Smári here, from the Mailpile team. There's no HSTS because Mailpile is generally supposed to be run on localhost. We don't bundle SSL certs because it simply wouldn't make sense. That said, we will be improving things w.r.t. use of SSL and Internet-facing installations before 1.0, including authentication mechanisms and such. We will also be doing some Content Security Policy work before 1.0.
just wanted to say it's great seeing security integrated into such a product from the start!
It should run on SSL even if it is localhost. Self-signed cert/adding a personal CA is a valid config.
If you are proposing to be secure, I would think that you want to cover security (encryption in this case) for both in-flight and at-rest data in both local and internet facing configurations.