- Starting price
- Free
- Free tier
- Yes
- Platforms
- Windows · macOS · Linux
- Developer
- Gracious Tech Pty Ltd
- Launched
- 2021
- Updated
- Aug 16, 2026
The verdict
Stello is a rare alternative to conventional newsletter platforms. The desktop app keeps drafts and contacts on the sender’s device, uploads encrypted copies of each message, and emails individual links through the sender’s own account. Recipients need no Stello account and can view interactive sections, slideshows or video and send encrypted comments or reactions. Messages can expire or be retracted. It is free and open source, but it is not anonymous, multiuser, high-volume, or invulnerable: link recipients can forward or copy content, invitation emails remain ordinary email, local data is not separately encrypted, and sending is limited by the connected provider. Consent, unsubscribe, records, anti-spam law, device security, backups, and sensitive-region threat modeling remain the sender’s job.
Try Stello ↗Opens stello.news
Stello is a desktop newsletter composer from Australian nonprofit Christian technology developer Gracious Tech. Instead of placing the newsletter body in email, it sends each person a link to an encrypted browser-based letter. That allows richer layout, collapsible sections, galleries, video, reactions, comments, expiration, and retraction.
Drafts, contacts, and correspondence are primarily stored on the computer. Encrypted message copies and replies use cloud storage, while the decryption key stays in the URL fragment and is not sent to the hosting server. Stello says its service cannot read ordinary private correspondence by design, although abuse reports or voluntary access can reveal content.
The app uses the sender’s Google, Microsoft, or other email account to deliver invitations one by one. That can improve authenticity, but the provider’s daily limits and anti-abuse systems still apply. Stello’s guide gives examples from hundreds to a few thousand emails per day depending on account type and warns that real limits may be lower.
We reviewed the current site, technical and privacy guides, sending, contact, response, troubleshooting, privacy, terms, and faith.tools materials without conducting a cryptographic audit or production mailout. We did not verify source builds, penetration testing, provider OAuth scopes, deliverability claims, or recovery from every device-loss scenario.
✓ The good
- Free and open - Christian causes are promised continued free use and the software is openly inspectable
- Content encryption - cloud hosts receive encrypted message and response material rather than readable newsletters
- Local-first data - drafts and contacts remain primarily on the sender’s computer
- Recipient simplicity - readers open a browser link without creating an account or installing an app
- Interactive format - sections, media, comments, and reactions go beyond a flat email newsletter
- Expiry and retraction - hosted content can become unavailable after time, opens, or sender action
- Built-in unsubscribe - ordinary individual recipients receive an unsubscribe path tied to the sending profile
✗ Watch out
- Single-device design - there is no normal cloud login or collaborative multi-device editing workflow
- Local backup burden - losing an unbacked-up device can mean losing contacts, drafts, and readable history
- Link security model - anyone who obtains the full private link may read until expiration or retraction
- No copy prevention - recipients can screenshot, copy, photograph, download, or forward what they can view
- Provider sending limits - scale and account health depend on Gmail, Outlook, iCloud, or another connected service
- Local data not app-encrypted - Stello relies on the user to encrypt and secure the whole computer
- Compliance remains manual - consent, lawful basis, sender identification, records, suppression, and jurisdiction rules belong to the sender
Best for
- Missionaries and small ministries sending sensitive-but-shareable updates to a known, consenting list
- Christian organizations prioritizing local contacts, encrypted hosted content, no tracking business model, and zero software fee
- Solo communicators comfortable with desktop backups, email-provider limits, and a deliberately simple editor
- Teams whose recipients can safely receive a recognizable email containing a Stello link
Avoid if
- You need collaborative browser editing, granular team roles, CRM automation, large campaigns, transactional delivery, or advanced analytics
- A leaked link, screenshot, compromised device, or detectable Stello usage would create unacceptable safety consequences
- The ministry cannot maintain encrypted devices, tested backups, consent evidence, unsubscribe records, and sending-account security
- You expect expiry or retraction to remove copies that a recipient already captured or shared
What Stello is
Stello is an encrypted web-letter publishing tool layered on ordinary email invitations. It is not end-to-end encrypted email, anonymous communication, disappearing-message guarantee, secure document vault, email marketing service, CRM, team workspace, legal-compliance service, or protection from a compromised sender or recipient device.
The encryption protects hosted message content from the storage provider. It does not hide that Stello is being used, protect the ordinary invitation text, prevent link forwarding or screenshots, encrypt most local app data, or erase copies already made by a recipient.
Why local-first newsletters trade convenience for privacy
Conventional email platforms centralize a list, drafts, message bodies, opens, and automation in a vendor account. Stello stores the working relationship on one computer and gives the cloud only encrypted hosted copies plus limited operational metadata.
That reduces provider visibility but removes familiar conveniences. The sender becomes responsible for device encryption, backups, continuity, collaboration, provider authentication, sending limits, and recovery. This is a deliberate threat-model choice, not a universally better workflow.
Encrypted interactive web letters: secure hosting, shareable endpoints
Each recipient gets an individual invitation to a hosted message whose text, media, configuration, and replies are encrypted. The browser receives the key from the link, decrypts locally, and can display interactive content without an account.
Treat the full link as a bearer credential. Use short expiry and limited opens for higher sensitivity, avoid secrets that cannot tolerate copying, keep invitation text nonsensitive, and use a stronger channel when identifying the ministry itself is dangerous.
Own-account sending and contacts: authentic delivery with real limits
Stello connects to an email account, sends one invitation per person, maintains groups and profile-specific unsubscribes, can sync selected contacts, and resumes interrupted sends without intentional duplication.
Authenticate the account with strong multifactor protection, use an organizational mailbox rather than a personal life-critical account, start slowly, remove disengaged recipients, honor every unsubscribe, and never use the tool for unsolicited lists.
Expiry, retraction, responses, and local history: useful but not erasure
A sender can expire messages by time or opens, retract access, and receive encrypted reactions or comments tied to local contacts. Replies can remain encrypted unless the sender opts to put readable content in email notifications.
Expiration deletes or disables the hosted copy; it cannot retrieve screenshots, copied text, downloaded media, or a recipient’s notes. Plan retention and records intentionally, especially for donors, safeguarding, employment, and legal obligations.
Pricing
Stello software
Free
Desktop app, message hosting, encryption, interactive newsletters, responses, expiry, and retraction are offered without a paid plan.
Christian causes
Promised free
The privacy guide says Christian-cause use will never receive a premium plan; other uses are currently free.
Email account
Existing provider
Invitations use the sender’s own email service, whose subscription, OAuth policy, and daily limits apply.
Operations
User-managed
Encrypted device storage, backup, domain email, compliance, training, and security review remain outside the free service.
Stello charges nothing for the app or its standard hosted message service.
The project says it will not introduce a premium plan for Christian causes, while other use remains free for the foreseeable future. A promise is not a funded service-level agreement.
The connected email account may be free or paid and sets real volume limits. Exceeding them can temporarily stop all outgoing mail from that account.
Budget for a dedicated mailbox or domain, encrypted hardware, secure backup, security keys, staff time, compliance advice, and an alternative channel if Stello or the email provider is unavailable.
Where Stello falls behind
Publish current independent cryptographic and application security audits, threat model, vulnerability reporting, release signing, dependency process, and incident history.
Provide precise operational metadata, storage region, deletion timing, backups, logs, provider list, government-request practice, and disaster-recovery commitments.
Add a safe supported collaboration model or clearer continuity workflow for organizations without weakening local-first principles.
Improve account recovery, encrypted backup, restore testing, device migration, and key-management documentation for nontechnical ministry users.
Offer jurisdiction-aware compliance guidance and stronger suppression safeguards across sending profiles while keeping senders responsible for legal advice.
Stello vs. Mailchimp vs. Signal
Mailchimp is a full marketing platform with browser collaboration, templates, analytics, automation, segmentation, delivery infrastructure, and compliance tooling, but it centralizes much more data. Stello is free, local-first, encrypted, simple, and constrained by the sender’s email account.
Signal provides mature end-to-end encrypted person or group messaging but requires participants to use Signal and is not a designed newsletter publication workflow. Stello offers a reader-friendly no-account webpage while relying on the secrecy of each link.
Choose based on threat model and operation. Use Stello for known audiences and small secure-ish updates, Mailchimp for consented marketing operations where vendor processing is acceptable, and Signal or another vetted secure messenger for reciprocal high-sensitivity communication.
The bottom line
Stello is one of the few tools in this catalog whose limitations clearly follow from a coherent privacy design. It gives missionaries and small ministries a polished interactive letter without handing readable newsletters and a full contact database to a marketing vendor. That does not make every message safe: the invitation, link, devices, recipients, and email account remain exposed. Use dedicated accounts, strong device encryption, tested backups, short expiry, consented lists, and modest sensitivity. For that audience and threat model, Stello is an excellent free tool.
Alternatives to Stello
Frequently asked questions
Is Stello really free?
Yes. The software and standard message hosting are free, with an explicit promise of no premium plan for Christian-cause use.
Do recipients need Stello?
No. They open an individual browser link from the invitation and can read or respond without an account or installation.
Can Stello read my newsletters?
Ordinary hosted content is encrypted so the service says it cannot read it. Abuse reports, voluntary access, unencrypted notifications, devices, or recipients can still expose content.
Can a recipient forward a Stello message?
Anyone with the complete working link may be able to open it until limits, expiry, or retraction intervene. Recipients can also copy or screenshot visible content.
Can a team edit from several computers?
Not through a normal cloud workspace. Stello is intentionally single-device; its guide describes cautious workarounds and device migration rather than simultaneous collaboration.
How many newsletters can I send?
Stello does not set a marketing quota, but the connected email provider does. Its guide lists examples ranging from hundreds to a few thousand per day, often lower for new accounts.
Does retraction erase a message everywhere?
No. It blocks the hosted copy, but cannot erase screenshots, copied text, downloaded material, photos, or notes already made by a recipient.
