AliasCloak is designed so message and file content is end-to-end encrypted, except limited operational metadata such as timestamps. A conventional email address, phone number, or real-world ID is not required to create a generated mailbox. Payment information may be processed when a user purchases a custom alias.
Information used for mailbox and chat delivery
AliasCloak may process mailbox identifiers, aliases, public keys, encrypted payloads, timestamps, technical delivery information, and other operational data required to provide the service. End-to-end encryption applies to message and file content as described by the service, not necessarily to every item of metadata.
Payment information
Core AliasCloak mail, chat, and file-transfer use is free. When a user purchases a custom alias, a third-party payment processor may receive payment and transaction information. Payment records can create a link between a purchase and a payer even when message content remains encrypted.
Message, chat, and file content
AliasCloak is designed so mailbox messages, chat messages, and file content can be decrypted only with participant private keys. One-shot text is removed after successful recipient acknowledgement; encrypted attachment blobs and chat envelopes can remain for limited retention windows so downloads and offline catch-up continue to work. Decrypted history stored in the browser remains under the user’s control.
User responsibilities
- Protect private keys and devices used for decryption.
- Avoid placing unnecessary identifying information in messages or filenames.
- Store downloaded content only in approved locations.
- Understand that recipients can copy content after decryption.
- Review separate payment-processor terms when purchasing an alias.
Healthcare information
Do not use a privacy policy as a substitute for HIPAA contracting or security review. Organizations considering ePHI should separately assess Business Associate Agreement requirements, permitted use, risk management, record retention, incident response, and user access.
Policy completeness
This page is a plain-language product privacy summary. Before deployment, the site owner should ensure that the controlling AliasCloak privacy policy identifies the legal entity, contact method, subprocessors or categories of recipients, applicable rights, retention periods, jurisdiction, and effective date.
Privacy statements must match the actual deployed service. Update this page whenever product architecture, payment processing, metadata, deletion, or legal terms change.