Content-blind email assistant

Write the email.
Keep the names.

Paste an email you received, or just say what you want to say. cloak-post drafts, replies, rewrites and summarizes it — but every recipient, address, phone and account number is swapped for a realistic stand-in on your device before a single word reaches the AI. The model writes to the stand-in; cloak-post reseals the letter with your real values. The gateway never learns who it's for.

  • Cloaked before anything is posted
  • 4 ways to write
  • Signed on-device receipt

cloak-post never sends your mail. It hands you the finished draft to send yourself.

Try one

Answer an email you received.

Tone
Names have not been checked — the on-device name model did not run.
Egress monitor 0 raw-PII bytes
On-device
0
Gateway relay
0surrogates
Third-party
0

Your finished email will appear here.

Seal first — cloak-post drafts from surrogates, then reseals with your real names.

The delivery, in three moves

01

Seal, on-device

A WebAssembly engine plus a multilingual name model find names, emails, phones, addresses and cards — across Latin, Cyrillic, Arabic, Devanagari and CJK — and frank each with a realistic surrogate. Structured identifiers (cards, IBANs, national IDs, phones, emails, dates) match by rule; free-form names rely on the on-device model, so an unusual one can slip past — the preview shows exactly what leaves. Zero network.

02

Relay a cloaked copy

Only the surrogate-bearing text is sent to the drafting model, through the CloakAPI gateway with a cryptographic pre-tokenisation proof. The real values — and the map back — stay in the tab.

03

Reseal & copy

The draft returns carrying the same surrogates; cloak-post maps them back to your real values on-device, signs a receipt carrying the raw-PII byte count measured on what left, and hands you the email to copy and send. It never sends the mail for you.