HomeJoin Waitlist
Home•Join Waitlist•Policies•Privacy•Terms

© 2026 AliasFleet. All rights reserved.

    Policies
    Essential

    Privacy Policy

    Last updated July 10, 2026

    This Privacy Policy describes how AliasFleet collects, uses, and protects your personal information when you use our email alias management service.

    Information We Collect

    Account Information

    When you create an account, we collect:

    • Email address (for account notifications and password resets)
    • Username (public identifier for your account)
    • Full name (optional, for personalization)
    • Avatar URL (optional, for profile display)
    • Website URL (optional, for public profile)
    • Password (hashed using bcrypt with salt)
    • Identity number (internal reference)
    • IP address and user agent at registration

    Service Data

    To provide email forwarding services, we store:

    • Aliases: Alias names, domains, forwarding destinations, activation status, categories, and description
    • Destinations: Email addresses, verification status, PGP public keys (optional), WKD encryption settings
    • Custom Domains: Domain names, DNS verification status (MX, SPF, DKIM, DMARC), DKIM keys
    • Email Logs: Delivery status, timestamps, sender/recipient metadata (not email content)
    • Settings: Display preferences, notification settings, From name/subject customizations
    • Advanced Configurations (Pro/Business): Custom forwarding rules, whitelists/blacklists, catch-all routing settings, webhook URLs, log anonymization schedules, and Developer API keys

    Usage and Analytics Data

    We collect activity and system information to monitor service performance, prevent abuse, and improve the user experience:

    • Login timestamps and IP addresses
    • Session information (device type, browser, pageview URLs)
    • Alias creation and modification history
    • Email forwarding counts per alias
    • Failed authentication/login attempts (retained for 30 days)
    • Developer API usage (for rate limiting and system monitoring)
    • Error Monitoring (via Sentry): We collect application error logs to diagnose and fix bugs. This error monitoring processes technical logs only; it does not collect Personally Identifiable Information (PII) or perform session replays.
    • Product Analytics (via PostHog): We collect pageview URLs, browser/device information, and identified user details (email and full name). PostHog does not track email content, passwords, or perform session replays.

    What We Don't Collect

    We do not:

    • Read, store, or analyze the content of emails passing through aliases
    • Store email attachments or message bodies
    • Track your browsing behavior outside AliasFleet
    • Sell your personal information

    Payment Information

    For paid subscriptions (Pro and Business), we integrate with Stripe:

    • We do NOT store payment card details on our servers
    • We retain: Stripe Customer ID, Stripe Subscription ID, billing plan type, current period end
    • Invoice records (subscription amount, status, date)
    • Payment method last 4 digits and brand (for display purposes only)

    How We Use Your Information

    We use your information for:

    • Core Service: Forward emails from your aliases to verified destinations, or send/reply via Quick Send (Pro+) without exposing your real address
    • Authentication: Secure account access via password and two-factor authentication (2FA via TOTP and email OTP)
    • Security: Prevent fraud, detect suspicious activity, enforce rate limits, and block spam with custom filtering modes
    • PGP Encryption: Encrypt forwarded emails when you provide a public key (Pro+)
    • Notifications: Send account alerts, security warnings, webhook notifications, and billing updates
    • Support: Respond to support tickets and troubleshoot issues
    • Compliance: Meet legal obligations and respond to valid legal requests

    Data Sharing

    We do not sell your personal information. Limited sharing occurs with:

    Stripe (Payment Processing): Subscription billing and payment processing. Data is subject to Stripe's privacy policy.

    Cloudflare (DNS, Security, and DDoS Protection): Custom domain DNS management, routing, and security protection.

    Sentry (Error Monitoring): Application diagnostic data and error logs (no PII, no session replays, errors only).

    PostHog (Product Analytics): Pageview URLs, browser/device information, and identified user details (email and full name). No email content or password tracking, and no session replays.

    Legal Requirements: We may disclose information if required by law, court order, or to protect our rights and users' safety.

    Data Storage and Jurisdiction

    Your data is stored on dedicated servers leased from a third-party infrastructure provider located in France and Germany. This ensures that your personal data remains within the European Union (EU) jurisdiction and is protected in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.

    All data in transit is encrypted using TLS, and data at rest is encrypted on our servers.

    GDPR and CCPA Compliance (Your Rights)

    Under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws, AliasFleet acts as the Data Controller. You have the following rights regarding your personal data:

    • Access: View all data we have about you via your account settings
    • Correction (Rectification): Update or correct your profile information and settings at any time
    • Deletion (Erasure): Permanently delete your account and all associated aliases. Most data is removed within 24 hours of deletion
    • Portability: Export and download a complete copy of your data in JSON format to transfer to another service
    • Restriction and Objection: Object to or restrict the processing of your personal data under certain conditions

    To exercise any of these rights, or if you have questions regarding this policy, please contact our data protection team at legal@aliasfleet.com. We confirm that this contact address is actively monitored and will respond to valid requests promptly.

    Data Security

    We implement rigorous technical and organizational security measures to protect your data:

    Encryption:

    • Data encrypted in transit via TLS for all connections
    • Optional PGP encryption for forwarded emails (Pro+)

    Access Controls:

    • Cryptographic password hashing (bcrypt)
    • Two-factor authentication (2FA) via TOTP and email OTP
    • Strict authentication session management

    Infrastructure:

    • All data stored on our servers
    • Automated security updates, firewalls, and access control lists
    • DNS and DDoS protection via Cloudflare

    Monitoring:

    • Failed login attempt tracking (retained for 30 days)
    • Rate limiting to prevent abuse and brute-force attacks
    • Error monitoring via Sentry (errors only, no PII collected, no session replay)

    Data Retention

    We retain data only as long as necessary to provide our services and comply with legal obligations. Our data retention schedule (detailed in our Data Retention & Deletion Policy) is as follows:

    Data TypeRetention Period
    Active account dataUntil account deletion
    Email forwarding logsFree: 7 days, Pro: 30 days, Business: 90 days
    Failed login attempts30 days
    2FA recovery codesHashed, until regenerated
    Support tickets90 days after closure

    Note: Billing records and invoices are processed and handled by Stripe. We do not store payment card numbers, billing addresses, or complete transaction details on our servers.

    Third-Party Services

    To provide our service, we integrate with the following third-party processors:

    • Stripe: Payment processing for Pro and Business subscriptions. Stripe collects payment card details and billing information directly. Subject to Stripe's Privacy Policy.
    • Cloudflare: DNS and DDoS protection, ensuring the secure and fast routing of email and web traffic. Subject to Cloudflare's Privacy Policy.
    • Sentry: Application error monitoring. Technical error traces are collected to ensure reliability. No PII is collected, and no session replays are captured. Subject to Sentry's Privacy Policy.
    • PostHog: Product analytics to understand usage patterns. Only pageview URLs, browser/device information, and identified user details (email and full name) are tracked. No email content, passwords, or session replays are captured. Subject to PostHog's Privacy Policy.

    International Data Transfers

    Our primary servers are located in France and Germany (within the European Union). Because these servers are located in the European Union, your data is processed within the EU. For users residing outside the EU, your data will be transferred to and stored on these European servers. If any limited data processing occurs via our third-party processors (such as Stripe or Cloudflare), we ensure appropriate safeguards (such as Standard Contractual Clauses) are in place to protect your data.

    Policy Changes

    We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "lastUpdated" date in the metadata.

    Contact

    For privacy-related questions, data export/deletion requests, or to exercise your rights:

    Email: legal@aliasfleet.com
    Mailing Address: Available upon request

    Related

    Terms of ServiceAcceptable Use PolicyAnti-Spam PolicyCookie Policy

    Effective July 10, 2026. Contact support