HomeJoin Waitlist
Home•Join Waitlist•Policies•Privacy•Terms

© 2026 AliasFleet. All rights reserved.

    Policies
    Privacy

    Data Retention & Deletion

    Last updated July 10, 2026

    This policy details how long AliasFleet retains your data and the procedures for account deletion and data export.

    Data Retention Schedule

    Account Data (Active Accounts)

    While your account remains active, we retain the following:

    Data TypeRetention PeriodNotes
    Profile informationUntil account deletionName, email, username, avatar
    AliasesUntil deleted or account closureAlias names, domains, destinations
    DestinationsUntil deleted or account closureEmail addresses, verification status
    Custom domainsUntil deleted or account closureDomain names, DNS settings, DKIM keys
    User preferencesUntil account deletionTheme, settings, notification preferences
    PGP keysUntil removed or account deletionPublic keys only; private keys never stored
    2FA settingsUntil disabled or account deletionHashed secrets only

    Activity and Log Data

    Data TypeRetention PeriodPurpose
    Email forwarding logsFree: 7 days, Pro: 30 days, Business: 90 daysDelivery status, timestamps, and metadata (no email content is logged)
    Failed login attempts30 daysFraud detection and rate limiting
    API request logs90 daysSecurity analysis and debugging
    Session data14 days (inactive)Session management and security
    Support tickets90 days after closureCustomer service and issue resolution
    Abuse reports90 daysCompliance and security investigations

    Billing Data

    AliasFleet does not store billing records on our servers. All billing data is handled by Stripe:

    Data TypeStorageNotes
    Stripe Customer IDStripe onlyReferenced in our database for subscription management
    Subscription statusOur databaseActive/cancelled status only, no payment details
    Payment methodNever storedHandled entirely by Stripe
    InvoicesStripe onlyAvailable in your Stripe customer portal
    Billing addressesStripe onlyCollected during checkout

    For information about Stripe's data retention, see Stripe's Privacy Policy.

    Account Deletion

    How to Delete Your Account

    1. Navigate to Settings → Security
    2. Scroll to "Delete Account" section
    3. Review what will be deleted
    4. Confirm your identity (password/2FA required)
    5. Confirm deletion

    Warning: Account deletion is permanent and cannot be undone. We cannot recover deleted accounts.

    What Happens When You Delete

    Immediate (0-24 hours):

    • All aliases and forwarding configurations removed
    • Profile information deleted
    • Custom domains detached and DNS records scheduled for removal
    • Active sessions terminated
    • API keys revoked

    Short-term (7-30 days):

    • Data purged from primary database
    • Search indexes updated
    • Database backups purged per retention cycle

    Selective Data Deletion

    You can delete specific data without closing your account:

    Data TypeHow to DeleteImmediate?
    Individual aliasesAliases dashboard → DeleteYes
    DestinationsDestinations page → RemoveYes (requires re-verification to re-add)
    Custom domainsDomain settings → DeleteYes (DNS propagation may take 24-48 hours)
    PGP keysDestination settings → Remove encryptionYes
    Active sessionsSettings → Security → Revoke sessionsYes
    Export dataDelete downloaded files from your deviceYes

    Data Export

    You can export a copy of your data before deletion:

    1. Go to Settings → Profile → Export Data
    2. Select data types to include
    3. Request export
    4. Download the JSON archive when ready
    5. Verify the export contains expected data

    Export includes:

    • Profile information
    • Alias configurations
    • Destination addresses
    • Custom domain settings (without DKIM private keys)
    • User preferences
    • Billing history (last 12 months)

    Export does NOT include:

    • Email content or attachments
    • PGP private keys (we don't store these)
    • System logs or internal identifiers
    • Other users' data

    Data Retention Exceptions

    Legal Holds

    We may be required to retain certain data beyond standard periods when:

    • Subject to active litigation or investigation
    • Required by court order, subpoena, or legal process
    • Related to fraud, abuse, or security incident response
    • Mandated by government request under applicable law

    When a legal hold applies:

    • Affected data is preserved and protected from deletion
    • You will be notified if legally permitted
    • Data is released only to authorized parties per legal process

    Security Incidents

    In the event of a security breach or attack:

    • Relevant logs may be retained beyond standard periods
    • Data is used for investigation, remediation, and prevention
    • Retention extends only as long as necessary for security purposes

    Automated Data Purging

    Our systems automatically delete data according to the following schedule:

    Data TypePurge FrequencyRetention
    Email forwarding logsDailyFree: 7 days, Pro: 30 days, Business: 90 days
    Failed login attemptsDaily30 days
    Temporary session dataDaily14 days inactive
    Deleted alias recordsWeekly30 days
    Old API keysMonthly90 days after revocation
    Closed support ticketsDaily90 days after closure
    Analytics logsMonthly90 days

    Third-Party Data

    Some data is processed by external services:

    Stripe (Payments):

    • Billing data subject to Stripe's retention policies
    • Payment card details never touch our servers

    Cloudflare (DNS & DDoS Protection):

    • DNS routing and DDoS mitigation are provided by Cloudflare
    • Custom domain DNS records managed via Cloudflare's API
    • DNS propagation typically takes 24-48 hours after deletion
    • No email content or user data is stored by Cloudflare

    PostHog (Product Analytics):

    • Used to capture pageview URLs, browser/device info, and identified user details (email and full name)
    • No email content or password tracking is performed

    Sentry (Error Monitoring):

    • Used to monitor and debug application errors
    • No PII is collected, no session replay is used, and only error details are processed

    Infrastructure & Security

    All user data (except data processed by Stripe, Cloudflare, Sentry, and PostHog as described above) is stored on dedicated servers leased from a third-party infrastructure provider in the European Union (specifically France and Germany). All data is encrypted in transit via TLS.

    GDPR and CCPA Privacy Rights

    Under privacy laws such as the General Data Protection Regulation (GDPR) in the EU and the California Consumer Privacy Act (CCPA) in the US, AliasFleet acts as the Data Controller for your personal data.

    Depending on your jurisdiction, you have specific data subject rights:

    • Right to Access / Know: Request a copy of your personal data stored on our systems.
    • Right to Rectification / Correction: Correct inaccurate or incomplete personal information.
    • Right to Deletion / Erasure: Request the permanent removal of your personal data.
    • Right to Data Portability: Request that your data be provided in a structured, commonly used, and machine-readable format.
    • Right to Restriction of Processing: Limit how we process your personal data in certain circumstances.

    To exercise any of these rights:

    • Submit your request directly to our legal department via email at legal@aliasfleet.com.
    • Please include your account email address and specify which right you wish to exercise.
    • For security purposes, we require identity verification before processing requests that access or modify personal data.

    Verification of Deletion

    When you request deletion, we provide:

    • Confirmation when deletion is complete
    • Reference number for your records
    • List of any data retained under legal exceptions

    What We Cannot Delete

    Certain data cannot be deleted:

    • Anonymized analytics: Data stripped of personal identifiers
    • Aggregated statistics: Summarized usage metrics
    • Legal records: Data required by law to retain
    • Backup archives: Until the backup rotation cycle completes (up to 30 days)

    Policy Updates

    We may update this Data Retention Policy to reflect:

    • Changes in legal requirements
    • New service features
    • Improved data practices

    Updates will be posted on this page with an updated effective date.

    Contact

    Privacy and data requests: legal@aliasfleet.com

    Related

    Terms of ServicePrivacy PolicyAcceptable Use PolicyAnti-Spam Policy

    Effective July 10, 2026. Contact support