/* Not legal advice. This page is research, not compliance guidance. */ /* */
Email-Alias Service Comparison: Identity, Retention, Replying, and Limits
Status: 6 email-alias services compared on a fixed, neutrally ordered schema (alphabetical by operating entity). No score, ranking, or recommendation is rendered. Not legal advice.
Short answer
This page compares email-alias services only through the frozen tool-cell schema: masking boundary, who else receives identifying information, signup and later verification, retention, platform and forwarding constraints, lawful-request transparency, alias limits, reply and send support, and custom-domain support. A cell with no primary-source answer renders as an explicit typed unknown, never as a silent blank or an inferred zero.
What the email-alias service masks
No reviewed cell in this sample states the recipient-facing masking boundary as its own claim, independent of alias-limit or forwarding fields (see masked_identifier in the comparison matrix below) — this is recorded as a typed unknown for every vendor rather than inferred from adjacent alias-creation or forwarding cells. It does not imply the underlying identity is erased for any vendor.
Who still receives identity information
Operating entity, entity jurisdiction, and payment-method fields are compared per vendor in the matrix below. A payment counterparty is rendered only where a cell states one; most free-tier alias services in this sample do not disclose a payment-collection flow (paid tiers do, where captured — see Firefox Relay). Nothing here implies anonymity from any counterparty not named in a cell.
Signup identifiers and later verification triggers
Signup identifiers and later verification triggers are compared per vendor below. A signup identifier is never merged with a later verification event — they are separate columns, separately sourced.
| Vendor | Masked identifier | Operating entity | Entity jurisdiction | Signup identifiers | Identity verification triggers | Payment methods | Data retained | Retention period | Account deletion | Platforms | Forwarding constraints | Lawful-request process | Request counts published | Creation limit | Active-alias limit | Reply from alias | Send from alias | Custom domain |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| addy.io | Not disclosed in the captured primary sources. | Not disclosed in the captured primary sources. | hosting jurisdiction: Netherlands; governing law: England and Wales (source, as of ) | Exact required signup identifiers are not disclosed in the captured public documents. (source, as of ) | No later identity-verification trigger is disclosed in the captured public documents. (source, as of ) | Not disclosed in the captured primary sources. | Email content is stored only for enabled failed-delivery handling; log files are retained for 3 days. (source, as of ) | Email content is stored only for enabled failed-delivery handling; log files are retained for 3 days. (source, as of ) | Account deletion is initiated in Settings and is permanent, with anti-reuse exceptions for shared aliases and usernames. (source, as of ) | web-browser-extension-mobile-api (source, as of ) | recipient_limits: Free: 1; Lite: 5; Pro: 30; per_alias_verified_recipient_maximum: 10; same_custom_and_recipient_domain_allowed: No (source, as of ) | No lawful-request count report was located; no zero is inferred. (source, as of ) | Not disclosed in the captured primary sources. | Free: 10/hour; Lite: 20/hour; Pro: 50/hour (source, as of ) | standard_aliases: unlimited on all plans within other limits; active_shared_domain_aliases: Free: 10; Lite: 50; Pro: unlimited (source, as of ) | Free: not included; Lite: 50/day; Pro: 200/day; recipient_view: alias shown; verified recipient address not shown (source, as of ) | Free: not included; Lite: 50/day; Pro: 200/day; recipient_view: alias shown; verified recipient address not shown (source, as of ) | Free: 0; Lite: 1; Pro: 20 (source, as of ) |
| Apple Hide My Email | Not disclosed in the captured primary sources. | Apple Inc. for United States users including Puerto Rico; other Apple entities by region (source, as of ) | incorporation jurisdiction: not stated in cited clause; hosting jurisdiction: Apple says worldwide-collected personal data is generally stored by Apple Inc. in the United States; governing law: California by default, with enumerated regional exceptions (source, as of ) | Apple Account sign-in is required; two-factor authentication is required to create an address on iCloud.com. (source, as of ) | Apple says account sign-in and identity verification occur when privacy rights are exercised. (source, as of ) | Not disclosed in the captured primary sources. | Relayed message content is deleted after delivery, usually within seconds; alias-metadata retention is not disclosed here. (source, as of ) | Relayed message content is deleted after delivery, usually within seconds; alias-metadata retention is not disclosed here. (source, as of ) | An inactive alias can be permanently deleted; Apple says it is deleted on all configured devices and cannot be reactivated. (source, as of ) | web-ios-ipados-macos (source, as of ) | iCloud Mail or another email address associated with the Apple Account (source, as of ) | Apple reports government requests at account/email-address scope; no Hide My Email-specific count is disclosed. (source, as of ) | period: periodized transparency reporting; no Hide My Email-specific period disclosed; jurisdiction: global and country/region filters; unit: Apple Account or email-address based account requests, not Hide My Email product unit (source, as of ) | as many as needed, subject to Apple's reserved right in the iCloud terms to limit availability (source, as of ) | no fixed number disclosed (source, as of ) | yes; replies appear from the alias (source, as of ) | Not disclosed in the captured primary sources. | Not disclosed in the captured primary sources. |
| Cloaked | Not disclosed in the captured primary sources. | Cloaked, Inc. for U.S. users; Cloaked International, Inc. for users outside the U.S.; Cloaked Pay, LLC named for Cloaked Card products/services. (source, as of ) | governing law: U.S. and Commonwealth of Massachusetts law; contracts entered into and performed in Massachusetts (source, as of ) | Not disclosed in the captured primary sources. | Not disclosed in the captured primary sources. | Not disclosed in the captured primary sources. | Account/service duration, plus legal or regulatory exceptions. (source, as of ) | Account/service duration, plus legal or regulatory exceptions. (source, as of ) | 30-day scheduled deletion or immediate permanent deletion. (source, as of ) | all (source, as of ) | Not disclosed in the captured primary sources. | Legal-process policy stated; request counts not disclosed. (source, as of ) | Not disclosed in the captured primary sources. | Not disclosed in the captured primary sources. | One Cloaked email address per identity; total number of identities not disclosed here. (source, as of ) | Yes (source, as of ) | Not disclosed in the captured primary sources. | Not disclosed in the captured primary sources. |
| DuckDuckGo Email Protection | Not disclosed in the captured primary sources. | Duck Duck Go, Inc. (source, as of ) | hosting jurisdiction: corporate systems use data centers across the world and may transfer data among them; governing law: New York law; claims associated with the services or terms must be filed in state or federal courts in New York, New York, USA (source, as of ) | Signup requires a valid forwarding email address for an account the user controls; the service is restricted to people age 13 or older. (source, as of ) | No post-signup trigger for additional identity evidence is disclosed in the captured Email Protection terms or help pages. (source, as of ) | Not disclosed in the captured primary sources. | Ordinary forwarded messages are processed in memory and not saved; breakage submissions are removed after 30 days, flagged-spam metadata within 90 days, and deletion backups after 30 days unless law requires longer. (source, as of ) | Ordinary forwarded messages are processed in memory and not saved; breakage submissions are removed after 30 days, flagged-spam metadata within 90 days, and deletion backups after 30 days unless law requires longer. (source, as of ) | Account deletion may be initiated through the deletion page or support; complete removal follows a 30-day backup period unless law requires longer, and deleted Duck Addresses cannot be reused. (source, as of ) | web-browser-extension-mobile (source, as of ) | must be a valid email account the user controls; each additional Email Protection account needs a different unique forwarding address; forwarding address can be changed in Account settings (source, as of ) | DuckDuckGo states its legal-disclosure process, but no Email Protection-specific lawful-request counts are disclosed in the captured primary pages. (source, as of ) | unit: Email Protection (source, as of ) | effectively unlimited private Duck Addresses, subject to an undisclosed daily anti-abuse limit (source, as of ) | no overall fixed active-private-address limit disclosed; one Duck Address account can be enabled for autofill/generation in a browser at a time (source, as of ) | yes for most Duck Addresses; routed through duck.com; unsupported when the forwarding address uses a unique domain without an SPF record (source, as of ) | Not disclosed in the captured primary sources. | Not disclosed in the captured primary sources. |
| Firefox Relay | Not disclosed in the captured primary sources. | Mozilla Corporation (source, as of ) | hosting jurisdiction: Mozilla Corporation and its servers are based in the United States; Firefox Relay uses Amazon Web Services to receive and forward masked email; governing law: California law, excluding California conflict-of-law rules (source, as of ) | Firefox Relay requires a Mozilla account with a verified email address; paid subscriptions additionally send payment details to a listed payment provider, with a limited billing record returned to Mozilla. (source, as of ) | Mozilla may request additional information to confirm identity before processing a privacy-rights request; the specific evidence is not enumerated. (source, as of ) | identifier_type: payment method and billing address; requiredness: required only for a paid subscription; full payment details go to Stripe, Apple, PayPal, or Google Pay, while Mozilla receives billing address, last four digits, and subscription status; collecting_actor: third-party payment provider; limited record received by Mozilla Corporation; plan: paid subscription; region: vendor-documented; platform: web or app-store purchase (source, as of ) | Relay does not retain ordinary email content beyond delivery; undeliverable mail is capped at three days, while Mozilla account and interaction data follow separately stated account-retention periods. (source, as of ) | Relay does not retain ordinary email content beyond delivery; undeliverable mail is capped at three days, while Mozilla account and interaction data follow separately stated account-retention periods. (source, as of ) | Mozilla provides a privacy-request portal and recognizes deletion rights, but the captured primary pages do not state a Firefox Relay-specific completed-erasure timeframe. (source, as of ) | web-browser-extension-mobile (source, as of ) | masks forward to the primary/true email associated with the Mozilla account; messages over 10 MB are not forwarded (source, as of ) | Mozilla publishes transparency reporting, but the captured pages do not disclose Firefox Relay-specific lawful-request counts. (source, as of ) | period: Mozilla moved to annual reporting in 2025; fetched 2025 page says the DSA report was published February 27, 2026 and the standard global report was still described as forthcoming; jurisdiction: Mozilla aggregate; 2025 DSA law-enforcement figures limited to the EU; unit: Mozilla, not Firefox Relay (source, as of ) | conflicting current vendor statements for the free plan: product page and FAQ describe 5 total masks, while effective-2026-09-16 terms say up to 50; paid subscriptions are consistently described as unlimited (source, as of ) | same unresolved free-plan conflict; no separate deactivation ceiling disclosed (source, as of ) | Relay Premium users may reply within three months of receipt; adding CC or BCC exposes the original address (source, as of ) | Not disclosed in the captured primary sources. | paid subscription offers a custom subdomain under mozmail.com; own-domain support is not disclosed (source, as of ) |
| SimpleLogin | Not disclosed in the captured primary sources. | Proton AG (source, as of ) | incorporation jurisdiction: Switzerland (vendor-stated registration); hosting jurisdiction: Germany; Switzerland; Netherlands; France (source, as of ) | The current privacy policy says email is required and name is optional; the current terms say full name, email, and login credentials are collected at registration. (source, as of ) | No post-signup trigger that requests additional identity evidence is disclosed in the captured vendor-primary documents. (source, as of ) | Not disclosed in the captured primary sources. | Undeliverable email and routine IP-bearing logs: 7 days; deletion backups: up to 14 days; deletion system-log purge: up to 30 days; terms-breach IPs may be permanent. (source, as of ) | Undeliverable email and routine IP-bearing logs: 7 days; deletion backups: up to 14 days; deletion system-log purge: up to 30 days; terms-breach IPs may be permanent. (source, as of ) | Settings initiates irreversible deletion; running-database deletion is immediate and full system purge is stated as no more than 30 days. (source, as of ) | web-ios-android (source, as of ) | Free: 1 mailbox; Premium: unlimited mailboxes; aliases forward to a mailbox/inbox (source, as of ) | The policy states a warrant/court-order condition and notice practice, but no SimpleLogin request counts, period, jurisdiction, unit, or report scope are disclosed. (source, as of ) | Not disclosed in the captured primary sources. | Free: 10 aliases; Premium: unlimited aliases (source, as of ) | Free: 10 aliases; Premium: unlimited aliases (source, as of ) | reply from alias on Free and Premium; Premium can initiate to a new contact using a reverse alias (source, as of ) | reply from alias on Free and Premium; Premium can initiate to a new contact using a reverse alias (source, as of ) | Premium: unlimited custom domains (source, as of ) |
Source: every cell above transcludes one vendor's own tool cell (rigs/content-production/pp-privacy/tools/cells/<vendor>.json), captured from vendor-primary documentation under the frozen selection rules (methodology hub). MySudo is excluded: it has no email class pair in its own captured data (it is a phone and masked-card vendor only).
Data retained and retention periods
Retained data, retention periods, and account-deletion statements are compared per vendor in the matrix above. Deletion initiation is kept separate from a stated completed-erasure timeframe; where a vendor's captured pages do not state one, that remains a typed unknown rather than an assumed immediate erasure.
Portability and operational constraints
Platform and forwarding-destination constraints are compared per vendor above, scoped to the plan and platform each cell itself states. No portability claim is rendered beyond what a vendor's own cell establishes.
Lawful-request process and transparency reporting
Lawful-request process statements and published request counts are compared per vendor above. Where no vendor-specific count is disclosed, that is recorded as a typed unknown — absence of a published report is never rendered as zero requests.
Claim labels, sources, and capture dates
Every stated cell above links its own primary source and capture date inline. The table below lists claim type and source origin — kept as separate evidence labels, per vendor and attribute — for every cell that has a stated value; a typed-unknown cell has no source to list and is not repeated here.
| Vendor | Attribute | Claim type | Source origin | Capture date |
|---|---|---|---|---|
| addy.io | Entity jurisdiction | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Signup identifiers | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Identity verification triggers | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Data retained | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Retention period | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Account deletion | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Platforms | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Forwarding constraints | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Lawful-request process | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Creation limit | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Active-alias limit | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Reply from alias | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Send from alias | vendor_stated | vendor_primary | 2026-09-30 |
| addy.io | Custom domain | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Operating entity | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Entity jurisdiction | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Signup identifiers | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Identity verification triggers | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Data retained | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Retention period | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Account deletion | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Platforms | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Forwarding constraints | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Lawful-request process | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Request counts published | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Creation limit | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Active-alias limit | vendor_stated | vendor_primary | 2026-09-30 |
| Apple Hide My Email | Reply from alias | vendor_stated | vendor_primary | 2026-09-30 |
| Cloaked | Operating entity | vendor_stated | vendor_primary | 2026-09-30 |
| Cloaked | Entity jurisdiction | vendor_stated | vendor_primary | 2026-09-30 |
| Cloaked | Data retained | vendor_stated | vendor_primary | 2026-09-30 |
| Cloaked | Retention period | vendor_stated | vendor_primary | 2026-09-30 |
| Cloaked | Account deletion | vendor_stated | vendor_primary | 2026-09-30 |
| Cloaked | Platforms | vendor_stated | vendor_primary | 2026-09-30 |
| Cloaked | Lawful-request process | vendor_stated | vendor_primary | 2026-09-30 |
| Cloaked | Active-alias limit | vendor_stated | vendor_primary | 2026-09-30 |
| Cloaked | Reply from alias | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Operating entity | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Entity jurisdiction | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Signup identifiers | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Identity verification triggers | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Data retained | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Retention period | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Account deletion | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Platforms | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Forwarding constraints | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Lawful-request process | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Request counts published | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Creation limit | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Active-alias limit | vendor_stated | vendor_primary | 2026-09-30 |
| DuckDuckGo Email Protection | Reply from alias | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Operating entity | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Entity jurisdiction | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Signup identifiers | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Identity verification triggers | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Payment methods | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Data retained | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Retention period | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Account deletion | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Platforms | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Forwarding constraints | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Lawful-request process | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Request counts published | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Creation limit | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Active-alias limit | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Reply from alias | vendor_stated | vendor_primary | 2026-09-30 |
| Firefox Relay | Custom domain | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Operating entity | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Entity jurisdiction | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Signup identifiers | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Identity verification triggers | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Data retained | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Retention period | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Account deletion | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Platforms | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Forwarding constraints | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Lawful-request process | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Creation limit | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Active-alias limit | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Reply from alias | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Send from alias | vendor_stated | vendor_primary | 2026-09-30 |
| SimpleLogin | Custom domain | vendor_stated | vendor_primary | 2026-09-30 |
Additional vendor facts
A few more stated facts about vendors already in this comparison exist in the captured tool cells but are outside U7's own comparison schema (open-source repository status; a vendor-stated audit-completion claim). Listed here as plain supplementary facts, not additional comparison columns — no new vendor, ranking, or recommendation is added.
| Vendor | Fact | Stated value | Source origin | Source |
|---|---|---|---|---|
| Firefox Relay | Open-source availability | Mozilla links the Firefox Relay service source to the `mozilla/fx-private-relay` repository, whose fetched repository and LICENSE identify MPL 2.0 with stated image exceptions. | public_repository | source, as of |
| SimpleLogin | Open-source availability | The public SimpleLogin back-end/web repository identifies an AGPL-3.0 license; captured master commit 995904d5bc08ff5f951ad794b9372cbeb04d5fb6. | public_repository | source, as of |
| Cloaked | Audit report | Vendor states SOC 2 Type 2 and PCI DSS v4.0.1 audit completion; assessor/date/report access not disclosed. | vendor_primary | source, as of |
Corrections and version history
The shared correction procedure is maintained on the methodology hub. No correction has been filed against any email-class tool cell as of this population pass.
Alias creation and active-alias limits
Creation limits and simultaneous active-alias limits are compared per vendor in the matrix above and are never merged into one value — a vendor can disclose one without the other.
Replying and sending from an alias
Reply and send behavior are compared as separate columns above. Where a vendor's captured documentation describes only replying (not an independent send-to-a-new-contact capability), send support is recorded as a typed unknown rather than assumed from reply support.
Custom-domain support
Custom-domain support is compared per vendor above. Support for a custom domain does not imply ownership, portability, or any alias limit beyond what the vendor's own cell states.
Sources
Every value in the comparison matrix above transcludes one vendor's own cell from rigs/content-production/pp-privacy/tools/cells/<vendor>.json, each bound to a source URL, a claim type, a source origin, and a capture date. No affiliate parameter, referral link, sign-up call to action, or ranking is rendered on this page.
Not legal advice
Email-alias service policies, forwarding behavior, retention statements, and verification flows can change. This page is a source-bound comparison and not operational, legal, financial, or compliance guidance.