived, blocked, rule-fired, forwarded — recorded with actor, timestamp, before/after. Export your trail any day.
When a sender ignores your unsubscribe, we file a formal complaint to the relevant Data Protection Authority — pre-filled with evidence — automatically.
Your protected inbox. Multiple domains, unlimited aliases, classification, & quarantine.
The protocol-level inbox. JMAP for any client, GPG transport, custom rules, unlimited retention.
Pro, with a human on the other end. Priority pipeline, migration help, and white-glove setup.
Run your whole company on Numaeel — every employee on your domain, shared aliases, admin controls, SSO, and unlimited users on every plan. From €10/mo.