How Cora protects your account data

Cora is built with security as a first priority. Here's a plain-language look at what that means in practice — no jargon required.

Your data is encrypted on your device

Passwords, tokens, and your local copy of messages are stored in encrypted storage on your device, not in plain text. Even if someone gained access to the underlying files, they would not be readable without your device's protected key.

Cora checks itself every time it starts

Each time Cora launches, it verifies that its encrypted storage is intact and that the security keys it depends on are available and valid before loading any account data. If something looks wrong, Cora will ask you to sign in again rather than risk exposing data insecurely.

Signing in again after a full restart

For your protection, Cora asks you to sign in again every time the app is fully closed and reopened (a "cold start") — not only once your session has technically expired. Simply switching away from Cora and coming back (for example, from your lock screen or another app) does not require signing in again during that same session.

App passwords and tokens, not your master password

Where possible, Cora uses provider-issued app passwords or tokens (rather than storing your main account password) — see Gmail / IMAP with an app password for an example.

Cora never sends your email password or app password to gocora.com servers for the purpose of accessing your mail — it connects directly from your device to your mail provider.