Last updated

Common privacy questions

Does Emcognito read or store the emails forwarded through my aliases?

No — we don't read, scan, or analyze message contents. A forwarded message sits on our forwarder only until AWS SES accepts it, then it's deleted. One exception: if your account is over its monthly forward cap, the message is held undelivered for up to 72 hours so it can still reach you if you upgrade in that window, and it is deleted once the window passes. The hold is a best-effort second chance rather than a guarantee: the holding area is bounded in size, so when it is full further over-cap messages are refused and permanently lost, and we make no claim that held mail is encrypted at rest.

Do you sell or share my email address with third parties?

No. We use your account email for forwarding, sign-in, account and lifecycle notices, support, and paid-plan administration through Stripe. We never sell it, rent it, or share it with marketers or data brokers.

What information does Emcognito actually collect?

Your account email (used as the destination for forwarded mail and for passwordless sign-in), the aliases you create, and basic usage metrics like forward counts so we can enforce plan limits and keep the service running. Two of those metrics are about mail we could not deliver. The first is always on for everyone: when a message is blocked because you are over your monthly forward cap, we add 1 to a running count on your account, so we can tell you how many you missed. It is only a number — no sender, no subject, no alias, no time — and it resets when your cap does. The second is optional and off by default: if you switch on "Keep a record of what I miss" in Billing Settings, we also store the sender address and subject line — never the message itself — of that mail, so you can see what you missed. That record is deleted automatically 30 days after each entry, and you can switch it off at any time, which deletes what has been recorded.

Can I delete my account and all my data?

Yes. You can suspend or delete individual aliases at any time. To wipe your full account, email support and we will delete your account record and all associated aliases.

Where is Emcognito based and which privacy laws apply?

Emcognito is operated from Pennsylvania, United States. We apply GDPR-style data-minimization principles globally and respect data subject rights regardless of where you sign up from.

The full legal policy follows below. For product context, read the email privacy best practices guide, compare disposable email vs email aliases, or create a free private alias.

Privacy Policy

Last updated: July 26, 2026

This policy describes what Emcognito collects, why we collect it, who we share it with, and the choices you have. The plain-English questions above are part of this policy; the sections below are the formal version. Where the two ever disagree, the plain-English answer is the controlling one and you should email hello@wm.emcognito.com so we can fix the formal text.

Who we are

Emcognito is operated by VectraSEO LLC, a Pennsylvania limited liability company and a small independent team. When this policy says "we," "us," or "Emcognito," it means that operator. When it says "you," it means the person using the service at emcognito.com. For any privacy matter you can reach us at hello@wm.emcognito.com.

What we collect, and why

Information you give us

  • Your account email address. Used as the destination for forwarded mail, passwordless sign-in, account and service notices, lifecycle messages, support, and, for paid accounts, the Stripe customer relationship. This is the one piece of personal data the service cannot function without.
  • The aliases you create. Each alias is a unique address on a domain we operate (for example, abc123@emcognito.com). You may optionally attach a label, source, note, or category to an alias; if you do, we store that text so the dashboard can show it back to you.
  • Optional support messages and feedback. If you email us or use the feedback form, we keep the message so we can reply.
  • Custom-domain research waitlist responses. If you submit the research waitlist form in Billing Settings, we store your configuration choices (domain status, count, use case, timeline, catch-all/migration needs, and optional notification email opt-in) linked to your account. No domain name is ever requested or stored. You can edit your choices or withdraw/delete your response at any time using "Leave research waitlist" in Billing Settings, which immediately deletes the entry from our database.
  • Billing details (paid plans only). If you subscribe to a paid plan, Stripe — not Emcognito — collects and holds your payment card. We store a customer identifier and the subscription state Stripe sends us, never your card.

Information we collect automatically

  • Forward counts and timestamps. For every forwarded message we increment a counter on the destination alias and on your account so we can enforce monthly plan limits, surface aliases that are getting unusual volume, and detect a destination inbox that's bouncing. We do not retain the message body after delivery, apart from the bounded over-cap hold described under "How long we keep things" below.
  • A count of messages you missed. When a message cannot be forwarded because your account is over its monthly cap, we add 1 to a running total on your account. This happens whether or not you have switched on the optional missed-mail record described below — it is on for everyone, and it is how we can tell you "you missed 12 messages this month" without keeping anything about them. It is only a number: no sender, no subject, no alias, no time. It resets when your monthly cap resets. If the detailed record fills up for the month we keep a second number for the remainder, on the same terms. We are calling this out separately from the optional record because "off by default" applies to that record and not to this count.
  • Standard request logs. AWS records request metadata for the website and API, and DigitalOcean records operational metadata for the mail forwarder. Depending on the service, this can include IP address, user agent, timestamp, route, and HTTP or SMTP status. We use these records for delivery, security, reliability, and abuse prevention; retention follows the configured provider and service settings rather than a single promised period.
  • Consent-based analytics. Google Analytics 4 (GA4) is not loaded until you explicitly accept analytics. If accepted, it records page views and product interaction events across public and signed-in pages. We do not use GA4 for advertising. You can decline initially or withdraw consent at any time through "Analytics preferences" in the footer; withdrawal blocks future events and removes accessible GA cookies where possible.
  • Service and lifecycle email events. Account, onboarding, quota, and other lifecycle messages may record delivery outcomes and use signed links or a small image request to record clicks or opens. Open data can be affected by mail-client privacy proxies and is treated as an approximate engagement signal. These operational lifecycle events are separate from optional GA4 browser analytics.

What we don't do

  • We do not read, scan, profile, or analyze the contents of the email messages forwarded through your aliases. They pass through our forwarder host (Postfix → AWS SES) and are deleted from disk as soon as SES accepts them for delivery. The one exception is a message that arrives while your account is over its monthly forward cap: that message waits, undelivered and unread, in a holding area on the same forwarder host for up to 72 hours, so it can still be delivered if you upgrade within that window. See "How long we keep things" below.
  • We do not sell, rent, or trade your information to third parties.
  • We do not share your data with marketers, data brokers, or advertising networks.
  • We do not build behavioral profiles of you across sites.
  • We do not use third-party advertising trackers or ad pixels on this site.

How we use what we collect

Specifically and exhaustively:

  • To run the service: route forwarded mail, enforce plan quotas, issue magic-link sign-ins, suspend aliases that are getting bounced by a dead destination inbox.
  • To bill you (paid plans only): create a Stripe customer, process subscriptions, deliver receipts.
  • To keep the service safe: rate-limit abusive traffic, detect credential stuffing or magic-link enumeration attempts.
  • To support you: reply to your emails, investigate issues you report.
  • To improve the service: GA4 analytics tell us which pages people read, which CTAs they click, and which product actions they take in the dashboard, so we can fix confusing flows and prioritize features. We configure GA4 not to identify you by name and do not merge GA events into your account record.
  • To comply with legal obligations: respond to lawful requests from authorities with jurisdiction over us; preserve records we're required by law to preserve. Now that some undelivered mail sits with us briefly, it is worth being precise about that mail specifically: US law treats a message awaiting delivery as being in electronic storage, and we will not disclose the contents of a held message to a government authority on a subpoena alone. For content we require a warrant, and we will decline or challenge requests that do not meet that bar. We will of course comply with a valid warrant.

Our legal bases (for EEA/UK users)

If GDPR or UK GDPR applies to you, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — to create your account, forward your mail, sign you in by magic link, and bill paid plans.
  • Legitimate interests (Art. 6(1)(f)) — to keep the service secure, prevent abuse, enforce plan limits, and understand product usage through analytics, balanced against your privacy rights.
  • Legal obligation (Art. 6(1)(c)) — to keep tax and accounting records and to respond to lawful requests.
  • Consent (Art. 6(1)(a)) — where we ever ask for it explicitly; you can withdraw consent at any time without affecting prior processing.

Mail written by other people

A message forwarded through one of your aliases was written by somebody else. That sender is not an Emcognito user, has not agreed to our Terms, and usually does not know Emcognito is in the path at all. Their message is still personal data that we handle, and since we now hold some of it briefly rather than passing it straight through, we would rather set out exactly what that means than leave it to inference.

  • What we do with it. We accept the message, hand it to AWS SES for delivery to your real inbox, and delete it. If your account is over its monthly forward cap, we instead hold it undelivered for up to 72 hours so it can still reach you, as described under "How long we keep things." If — and only if — you have switched on the optional missed-mail record described in the next bullet, we additionally note the sender's address and the subject line of a message we could not deliver because you were over your cap. Apart from those two cases, that is the entire list. We do not read it, scan it, index it, profile from it, train anything on it, use it for analytics, or keep it for any purpose other than delivering it to you.
  • The optional missed-mail record. If you switch on "Keep a record of what I miss", then for mail that arrives while you are over your monthly forward cap we keep the sender's address, the subject line, the alias addressed, and the arrival time for 30 days, so you can see what you missed. This is the one place where something a sender wrote is retained in a readable form after the message itself is gone, and the sender has no say in it — so we keep it to the minimum that answers the question "what did I miss", never store the body, delete each entry automatically after 30 days, delete the whole record if you switch the setting off, and leave it off unless you deliberately turn it on. The Art. 14 notice below covers this data too.
  • Our legal basis for the sender's data (EEA/UK). Legitimate interests (Art. 6(1)(f)): the recipient's interest in receiving mail addressed to them, and the sender's own interest in having the message they sent actually arrive. We do not rely on your contract with us (Art. 6(1)(b)) as the basis for handling a third party's personal data, because the sender is not a party to that contract.
  • Why the window is 72 hours. It is the shortest period that still gives an account holder a realistic chance to see the cap notice and act on it before the mail is lost — roughly a long weekend. It is a ceiling, not a target: held mail is released the moment your account has capacity again, and nothing is kept after the 72 hours for any purpose.
  • Our role, and why the limits above are the point. European guidance takes the view that where a provider's only role is to enable the transmission of a message, the provider is not the controller of the personal data inside that message — the person who wrote it is. We keep to that role deliberately. The list above is not modesty about what we happen not to do; it is the boundary that keeps us a carrier of your mail rather than a reader of it, and we would have to tell you here if that changed.
  • Notice to senders (GDPR Art. 14). For the routing data we do control — which alias was addressed, when, the sending address, and, where the recipient has switched on the optional missed-mail record, the subject line — we have no relationship with senders and no practical way to notify each one individually. Writing to them would mean sending unsolicited mail to people who never contacted us, and would reveal that their message passed through an alias, undoing the privacy the service exists to provide. We publish this policy as that notice. If you are a sender and you want to know whether we are holding a message of yours, or want it deleted, email hello@wm.emcognito.com and we will act on it.

Subprocessors — the third parties we use to run Emcognito

We use a small number of named third parties ("subprocessors") to run the service. Each has access only to the categories of data it needs to do its job. We list them so the policy you read matches what you'd find with a network inspector.

  • Amazon Web Services (AWS). Hosts the web app and static assets (S3 and CloudFront), API compute, account and alias data (DynamoDB), and outbound delivery (SES). AWS processes account and alias records, API request metadata, and forwarded messages handed to SES for delivery.
  • DigitalOcean. Hosts the Postfix mail forwarder. It processes incoming message bodies and routing metadata while messages are delivered or, when the cap hold applies, temporarily held.
  • Stripe, Inc., United States. Payment processing for paid plans. Stripe sees billing email, card details (which they hold, we never see), and subscription state. Stripe's privacy policy: stripe.com/privacy.
  • Google LLC (Google Analytics 4). Processes browser analytics only after explicit consent. GA4 receives event and network metadata, but not forwarded message contents. Google's privacy policy: policies.google.com/privacy.
  • DNSCove. Provides authoritative DNS for emcognito.com. DNS resolvers may send DNS request metadata; DNSCove does not receive Emcognito account records through the product.

Provider processing locations depend on each provider's infrastructure and policies. We do not use AI-model providers (OpenAI, Anthropic, etc.) on user data. If we add or change a material subprocessor, we will update this list and the date at the top.

International data transfers

Emcognito is operated by a US company and uses providers whose processing locations vary by service and provider policy. If you use the service from a country with data-transfer rules, your information may be transferred internationally. You can ask about the safeguards relevant to your account at hello@wm.emcognito.com.

How long we keep things

  • Forwarded email bodies (delivered normally): not retained. Stored on disk only between Postfix receipt and SES handoff (seconds), then deleted. The one exception is the over-cap hold described in the next bullet.
  • Forwarded email bodies held at your monthly cap: up to 72 hours. If a message arrives when your account is over its monthly forward cap, we do not delete it and we do not deliver it — it waits in a holding area on our forwarder host. It is delivered as soon as your account has capacity again (because you upgraded, or because your monthly cap reset), and it is deleted once it has been waiting 72 hours, whichever comes first. We do not read it while it waits. Two limits you should assume rather than hope against: the holding area is bounded in size and in message count, so when it is full, further over-cap messages are refused at the door and are permanently lost — we cannot recover them and we do not notify the sender or you which messages were lost; and a message held for the full 72 hours without your account regaining capacity is deleted undelivered. The hold is a best-effort second chance to receive mail you were otherwise over your limit to receive. It is not a mailbox, not a backup, and not a delivery guarantee.
  • Account row (your account email and plan state): retained while your account is active and removed when an account-deletion request is processed, except records we must retain for security, billing, or legal obligations.
  • Alias rows (your aliases and their labels): retained while your account is active or until you delete each alias.
  • Missed-mail record (optional, off by default): 30 days. If you switch on "Keep a record of what I miss" in Billing Settings, then for each message that arrives while your account is over its monthly forward cap we store the sender's address, the subject line, which alias it was addressed to, and the time it arrived. We do not store the message body — there is no field for one. Each entry is deleted automatically 30 days after it is recorded. You can switch the record off at any time, which deletes everything already recorded. Nothing is recorded in this record while the setting is off, and it is off unless you turn it on — but the plain count of how many messages you missed, described under "Information we collect automatically" above, is kept for everyone either way. Note that this record necessarily contains information about the people who wrote to you, not only about you; we do not use it for anything other than showing you what you missed.
  • Missed-message count (always on): until your monthly cap resets. A single number per account, with no sender, subject, alias, or timestamp attached to it. There is nothing to delete individually and nothing to switch off; deleting your account removes it with the rest of the account record.
  • Custom-domain research waitlist response: retained while your account is active or until you edit or delete it using "Leave research waitlist" in Billing Settings or delete your account.
  • Magic-link tokens: 15-minute TTL; deleted automatically once consumed or expired.
  • Standard request logs: retained according to the relevant AWS, DigitalOcean, and application configuration; we do not promise one universal retention period.
  • Stripe billing records: retained by Stripe under its policy and by us where needed for subscription administration, accounting, disputes, and applicable legal obligations.
  • Support emails: retained for up to 2 years after the last reply, then deleted.

Your rights

Wherever you sign up from, we apply the following:

  • Right to access: email hello@wm.emcognito.com and we'll send you a copy of what we have on you.
  • Right to deletion: from inside the app you can delete individual aliases at any time. To wipe your entire account record and every associated alias, email support and we'll do it. We will confirm completion within 30 days. Deleting your account also destroys any mail then sitting in the over-cap hold — it is discarded undelivered, not forwarded on.
  • Right to correct: you can edit alias labels and notes inside the app at any time. Email support to correct anything you can't change yourself.
  • Right to portability: email support and we'll export your aliases as JSON or CSV.
  • Analytics choice: GA4 does not load before you explicitly accept it. Use "Analytics preferences" in the footer to accept, decline, or withdraw that choice. A tracker blocker can provide an additional control.
  • Right to object / restrict (EEA/UK): where we process data on the basis of legitimate interests, you may object to that processing or ask us to restrict it; email support and we'll review the request.
  • Right to lodge a complaint: EU/EEA residents may complain to their national data-protection authority and UK residents to the ICO. California residents have the rights described under the CCPA/CPRA — including the right to know, the right to delete, the right to correct, and the right to non-discrimination for exercising those rights. We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA — so there is nothing to opt out of on that front.

We don't charge for fulfilling rights requests and we don't ask for legal-style documentation — your account email is enough.

How we protect your data

  • In transit: HTTPS (TLS) for the website and API. Forwarded mail uses SMTP over TLS to AWS SES.
  • At rest: account and alias records are encrypted at rest in DynamoDB. Mail held at your monthly cap is different, and we would rather say so plainly than let the line above imply otherwise: it sits as a file on our forwarder host, protected by host hardening and access control rather than by any encryption we apply. We do not claim held mail is encrypted at rest. Whatever encryption exists at that layer is whatever our hosting provider applies to its own volumes, and we have not independently verified it. If that matters to your threat model, treat the hold as unencrypted storage.
  • Access: only the operator can read the production database. We do not use third-party customer-data tools (no Segment, no CRM, no support desk with full-account visibility).
  • Sign-in: magic links are single-use, expire after 15 minutes, and are consumed when verified. You may also register passkeys. Emcognito stores public passkey credential data, never the private key, PIN, or biometric; a platform provider may sync a passkey across your devices. Sessions are signed JWTs with a 7-day TTL.

No service can promise zero breaches. If we discover a personal-data breach that affects you, we will notify you by email without undue delay — and within any timeframe required by applicable law — describing what happened, what data was involved, and what you should do. Where a breach reaches the over-cap holding area it may also involve messages written by people who are not our users and whom we have no way to contact; in that case we will describe the exposure in our notice to you and to the relevant supervisory authority, and we will say so publicly on this page.

Cookies

We use necessary local-storage entries to keep you signed in (the emcognito_session entry contains your session JWT) and to remember preferences. Google Analytics is deferred until explicit consent and may then set analytics cookies across public and signed-in pages. Declining or withdrawing consent prevents future GA events and removes accessible GA cookies where possible. We do not set advertising cookies or use browser fingerprinting.

Children

Emcognito is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we've collected data from a child, email support and we'll delete it.

Changes to this policy

When we change this policy we update the "Last updated" date at the top. For material changes (new subprocessors, new categories of collection, new uses of data) we will also email registered users at least 30 days before the change takes effect.

Contact

Privacy questions, deletion requests, complaints, or anything else: hello@wm.emcognito.com.