Privily
Privacy policy

Privacy should be clear before you trust a service.

This policy explains what Privily handles when you create an account, use an email or phone identity, or choose exposure monitoring. Last updated 21 September 2026.

01

What this policy covers

Privily provides temporary email aliases, private phone identities, inbox tools, and optional online protection features. We collect and use information to operate those features, keep accounts secure, prevent abuse, and respond to required legal requests. We do not sell personal information or use the contents of your inbox to build advertising profiles.

02

Accounts and identity details

An account includes a username, account email, a password hash, account timestamps, and any verification information needed for sign-up. When you create an identity, we store the name and category you choose, its email address, any phone number, provider identifiers, and the optional credentials you enter for that identity. Use low-risk services with disposable identities; keep banking, healthcare, government, and account-recovery details on an address and number you control.

03

Email, phone, and inbox data

Email delivery and mailbox operations use specialist delivery providers. Messages are fetched so they can be displayed in your private dashboard and may include sender, recipient, subject, body, and provider message identifiers. Phone identities are provisioned through a telecom provider. Inbound SMS and messages sent from an identity can include phone numbers, message text, direction, timestamps, and provider identifiers so the conversation can be shown and abuse controls can work. Those providers may process and retain data under their own terms and technical logs.

04

Exposure and breach monitoring

Exposure monitoring is optional and requires your consent. Verified account or identity email addresses may be checked against an external exposure lookup service, and the app stores findings, dates, severity, status, recommendations, and scan history in your protection state. The breach catalog is cached to explain findings. Password checks use a partial hash prefix and are designed not to send the password itself. Do not add an identifier unless you are authorised to check it.

05

Retention and deletion

We keep account, identity, inbox-link, SMS, and protection records for as long as they are needed to provide the feature or maintain security and abuse records. Deleting an identity removes it from your active account records and releases an associated phone number when the telecom provider accepts the request. Email providers, telecom providers, backups, fraud-prevention records, and legally required records may have different retention periods, so deletion from the dashboard is not a promise of instant erasure from every external system.

06

Sharing and service providers

We share only what is needed with infrastructure and delivery providers, exposure lookup services when you enable monitoring, payment providers for phone subscriptions, and authorities when disclosure is legally required or needed to protect people and the service. We do not sell inbox contents, identity details, or monitoring findings.

07

Security, choices, and changes

Passwords are stored as hashes and access to account features requires an authenticated session, but no online service can guarantee absolute security. You can stop exposure monitoring, remove monitored identifiers, delete identities, and choose not to use phone or monitoring features. We may update this policy when the service changes; the date above identifies the current version. Questions about privacy should be raised through the Privily support channels.