Privacy Policy
Last updated 31 July 2026 · Data controller: Kazido, a sole proprietorship operating in New York, United States
Kazido exists to keep your real email address out of other people’s hands. A policy that then treated your data casually would be self-defeating. This describes exactly what we hold, for how long, and who can see it.
The short version.
We do not read your mail. We do not sell data or share it with advertisers, and we do not use your messages to train machine learning models. Our support staff can see that a message arrived, who it came from and what happened to it — never what it said. There is no screen anywhere in our systems that shows the body of your mail.
1. What we hold
Account information
- Your email address and a hashed password. Passwords are stored using PBKDF2-HMAC-SHA256 with 210,000 iterations and a per-account salt; we cannot recover the original.
- Your handle, which forms part of addresses on our shared domain.
- The forwarding address you nominate, and whether you have confirmed it.
- Any custom domains you connect, and the DNS records we generate for them.
- Your plan, and timestamps for account creation and last sign-in.
Mail metadata
For every message we handle we record the alias it arrived at, the sender’s domain and address, the subject line, the size, what we decided to do with it and why, and when. This is what makes the activity log and quarantine work.
Mail content
To relay a message we necessarily receive and process its full contents, including attachments. Delivered mail is not retained after relaying beyond the short-lived working copy described below. Mail we quarantine is stored so that you can read and release it.
Technical information
- IP addresses, used to rate-limit sign-in, signup and password reset. We do not build profiles from them.
- Server logs recording that a request or a message was handled.
- A session cookie. It holds only your account identifier, an expiry and a signature.
Payment information
Card details are handled entirely by Stripe and never reach our servers. We store only the identifiers Stripe gives us for your customer and subscription record.
2. How long we keep it
| Data | Kept for | Why |
|---|---|---|
| Raw message, while being processed | 7 days | A working copy so a failure can be retried rather than losing the message. |
| Quarantined mail | 30 days, then deleted (storage expires it at 60 days at the latest) | Long enough to notice something was held and release it. |
| Mail metadata and activity log | While your account is open | Shows you what happened to your mail and lets pinning work. |
| Server logs | 14 days | Diagnosing faults and abuse. |
| Account record | Until you close the account | Operating the service. |
| Billing records | 7 years | Tax and accounting obligations. |
When you close your account we stop accepting mail for your aliases and delete your account and mail data, except records we must keep for legal or accounting reasons.
3. What we use it for
- Running the service: receiving, filtering, relaying and storing mail as you have configured.
- Keeping accounts secure and preventing abuse, including rate limiting and investigating reports.
- Billing, where you subscribe.
- Service messages such as confirmation, password reset, and telling you when your forwarding address has stopped accepting mail.
- Meeting legal obligations.
Under the UK and EU GDPR our lawful bases are performance of a contract for operating the service and billing, legitimate interests for security and abuse prevention, and legal obligation where one applies. We do not rely on consent, and we do not send marketing email unless you separately ask us to.
4. What our staff can see
Support staff have a console that shows accounts and message metadata: the alias, the sender’s domain, the subject line, size, verdict, the reason for that verdict, and timestamps. It does not show message bodies, message previews, or the storage location of a message. That restriction is enforced in the software rather than by policy — the data is removed before it reaches the console — and every change a staff member makes to an account is recorded in an audit log.
A small number of engineers can reach production infrastructure in order to operate it. We do not access message content except where strictly necessary to investigate a specific fault or a report of serious abuse, or where legally compelled.
5. Who else is involved
We do not sell your data. We share it only with these processors:
| Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, databases, storage, and outbound mail delivery | United States (us-east-1) |
| Stripe | Payment processing and subscription management | United States, Ireland |
We may also disclose information where legally required, or where we reasonably believe it necessary to prevent serious harm. Where the law allows, we will tell you first.
Mail you send necessarily reaches its recipient and their mail provider. Kazido cannot control what they do with it.
6. International transfers
Our infrastructure is in the United States, and Kazido is operated from the United States. If you sign up from the UK, EEA or Switzerland, you are sending your data to a US service directly and on your own initiative.
Where we pass that data to the suppliers listed in section 5 — Amazon Web Services, which hosts the service, and Stripe, which handles payments — we rely on the Standard Contractual Clauses incorporated into their data processing agreements with us. Some of our suppliers additionally self-certify under the EU–US Data Privacy Framework; we do not rely on that certification on its own, because a certification can lapse and the contractual clauses do not. We do not use a supplier that offers neither.
7. Security
- Traffic to the dashboard and API is encrypted in transit. Our mail servers offer TLS to sending systems that support it.
- Stored mail and database volumes are encrypted at rest.
- Passwords are hashed, never stored or logged in a readable form.
- The database has no public endpoint and is reachable only from our own application.
- Browser-extension tokens are stored only as a hash and are limited to creating and listing aliases; they cannot change your password, alter domains or read quarantined mail.
No system is perfectly secure, and we do not claim otherwise.
8. Your rights
Depending on where you live you may have the right to:
- see what personal data we hold about you and get a copy;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to certain processing;
- withdraw consent, where we relied on it; and
- complain to a supervisory authority — in the UK the Information Commissioner’s Office, or your local authority in the EEA.
If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.
Email privacy@kazido.com to exercise any of these. We respond within 30 days.
9. Cookies and tracking
We set one cookie, to keep you signed in. There is no advertising, no analytics, and no third-party tracking on this site, which is why you are not being asked to accept anything. The marketing pages load no external fonts, scripts or images.
10. Children
Kazido is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
11. Changes
If we change this policy in a way that materially affects you, we will email you at least 30 days before it takes effect.
12. Contact
privacy@kazido.com ·
Kazido, a sole proprietorship operating in New York, United States
A postal address is provided on request to the address above, and to any supervisory
authority that asks for it.
EU and UK representative. Kazido is operated from the United States and is not directed at people in the EEA or the UK: the service is sold only in US dollars, only in English, and we do not advertise or market it in those regions. On that basis we have not appointed a representative under Article 27 of the GDPR or the UK GDPR. If that changes — if we price in euros or pounds, translate the service, or market it in those regions — we will appoint one and name them here before we do.
This does not affect what we will do for you. If you are in the EEA or the UK and want to see, correct or delete your data, write to privacy@kazido.com and we will handle it on the terms set out in section 8, wherever you live.