Plain-language summary

AliasCloak is designed so message and file content is end-to-end encrypted, except limited operational metadata such as timestamps. A conventional email address, phone number, or real-world ID is not required to create a generated mailbox. Payment information may be processed when a user purchases a custom alias.

Information used for mailbox delivery

AliasCloak may process mailbox identifiers, aliases, public keys, encrypted payloads, timestamps, technical delivery information, and other operational data required to provide the service. End-to-end encryption applies to message and file content as described by the service, not necessarily to every item of metadata.

Payment information

Core generated mailbox use is free. When a user purchases a custom alias, a third-party payment processor may receive payment and transaction information. Payment records can create a link between a purchase and a payer even when message content remains encrypted.

Message and file content

AliasCloak is designed so message and file content can be decrypted by the intended recipient using the appropriate private key. Encrypted content is designed to be automatically deleted from the delivery service after receipt.

User responsibilities

  • Protect private keys and devices used for decryption.
  • Avoid placing unnecessary identifying information in messages or filenames.
  • Store downloaded content only in approved locations.
  • Understand that recipients can copy content after decryption.
  • Review separate payment-processor terms when purchasing an alias.

Healthcare information

Do not use a privacy policy as a substitute for HIPAA contracting or security review. Organizations considering ePHI should separately assess Business Associate Agreement requirements, permitted use, risk management, record retention, incident response, and user access.

Policy completeness

This page is a plain-language product privacy summary. Before deployment, the site owner should ensure that the controlling AliasCloak privacy policy identifies the legal entity, contact method, subprocessors or categories of recipients, applicable rights, retention periods, jurisdiction, and effective date.

Important

Privacy statements must match the actual deployed service. Update this page whenever product architecture, payment processing, metadata, deletion, or legal terms change.