Privacy, clearly stated.
This policy describes how Alias Desk handles information at the public service hostname and its API.
What the service stores
Alias addresses and operational timestamps are stored when aliases are created. Synchronized messages may include sender and recipient headers, subject, snippets, message bodies, Gmail identifiers, and received times.
Access and isolation
The current public API does not provide user accounts or per-user ownership. Public endpoints can be reached by anyone who knows the service address, so aliases and stored messages should not be treated as confidential or private.
Synchronization and retention
A read-only Gmail worker polls the connected mailbox and stores matching messages in PostgreSQL. Data may remain until removed by the service operator. Delivery timing depends on Gmail availability and the worker’s polling interval.
Security measures
OAuth credentials and database configuration remain server-side. Message HTML is sanitized and rendered in a restricted browser frame. These measures do not replace access control or make public inboxes private.
Infrastructure
The service uses infrastructure providers required to operate the application, including Railway and PostgreSQL. We do not sell personal information.