Curo
Services
- AI
- SaaS
- Full-Stack
- Multi-Tenant
- Zero-Knowledge Encryption
- Universal Mailbox Ingestion
- AI Triage Engine
- Voice Personality Engine
- Metered AI Billing
- Native Calendar
- Two-Way Sync
- Booking Links
- Push Notifications
- PWA + Mobile
Architecture
CuroMail (curomail.com) is a full email client, owner console, and native mobile shell on a FastAPI + Postgres backend exposing 288 live API paths across 43 route modules. It connects Gmail OAuth, Microsoft Graph, or any IMAP account with auto-detection, and layers an AI triage engine that scores every message 1–10, categorizes it, and drafts a reply — with deterministic pre-AI filters that kill bounces and phishing at zero token cost. A linguistic Voice Engine profiles the user's real sent mail to draft in their own voice; smart views (Commitment Ledger, Ghosting Radar, an AI first-contact Screener, private auto-unsubscribe) sit on top. Security spans Fernet-encrypted credentials at rest, TOTP and WebAuthn hardware keys, a zero-access vault, and end-to-end-encrypted secure messages, with LemonSqueezy billing as merchant of record.
- Python
- JavaScript
- PostgreSQL
- AWS SES
- LemonSqueezy
- Firebase Cloud Messaging
- WebCrypto AES-256-GCM
Features
Universal mailbox — Gmail OAuth, Microsoft Graph, or any IMAP account auto-detected, with per-mailbox signatures, Cc/Bcc/from-override, scheduled send, templates, and history backfill
AI triage engine — scores every email 1–10, assigns a category, and drafts a reply; deterministic filters kill bounces and phishing before any token is spent
Voice Engine — deterministic linguistic analysis of your real sent mail builds a shareable Voice Card; a privacy invariant guarantees shared cards carry only derived numbers, never message content
Smart views — a Commitment Ledger that extracts promises and auto-detects fulfillment, a Ghosting Radar, a HEY-style first-contact Screener, and private auto-unsubscribe with no list-server ping
Encryption at rest — Fernet AES-128 protects OAuth tokens, IMAP passwords, and voice snippets (23/23 stored credentials verified to decrypt clean)
Hardware-key security — TOTP and WebAuthn, a Zero-Access Vault, E2EE secure messages with a Trust Center, and OpenPGP mail-to-mail, behind full HTTPS/HSTS headers
Honest data posture — message bodies sit plaintext in Postgres to power AI and search, protected by transport, OS, and localhost isolation rather than at-rest column encryption (disclosed, not overclaimed)
Owner console — a 1,846-line, 401-gated back office showing live spend by provider and model, unit economics per user and per 1k emails, margin and 10x/100x projections, and tenant lifecycle
Billing — LemonSqueezy merchant-of-record with Free, Pro, Power, and Team tiers, an HMAC webhook that fails closed, and plan-to-feature gating
Calendar sync — working Google (syncToken), Microsoft (delta), and CalDAV engines plus Calendly-style bookable links and .ics export
Native mobile shell — a Capacitor iOS + Android app with native push wrapping the web client; built and drafted for the stores, store submission pending
Gallery

Dark hero: "Your inbox, handled" with sample triaged email cards

AI Screener and Private Auto-Unsubscribe feature cards with example senders

Pricing table comparing four tiers by triage cadence and features

Ruthless noise filtering and roadmap section listing calendar and meeting features

Mobile hero view of the inbox-handled headline and waitlist buttons
Forensic Build Metrics
Lines of code
62,755
Commits
470
Defects logged
218
Traditional build cost
$1,301,625–$3,136,500
Effort (person-years)
16.4
Sustained team size
12.2
Built in 0.6 calendar months. Defects — valuation.json defects_total snapshot — matches proof.html and the forensic reports.
Deployed live at curomail.com as a production multi-tenant SaaS handling real signups, encrypted messaging, native calendar/booking, and metered AI billing.

Next project
6ixElement