Privacy policy for Maski
Maski by Jay Thorat
Maski privacy policy - browser extension
The full policy for the Maski service is at https://maski.dev/privacy. This is the part that applies to the extension.
What the extension stores on your device
An API key and your account email address, in extension local storage, so you connect once instead of on every use. Never in synced storage, so neither value is replicated to your other devices. Nothing else is stored.
What the extension sends to us
It contacts https://api.maski.dev and no other origin. There is no analytics, no telemetry, no error reporting, and no third-party request of any kind. Every font and icon ships inside the package, so no asset is fetched from a CDN.
It sends:
- your Maski API key, on authenticated requests;
- the alias name and domain you are registering;
- the hostname of the page you are on, at the moment you create an alias, which we store as that alias's label.
The label is private. Only you see it, and it never appears in mail you send or receive. It is what lets the extension show you which address you already use on a site, and tell you which signup a forwarded message came from. If you would rather an alias carried no site label, create it in the Maski dashboard, where the label field is yours to fill in or leave empty.
What the extension never sends
Your real email address. We resolve the forwarding destination from your account on the server, so the extension does not transmit an address you already hold.
Page content, form values, browsing history, or anything you type. The extension reads form-field attributes (name, type, placeholder, label text) on the page you are on to work out where an email address goes. That happens entirely inside your browser, is not stored, and is not sent anywhere.
Data collection declared at install
browsingActivity, for the hostname described above, and authenticationInfo, for the API key. Both are declared in the add-on's manifest and shown to you when you install it.
Retention and deletion
Aliases and their labels live in your Maski account and are deleted when you delete the alias or your account. Removing the extension deletes the API key and account email it stored on that device. Revoke the key itself in Maski under Account, Security, API keys.
Contact
Jay Thorat
hey@maski.dev