pux

Encrypted OTP relay. No accounts. No stored emails.

How it stays private

  • Client-side keys. Your encryption keypair is generated on your phone. The private key never leaves your device.
  • Public key only. The server stores your public key so it can encrypt OTPs for you. It cannot decrypt them.
  • Sealed boxes. OTP payloads are encrypted with libsodium sealed boxes before push delivery.
  • No stored mail. Inbound email is parsed in memory and discarded. OTPs are never written to disk or the database.
  • No accounts. A record ID is your only credential. Add more devices by scanning a QR from an enrolled phone.

Get started

  1. Install the pux Android app.
  2. Open the app and tap Create new relay.
  3. Copy your inbox address and set up email forwarding from your bank OTP address.
  4. Grant notification permission when prompted.

Enrollment happens entirely in the mobile app. The server never sees your private key.

SMTP relay

This server accepts inbound mail for *@pux.vidur.xyz (or your configured mail domain). Only recipients with a valid inbox token are accepted. Messages are size-limited and processed in memory.