Your key. Your provider. Your bill.
BYOK gives you every AI feature in Pro, routed through a provider key you supply. Use one model for everything or a different one per feature, keep token spend on your own account, and keep your key encrypted on our server, never in the browser.
Add a key, map your models, pay the provider.
Same AI features as Pro, only you decide which provider answers each one. Setup takes a few minutes in Settings, and nothing else about the app changes.
Add your provider key(s)
Settings → AI lets you paste keys for Anthropic, OpenAI, Gemini, xAI, or OpenRouter. We validate each one before saving. Use one. Use all five.
Map models to features
Each AI surface (triage, summary, draft, command bar, task suggest) gets its own model picker. Use one model for everything, or specialize per surface.
Tokens on your bill
Every call hits the provider you chose, on your account. Keys are encrypted at rest under your per-user DEK and never sent to the browser.
- 01
Add your provider key(s)
Settings → AI lets you paste keys for Anthropic, OpenAI, Gemini, xAI, or OpenRouter. We validate each one before saving. Use one. Use all five.
- 02
Map models to features
Each AI surface (triage, summary, draft, command bar, task suggest) gets its own model picker. Use one model for everything, or specialize per surface.
- 03
Tokens on your bill
Every call hits the provider you chose, on your account. Keys are encrypted at rest under your per-user DEK and never sent to the browser.
Seven AI features, each with its own picker.
Pro runs on our hosted Claude, so there's no token meter to watch. BYOK opens five providers and 300+ models, with a per-surface picker. Use one model for everything, or specialize: a small fast model for triage, a larger one for drafts.
Triage
Sorts incoming mail so the messages that need you come first.
Summary card
One-paragraph thread summary in the reader; cached on the latest message.
Action items
Extracts implied to-dos from a thread; you confirm before they become tasks.
Draft reply
Generates a reply in your voice; you review and press send.
Rules test
Try a rule against your inbox before saving it, so you see what it would catch.
Command bar
Natural language to app action. "Snooze every unread newsletter until Sunday."
Task suggest
Given a thread or selection, propose a task title, deadline, and time estimate.
Defaults shown. BYOK users can swap any row to any model across Anthropic, OpenAI, Gemini, xAI, or OpenRouter.
A provider key, kept like a secret.
BYOK means we hold a credential for you, so we treat it the way we treat OAuth tokens: encrypted, server-side, audited, and removable on demand.
Validated once, then encrypted at rest
We check each key against the provider before saving it, then store it with AES-GCM under your per-user data-encryption key, itself wrapped by a KMS master key.
Never sent to the browser
Keys live server-side only. Prompts go from our backend straight to the provider over TLS 1.2+; the key never reaches the client and never lands in a log or an error report.
You are the customer of record
Calls run under your own provider account, so their terms govern the request and every token lands on your bill at provider rates, with no Syncro meter and no markup.
Isolated from the hosted tier
BYOK routing and our hosted Pro routing stay isolated from each other. Your key is used only to authenticate the calls you initiate, and only for your account.
Yours to remove, any time
Flip back to Pro or delete a key whenever you like. Removing a key clears it from storage, and switching routing mode never breaks anything mid-month.
Validated once, then encrypted at rest
We check each key against the provider before saving it, then store it with AES-GCM under your per-user data-encryption key, itself wrapped by a KMS master key.
Never sent to the browser
Keys live server-side only. Prompts go from our backend straight to the provider over TLS 1.2+; the key never reaches the client and never lands in a log or an error report.
You are the customer of record
Calls run under your own provider account, so their terms govern the request and every token lands on your bill at provider rates, with no Syncro meter and no markup.
Isolated from the hosted tier
BYOK routing and our hosted Pro routing stay isolated from each other. Your key is used only to authenticate the calls you initiate, and only for your account.
Yours to remove, any time
Flip back to Pro or delete a key whenever you like. Removing a key clears it from storage, and switching routing mode never breaks anything mid-month.
Bringing your own key, answered.
Where is my provider key stored?
Encrypted at rest with AES-GCM under your per-user data-encryption key, itself wrapped by a KMS master key. It is validated once when you save it, used only to authenticate the calls you initiate, and never sent to the browser or written to a log.
Which AI providers does BYOK support?
Anthropic Claude, OpenAI, Google Gemini, xAI, and OpenRouter (which fans out to 300+ models). Use one key for everything, or wire different providers to different surfaces — a small fast model for triage, a larger one for drafts.
Can I switch between Pro and BYOK?
Yes. Routing mode is a single setting in Settings → AI. Switch any time; nothing breaks mid-month. Keys you added stay put if you flip back to Pro, and you can remove them whenever.
Who pays for the tokens?
You do, directly. Every call runs under your own provider account, so usage lands on your bill at provider rates — there is no Syncro token meter or markup on top. You are the customer of record with that provider.
Bring your own provider key, or run on ours.
Same AI features either way. Seven-day trial. Request access.