Superhuman vs Canary Mail for Privacy: Where Your Data Sits

The short answer
Canary Mail. Its own policy says it does not store your message content, keeps credentials on-device unless you enable push or cloud sync, and offers PGP end-to-end encryption. Superhuman Mail runs a server-side architecture with an AI index and publishes SOC 2 and ISO certifications — stronger assurance, more data on someone else's servers.
Superhuman vs Canary Mail privacy: where mail is processed, how AI requests are handled, and which one keeps less of your email on a server.
On this page
- 01The verdict up front
- 02At a glance
- 03Where Canary Mail wins: the mail never has to leave
- 04Canary's encryption is the dimension Superhuman simply does not compete on
- 05Where Superhuman wins: it can prove things Canary only asserts
- 06The AI question: what actually gets sent to a model provider?
- 07Credentials and OAuth tokens: the quiet difference
- 08Read receipts: both ship the thing privacy buyers dislike
- 09Pricing model shape, without the numbers
- 10Who each one is genuinely for
- 11A third option, honestly
- 12How to check any of this yourself
Most Superhuman vs Canary Mail privacy comparisons stop at a feature checklist: both have AI, both have shortcuts, one has encryption. That misses the thing that actually decides the question, which is architecture. One of these clients is built to keep your mail on your device. The other is built to keep a working copy on its servers so its AI can reach it.
Neither approach is wrong. They are different bets, and the right one depends on whether your risk is a vendor breach or a compliance auditor asking for a certification report. This post compares them on the four dimensions that follow from the architecture: where mail is processed, how credentials are stored, what the AI features transmit, and what encryption exists.
Everything below is checked against each vendor's own published pages as of September 2026. Both companies change these documents, so verify anything you are about to sign a contract on.
The verdict up front#
For keeping your email out of a third party's infrastructure, Canary Mail wins, and it is not close. Canary's privacy policy states plainly that it does not collect or store the content of your personal email messages. Your account credentials live on your device. Mail is fetched by the client from your provider, not mirrored into a Canary datastore.
Superhuman Mail takes the opposite position by design. Its published subprocessor list names Turbopuffer, a vector search service, alongside OpenAI and Google Cloud — the shape you would expect from a client that indexes your mail server-side so features like instant search and automatic drafting can work against it. That is also why it can do things Canary cannot.
Where Superhuman wins is assurance. It publishes SOC 2 Type 2 and ISO/IEC 27001:2022, plus 27017, 27018 and 27701. Canary's public site does not present an equivalent certification portfolio. If your security review is a questionnaire rather than a threat model, that gap matters more than the architecture does.
So the honest split: Canary minimises what leaves your machine, Superhuman documents what it does with what leaves your machine. Pick based on which of those two your organisation is actually asking for.
Which Superhuman do you mean?
At a glance#
This table compares documented behaviour, not marketing language. Where a vendor has not published a position, the cell says so rather than guessing.
| Privacy dimension | Superhuman Mail | Canary Mail |
|---|---|---|
| Where mail is processed | Server-side. Mail is synced and indexed in vendor infrastructure | Device-first. Policy states message content is not collected or stored |
| AI processing | Cloud. OpenAI named as a subprocessor | Cloud models named (OpenAI, Anthropic, Cohere, Google), plus on-device personalised models |
| Training on your mail | AI providers restricted from training; Superhuman's own training governed by an account setting | States it has opted out of data sharing so content is not used to train third-party models |
| End-to-end encryption | Not offered | PGP, plus SecureSend positioned for HIPAA workflows |
| Credential storage | Server-side, required for background sync | On device, unless push or cloud sync is enabled |
| Outbound tracking pixels | Read statuses use a pixel; vendor states it is now off by default | Read receipts offered as a feature |
| Inbound pixel blocking | Yes, via a command-palette setting | Not documented in the same detail publicly |
| Published certifications | SOC 2 Type 2, ISO 27001, 27017, 27018, 27701 | Not published in an equivalent portfolio |
Where Canary Mail wins: the mail never has to leave#
The strongest privacy claim either vendor makes is Canary's, and it is a specific one rather than an adjective. The policy states that Canary does not collect or store the content of your personal email messages, incoming or outgoing. Credentials are described as stored on your device and never shared with third parties.
That is a structural claim, not a promise about behaviour. If a vendor never holds the data, a breach of that vendor cannot expose it. This is the reason people in legal, clinical and security-adjacent roles keep choosing thick clients over hosted ones even when the hosted product is better.
There are two documented exceptions, and they matter. Push notifications and Cloud Sync both require server-side storage while enabled — Canary states notification data is deleted as soon as the notification is delivered to the device, and Cloud Sync data is cleared when the feature is turned off.
So the honest version of the claim is conditional: Canary is device-only until you enable the two features that make a mobile client feel normal. If you want instant push on your phone, you have opted into a server touching your mail. Read that as a trade you make knowingly, not as a contradiction.

Canary's encryption is the dimension Superhuman simply does not compete on#
Canary ships PGP end-to-end encryption in the client, and markets SecureSend for HIPAA-sensitive sending. Superhuman Mail offers no end-to-end encryption at all. This is not a close call or a matter of framing — it is a capability one product has and the other does not.
Be precise about what PGP buys you. It protects message content between you and a correspondent who also uses PGP, with keys you hold. It does not encrypt your metadata, it does not help with mail from people who will never install a key, and in practice most business email will not be end-to-end encrypted no matter which client you run.
Which is why the right way to read this row is: if you have specific correspondents whose messages must be unreadable to every intermediary, Canary can do that and Superhuman cannot. If you do not, this row is a tiebreaker rather than a decision.
No client is secure, only specific mechanisms are
Where Superhuman wins: it can prove things Canary only asserts#
Canary's privacy claims are strong and specific, but they are claims. Superhuman publishes SOC 2 Type 2 and ISO/IEC 27001:2022, along with 27017 for cloud controls, 27018 for personal data in the cloud, and 27701 for privacy management. Those are audited attestations with reports a procurement team can request.
That difference decides real purchases. A security reviewer at a mid-size company cannot accept an architecture argument in place of a report. If your deployment depends on passing a vendor questionnaire, Superhuman clears it and Canary requires a conversation.
Superhuman also publishes a named subprocessor list — Turbopuffer, OpenAI, Iterable, Fivetran, Google Cloud — which is more disclosure than most clients offer. Knowing precisely who touches your data is itself a privacy property, and it is one Superhuman does better than almost anyone in this category.
The trade is plain: you get transparency and audited controls over an architecture that holds more of your mail. Superhuman is not hiding that. It is the design.
The AI question: what actually gets sent to a model provider?#
This is the axis most comparison pages skip, and it is the one that changed in the last two years. Both clients ship AI, and both route it to external model providers, so the question is not whether your mail reaches a model — it is what happens to it there.
Canary names its providers openly: OpenAI, Anthropic, Cohere, Google and others. It states it has opted out of data sharing, so your data will not be used to train or improve third-party models. It also describes personalised models that are created and stored on-device, which is a meaningfully different posture from building a server-side profile.
Superhuman states it restricts its AI service providers from training their models on user content. Its own models are a separate matter: the policy says you can decide whether Superhuman can use your content to train its AI models by adjusting the training controls in your account settings.
Read that last sentence carefully, because the mechanism is a setting rather than a guarantee. A control you can adjust is a control that has a default, and a default you did not choose is still a choice. If you deploy Superhuman across a team, check that setting on every account rather than assuming it.
Credentials and OAuth tokens: the quiet difference#
Every client needs access to your mailbox, and the interesting question is where the resulting credential lives. Canary's answer is the device, by default, with the push and cloud sync exceptions noted above. Superhuman's answer has to be the server, because a server-side sync and index cannot run without a token it can use while your laptop is closed.
That is not a criticism of Superhuman so much as an unavoidable consequence. Any client that syncs in the background holds a credential in its own infrastructure. The meaningful follow-up is how it is protected — envelope encryption, isolation from application code and logs, and a revocation path you control.
Whichever you choose, keep the revocation path in your own hands. For Gmail and Microsoft accounts you can withdraw access from your provider's security settings, which cuts off the client regardless of what its servers hold. For IMAP accounts, use an app password you can rotate rather than your account password.
Read receipts: both ship the thing privacy buyers dislike#
Here is the part a privacy comparison should not flinch from. Superhuman's read statuses work by inserting a small tracking image into your sent mail; when the recipient's client loads the image, the sender learns the message was opened. Superhuman's own explainer describes this and says the feature is now off by default, with a command-palette toggle to control it.
Canary advertises read receipts on its marketing site as a feature for power users. The underlying technique for read receipts in a normal mail client is the same tracking pixel. A product that is careful about your privacy is not necessarily careful about your recipients'.
On the receiving side, Superhuman documents a pixel-blocking option that suppresses trackers while still showing other images. Canary does not present an equivalent control with the same prominence on its public pages, which is worth checking in the app before you assume it.
If protecting the people you email matters as much as protecting yourself, the correct configuration in either client is the same: read receipts off outbound, remote image loading controlled inbound.

Pricing model shape, without the numbers#
Prices in this category move, and printing one in an article is a good way to be wrong within a quarter. The shapes are stable enough to be useful, though, and they tell you something about each vendor's incentives.
Canary publishes a free tier plus paid tiers, so you can run the client and evaluate its device-first behaviour before paying. Superhuman Mail is a paid subscription, sold for individuals and for business, and it is also packaged into the broader Superhuman Suite alongside other products from the same parent company.
The suite packaging is the part to check before committing. A bundle can mean your mail client is now governed by a set of terms that were written for several products, and the privacy questions you asked about the client may have different answers for the bundle.
Verify on the vendor's page before you buy
Who each one is genuinely for#
Neither product is the general answer. Each is a good answer to a specific question, and the questions are almost opposites.
- Choose Canary Mail if your threat model is a vendor holding your mail. You want the client to talk to your mail provider and nobody else, you have correspondents who use PGP, or you handle information where the fewest copies is the only rule that matters.
- Choose Canary Mail if you are a solo practitioner or a small firm without a procurement process, where the architecture argument is the one you get to make to yourself.
- Choose Superhuman Mail if you must pass a vendor security review. SOC 2 Type 2 and ISO 27001 with a named subprocessor list answer a questionnaire in a way that a device-first architecture, however sound, does not.
- Choose Superhuman Mail if the AI features are the reason you are switching. Server-side indexing is what makes them work, and asking for those features without that architecture is asking for a product neither vendor sells.
- Choose neither, and look at a dedicated encrypted provider, if you need end-to-end encryption as the default rather than as an option for correspondents who opt in.
A third option, honestly#
This comparison has a gap in the middle, and it is worth naming because it is where a lot of readers actually sit: you want an AI assistant that genuinely acts on the inbox, and you are not willing to accept vague answers about what happens to the mail it reads.
That is the position AI Emaily is built for, and we build it, so read this section knowing that. Our architecture is server-side like Superhuman's — we do not pretend otherwise, because an agent that triages mail while your laptop is shut has to be. What differs is what we commit to on top of it. Every AI call runs zero-retention through a single gateway, and your mail is never used to train, fine-tune or evaluate any model, ours or a provider's. There is no account toggle governing that, because there is nothing to toggle.
The rest is control rather than architecture. Voice matching comes from a Personal Context brain you write and per-client profiles you set, not from an analysis of your sent folder. Nothing is sent without your approval in Copilot mode, every agent action is reversible, and each one lands in an append-only audit log with the message that triggered it. Inbound tracking pixels are blocked by default.
Where we lose to Canary: we do not offer PGP end-to-end encryption, and if that is your requirement we are the wrong product. Where we lose to Superhuman today: we do not yet hold SOC 2 Type II, which is on the roadmap and not something we will claim early. If either of those is a hard gate, the honest recommendation is the product that clears it.
If it is not, and what you actually want is an agent with an audit trail and a written no-training commitment, that is the thing we do. Pricing is a 7-day free trial on our paid plans, card required, and nothing charged if you cancel before day seven.
How to check any of this yourself#
Privacy documentation is the one part of a software evaluation you can verify without installing anything. It takes about twenty minutes per vendor and it is more reliable than any comparison article, including this one.
- 1
Read the privacy policy for the word content
Search the page for message content or email content. A vendor that does not store it says so explicitly. A vendor that does will use softer language about access and processing.
- 2
Find the subprocessor list
It is usually linked from a trust centre. The presence of a vector database or a model provider tells you mail is indexed and sent for inference, regardless of what the marketing page says.
- 3
Look for the training clause and its default
Note the difference between we do not train on your content and you can turn training off. The second one has a default state, and you need to know what it is.
- 4
Check the certification scope, not just the badge
A SOC 2 report covers named systems over a named period. Request the report and confirm the mail client is inside the scope rather than a sibling product.
- 5
Test the outbound tracker setting on day one
Send yourself a message from the client and inspect the raw source for a remote image. If you find one, read receipts are on, whatever the default is claimed to be.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.