Last Updated: September 2026. How we engineer sovereign privacy and safeguard your digital identity.
Our Unconditional Privacy Guarantee
We do not sell, rent, monetize, trade, or share your personal information, communications, or usage data with data brokers, advertisers, or third parties under any circumstances. Our platform is architected around ephemeral processing and strict data minimization: communication packets are protected with industry-standard encryption, server infrastructure operates on locked data streams, and private email bodies are not retained in persistent storage.
1. Ephemeral Encrypted Relay & Tracker Shield™
Incoming emails are encrypted in transit using industry-standard transport encryption where available. During forwarding, Masker temporarily processes message contents in volatile memory (RAM) to remove known tracking pixels and malicious telemetry before immediately relaying the sanitized email to your verified destination inbox.
Email bodies are processed temporarily in volatile memory for delivery and tracker removal. After successful forwarding, Masker does not intentionally retain message bodies in persistent storage except where required for debugging, abuse prevention, or legal compliance.
🛡️ Tracker Shield™ ProtectionTracker Shield automatically removes known email tracking pixels, spy beacons, read receipts, and telemetry links before emails reach your inbox. Every removed tracker is counted and displayed inside your Privacy Dashboard so you have total visibility into blocked surveillance attempts.
2. Information We Collect & Security Architecture
We adhere strictly to the principle of data minimization. We only collect the bare technical data necessary to operate your sovereign account:
Account Credentials & Passwords: Your registered account email address. Passwords are securely hashed using modern cryptographic algorithms (such as bcrypt or Argon2id). Transport encryption strictly uses HTTPS/TLS 1.3 across all communication channels.
Routing Configuration: The privacy aliases you create, claimed username subdomains, mapped custom domains, and verified destination inboxes required to route your communications.
Billing Identifiers: Subscription status and prepaid credit balances. Sensitive payment card numbers (PAN, CVV) are handled directly by licensed PCI-DSS payment gateways and are never stored on or accessible to our servers.
Aggregated Counters: High-level numerical volume counters (e.g., total forwarded emails this billing cycle) required to prevent network abuse and enforce subscription quotas.
Cookies & Local Storage
We use strictly functional cookies and local storage tokens for:
User interface preferences (dark theme selection and regional currency detection cache).
Security tokens (CSRF protection).
We do not use third-party advertising cookies or cross-site tracking trackers.
3. Data Access Safeguards & Communications Privacy
Masker does not access or review users' email contents except when processing is technically required to provide the service (for example, forwarding emails or removing tracking pixels), or where required by applicable law or with the user's explicit request for support.
❌ Email Bodies & AttachmentsMessage bodies are processed ephemerally in RAM and are not permanently retained in storage databases after forwarding.
❌ Voice Call ContentWe do not record, tap, or transcribe voice calls. Call metadata (such as timestamps, duration, routing status, and forwarding success) may be retained for billing, abuse prevention, diagnostics, and quota enforcement.
📱 Inbound SMS Retention ControlsUsers may configure automatic SMS deletion after 24 hours, 7 days, 30 days, or retain messages until manually deleted from their dashboard inbox.
❌ Browsing Histories & ProfilesWe do not track web browsing history, sell device fingerprints, or build advertising behavioral profiles.
4. Third-Party Infrastructure & Carrier Delivery
Masker uses third-party infrastructure providers, email delivery services, payment processors, and licensed telecommunications carriers solely to provide forwarding, SMS delivery, phone numbers, and payment processing.
To execute core telecommunication and message delivery functions across national carrier networks and global routing paths, strictly necessary delivery payloads and technical routing headers (such as destination phone numbers, recipient email MX records, and message transmission envelopes) are transmitted directly to our authorized upstream partners. These partners process data solely to execute technical delivery in compliance with global telecommunications regulations and carrier security standards.
5. Virtual Numbers & Breach Shield
Virtual Phone Lines & Inbound SMS: Incoming SMS verification messages sent to your allocated masked lines are received via encrypted webhooks and displayed privately within your authenticated Dashboard inbox.
Breach Shield: Masker securely queries trusted breach-monitoring providers to determine whether your registered email addresses have appeared in known public data breaches. Only the minimum information required to perform the lookup is transmitted.
6. Browser Extension Permissions
The official Masker browser extension requests specific permissions strictly to facilitate in-browser privacy:
Form Field Interaction: The extension detects email and phone input fields on web pages to render the Masker icon, enabling one-click generation and auto-filling of new privacy aliases.
API Communication: The extension communicates exclusively with Masker servers via authenticated API tokens to fetch or create aliases.
No Browsing Tracking: The extension never logs keystrokes outside generated alias fields, does not record browsing history, and never transmits visited web URLs to our servers.
7. Data Retention & Right to Complete Deletion
You maintain complete sovereignty over your privacy data:
Alias Deactivation & Burning: Disabling or deleting an alias immediately severs the routing tunnel. Any subsequent incoming emails to that address are rejected at the edge gateway. Deleted aliases cannot be recovered once deletion is completed.
Permanent Account Deletion: You may request full account deletion at any time via Account Settings. Account termination permanently purges all aliases, username subdomains, mapped domains, and phone number allocations from our database.
International Privacy Rights: In compliance with global privacy regulations (including GDPR, CCPA, and NDPR), you possess the right to access, rectify, port, and delete any personal data associated with your identity.
8. Privacy Inquiries & Contact
If you have any questions regarding this Privacy Policy, our ephemeral routing protections, or wish to exercise your statutory data subject rights, please reach out to our privacy compliance desk through your authenticated dashboard or via our dedicated support links.
Also review our Terms of Service for rules governing platform usage, billing error exceptions, and acceptable use.