Privacy

Privacy policy.

Last updated: 2026-07-24. Effective: 2026-07-24.

This policy describes what Maski collects, why we collect it, how we protect it, and what you can do with it. It applies to maski.dev, the Maski API, any branded alias domain we operate (e.g. alias4me.in), and any custom domain you connect to Maski and verify.

What we collect

Account data. The email address you sign up with, an optional secondary email for recovery, an optional password (Argon2id-hashed), your active sessions, and your plan state. If you set up paid billing, we also store the customer and subscription identifiers issued by our payment processor, never your card details.

Alias data. The aliases you create, the destination address each alias forwards to, and per-sender rules you configure (forward, block, or hold). If you connect a custom domain, we also store the domain name and the DNS-verification records we generate to confirm you control it.

Browser extension. If you install the Maski browser extension, it stores an API key and your account email address on that device only, so you do not have to connect again. When you create an alias from the extension, it sends us the hostname of the page you are on and we store it as that alias's label. The label is private: only you see it, and it never appears in mail you send or receive. It is what lets the extension show you which address you already use on a site. The extension reads form fields on the page you are on to find where an email address goes; that stays in your browser and is never sent to us. It does not read page content, form values, or your browsing history, and it contacts no server other than ours.

Message metadata. For every inbound message that hits one of your aliases, we record sender, recipient alias, timestamp, size, content-type summary, and delivery status (forwarded, held, dropped, bounced). This is what lets us bill, surface activity in your dashboard, and stop forwarding when a destination starts hard-bouncing.

Message contents. Subjects, bodies, and attachments. We hold them only as long as we need to forward them, plus any inbox-hold window you've configured for a specific sender.

Operational logs. Web request logs, SMTP connection logs, and error reports. These are scrubbed of email addresses, message contents, and credentials before they're written.

Site analytics. maski.dev runs Cloudflare Web Analytics to see aggregate traffic: page views, referrers, and load performance. It is cookieless: it sets no cookies, stores nothing on your device, and does not fingerprint you or build a cross-site profile. Cloudflare processes this on our behalf and does not sell or enrich the data. It measures the website, never the contents of your mail.

What we do not collect

We do not place tracking cookies on maski.dev. Our only analytics is the cookieless Cloudflare Web Analytics described above, and we run no other third-party analytics scripts and no advertising trackers. We do not buy or enrich identity data from third parties.

The browser extension sends us no page content, no form values, and no browsing history — only the hostname you create an alias on, and only at the moment you create one.

How we protect your data

Encryption at rest. Sensitive fields are encrypted with AES-256-GCM before they're written to the database. That covers your login email, secondary email, alias destinations, sender contact addresses, and message subject + body + attachments. The encryption keys are stored on the server, separate from the database.

Blind-index lookups. For fields we need to look up (your login email, an alias destination, a sender contact), we store a one-way HMAC-SHA-256 fingerprint alongside the ciphertext. Lookups happen against the fingerprint. An attacker with read access to a database dump cannot enumerate or reverse the encrypted values.

Encryption in transit. All web traffic uses TLS. WebSocket connections use WSS. The database connection enforces TLS. Inbound SMTP advertises STARTTLS to senders that support it.

Log discipline. Our logger filters strip email addresses, message contents, API keys, and session tokens. We do not log the bodies of the messages we forward.

Operator access. No Maski operator has standing access to your message contents. Subjects, bodies, and attachments stay encrypted at rest and are never shown in our admin tools. For support, an operator can look up your account and reveal account details such as your login email address; that address is decrypted only for that request, is never stored in plaintext, and every reveal is recorded in our audit log. That audit log (an append-only record of admin actions against accounts, including who did it and to whom) is live today. Database access is otherwise restricted and time-bound.

Who we share it with

We share data only with the sub-processors required to run the service. We do not sell your data, share it for advertising, or analyze message contents for training, ads, or insights of any kind.

| Sub-processor | What they receive | Purpose | | --- | --- | --- | | Amazon Web Services | Encrypted application and database data at rest, the outbound forwards we send plus their envelope metadata, and encrypted backups and exports | Hosting (EC2), email delivery (SES), and backup storage (S3), all in the ap-south-1 (Mumbai) region | | Dodo Payments | Your billing email, plan, and subscription state | Merchant of Record, handles tax, invoicing, refunds, and chargebacks |

If we add or remove a sub-processor, we update this list and date the change in the "Last updated" line above. Material changes also go out by email.

How long we keep it

Aliases you delete enter a 30-day grace period during which mail to them is silently dropped. After the grace window, the alias is permanently retired, and neither you nor anyone else can re-claim it. This protects the next person who might otherwise inherit residual mail.

Held messages sit in your inbox-hold area only as long as the configured TTL (default 7 days). After that, they're deleted.

Anonymous-mode forwards are held for the brief configurable window (default 5 minutes), forwarded, and discarded. They are not retained afterwards.

Your account. When you delete your account, deletion is immediate. The cascade removes every row that belongs to you: aliases, contacts, sender rules, held mail, sessions, recovery codes, audit entries, and billing references. There is no "we'll process this within 30 days" delay. Aliases you've previously retired stay retired.

Operational logs. Retained 30 days, then rotated out. PII is already filtered before write.

Your rights

Export. From the Account page, you can export everything we hold for you as JSON. Available on every plan, including free, including during a trial.

Correction. Update your login email, secondary email, and alias destinations from your account at any time.

Deletion. Delete your account from the Account page. Immediate. Cascading. No retention.

Objection and restriction. You can pause an alias instantly to stop new mail. You can block any sender. You can opt your account out of the pilot promotion grant.

Complaints. If you believe we've handled your data improperly, you can write to hey@maski.dev. If you're in a jurisdiction with a data protection authority, you may also complain to that authority directly. Maski's status is that of a data controller for the data described in this policy.

Children

Maski is not directed at children under 13, and we do not knowingly collect data from anyone under 13. If you are under the age of majority in your country, you may use Maski only with the consent and supervision of a parent or legal guardian. If you believe a child has signed up without that consent, write to hey@maski.dev and we'll remove the account.

International transfers

Maski's primary infrastructure (application, database, outbound email, and backups) runs in Amazon Web Services' ap-south-1 (Mumbai) region, in India. Our payment processor, Dodo Payments, operates globally for payment, tax, and fraud processing. If you use Maski from outside India, your data is processed in India and, for payments, may be processed in other regions.

Changes to this policy

We update this policy when our practices change. The "Last updated" date at the top reflects the most recent revision. Material changes (adding a sub-processor, changing what we collect, changing retention windows) go out by email to your account address before they take effect.

Contact

For privacy questions, complaints, sub-processor questions, or security disclosures: hey@maski.dev.