Privacy
Privacy policy
The short version: there is no account with us, no server of ours between your device and Fastmail, and nothing about your masked addresses is sent anywhere else.
What the app stores on your device
- Your Fastmail API token. Held in the app's own storage and sent only to Fastmail's API to authenticate your requests.
- Your masked email list. Cached so the list is there before the network answers. It is a copy of what Fastmail already holds.
- Your settings. The address prefix, and how many addresses you have created against the free tier limit.
Deleting the app removes all of it. Your masked addresses live in your Fastmail account and are unaffected.
What the app sends, and where
Fastmail
Every masked email operation goes from your device straight to Fastmail's API. The requests carry your token and the details of the operation: creating an address, listing them, enabling or disabling one. This traffic is between you and Fastmail, and it is not relayed through anything of ours.
Crash and error reporting
App Store and TestFlight builds send crash and error reports to Sentry. A report contains what went wrong: the error, where in the code it happened, the app version, the device model and OS version, and a structural snapshot of the screen at the time. Your API token, your Fastmail identity and your masked addresses are not part of it. Reports are used to fix bugs and nothing else.
Purchases
The Full Version is an Apple in-app purchase. Apple handles the payment; this app never sees your payment details. Purchase state is checked through RevenueCat, which receives an anonymous identifier and the receipt so the app knows whether the purchase is active.
The website
maskedmail.app is static pages hosted on Cloudflare Workers, which records
standard request logs. The site uses PostHog
to count visits and see which pages people arrive on. It records page views and
clicks on the page, including which links off the site were followed and the
text of those links, along with the usual analytics data: referrer, browser,
approximate location, and a cookie to recognise a repeat visit. Visitors are not linked to a person
profile, because the site has nothing to sign in to. Analytics requests go
through px.digitalvibes.dev, a proxy on the author's own domain,
rather than to PostHog directly.
Browser or extension settings that block analytics work here, and nothing on the site stops working when they do. The website has no account, no login and no contact form.
What the app never collects
- The contents of your mail, which a Masked Email token cannot read
- Your Fastmail password
- Your masked addresses, on any server of ours
- Contacts, precise location or advertising identifiers
Your controls
- Revoke access. Delete the API token in Fastmail's settings and the app loses access immediately.
- Delete the local data. Delete the app.
- Manage the purchase. In-app purchases are managed in your Apple Account settings.
Children
The app is not directed at children, and it requires a Fastmail account to be of any use.
Changes
If this policy changes in a way that affects what is collected, the updated version will be published here before the change ships.
Contact
Questions about any of this go to appfeedback@davidmohl.com, or to contact@davidmohl.com for anything about this policy itself.