Privacy Policy

    Last updated: September 7, 2025

    1. Introduction

    At Khos, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose and safeguard your information when you use our email aliasing service. Please read this policy carefully to understand our practices regarding your personal data.

    2. Information We Collect

    We collect the following types of information:

    • Account Information: Email address, name, google OAuth photo (if applicable) and subscription status.
    • Service Usage Data: Email aliases created, forwarding preferences, email volume and feature usage statistics.
    • Technical Data: IP address, user agent and cookies for service improvement, security and rate limiting (we are committed to user privacy and do not permanently store this data).
    • Email Metadata: Sender information, timestamps, subject lines and delivery status to provide our service.
    • Security Preferences: Your privacy settings including virus scanning, tracker blocking, enhanced privacy mode and data retention preferences.
    • Rate Limiting Data: Alias creation logs with timestamps and IP addresses to prevent abuse.
    • Quarantine Data: Information about blocked or quarantined emails (Pro users only).

    3. How We Use Your Information

    We use your information for the following purposes:

    • Service Provision: To provide email aliasing, forwarding and security features
    • Security Features: To perform spam filtering, virus scanning and tracker blocking (Pro users)
    • Rate Limiting: To enforce usage limits and prevent abuse (15 aliases per hour)
    • Content Filtering: To block reserved aliases and inappropriate content
    • Account Management: To manage your subscription, billing and account settings
    • Customer Support: To provide assistance and resolve issues
    • Service Improvement: To analyze usage patterns and improve our service
    • Security Monitoring: To detect and prevent fraud, abuse and security threats
    • Legal Compliance: To comply with applicable laws and regulations

    4. Email Processing and Storage

    Our email processing follows strict privacy principles:

    • Email Content: We do not read, analyze or permanently store email content beyond what is necessary for forwarding
    • Temporary Storage: Emails are temporarily cached for up to 4 hours to ensure reliable delivery
    • Metadata Retention: Email metadata (sender, recipient, timestamps) is not permanently stored
    • EU Storage Option: Users metadata is stored in EU data centers for enhanced privacy
    • Automatic Deletion: All email data is automatically deleted after the retention period
    • Security Scanning: Pro users' emails may be scanned for spam and viruses but content is not stored
    • Tracker Removal: Pro users can enable automatic removal of tracking pixels and links which uses our internal tracker removal engine which due to the dynamic nature of the mailing industry, is in constant development and improvement

    5. Data Security and Encryption

    We implement comprehensive security measures to protect your data:

    • Encryption: All data is encrypted in transit and at rest using industry-standard encryption
    • Access Controls: Strict access controls limit who can view your data
    • Audit Logging: All data access is logged and monitored
    • Regular Security Updates: We regularly update our security measures and systems
    • Third-Party Security: We use trusted third-party services (AWS, Supabase and Cloudflare) with their own security measures
    • Data Minimization: We only collect and store the minimum data necessary for our service

    6. Data Sharing and Disclosure

    We are committed to protecting your privacy and limit data sharing:

    • No Sale of Data: We do not sell, trade or rent your personal information to third parties
    • Service Providers: We use trusted service providers (Supabase) to host and process data necessary for operating our service
    • Legal Requirements: We may disclose data if required by law or to protect our rights
    • User Notification: We will notify you before complying with any legal requests for your data, unless legally prohibited from doing so
    • Business Transfers: In case of merger or acquisition, data may be transferred to the new entity
    • Aggregated Data: We shall not share anonymized, aggregated statistics even if they cannot identify you
    • Consent: We will not share your data for other purposes without your explicit consent

    7. Third-Party Service Providers

    We use the following third-party services to provide our service:

    • AWS (Amazon Web Services): For email processing, storage and infrastructure
    • Supabase: For database services, authentication and user management
    • Stripe: For payment processing (Pro subscriptions)
    • Cloudflare: For content delivery and security

    All third-party providers are bound by strict data protection agreements and can only access data necessary to provide their services.

    8. Your Data Protection Rights

    You have the following rights regarding your personal data:

    • Access: Request a copy of all personal data we hold about you
    • Rectification: Correct any inaccurate or incomplete information
    • Erasure: Request deletion of your personal data (right to be forgotten)
    • Portability: Receive your data in a structured, machine-readable format
    • Restriction: Limit how we process your data
    • Objection: Object to processing based on legitimate interests
    • Withdraw Consent: Withdraw consent for data processing where applicable

    To exercise these rights, contact us at [email protected]. We will respond within 30 days.

    9. Data Retention Policies

    We retain different types of data for different periods:

    • Email Content: Maximum 7 days (until the email is delivered or deleted, whichever happens first)
    • Email Metadata: 90 days by default (configurable for Pro users) and includes sender/recipient info and timestamps only, not email content. Used for security monitoring, spam prevention and user control over their aliases, but its never permanently stored
    • Account Data: Until account deletion or 3 years of inactivity
    • Usage Logs: 24 hours for rate limiting, 90 days for security monitoring
    • Quarantine Data: 90 days (Pro users only)
    • Billing Data: 7 years (legal requirement)
    • Support Data: 2 years after last contact

    10. International Data Transfers

    Your data may be processed in different countries:

    • Primary Processing: Europe (AWS, Supabase)
    • EU Option: Pro users can choose to opt out of EU data centers for specific storage
    • Adequacy Decisions: We ensure appropriate safeguards for international transfers
    • Standard Contractual Clauses: We use EU-approved data transfer mechanisms

    11. Cookies and Tracking

    We use cookies and similar technologies for:

    • Authentication: To keep you logged in to your account
    • Preferences: To remember your settings and preferences
    • Security: To protect against fraud and abuse
    • Analytics: To understand how our service is used (anonymized)
    • Analytics: We only use PostHog for privacy-focused analytics with EU data storage (requires your explicit consent and you may withdraw consent at any time)

    12. Children's Privacy

    Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided us with personal information, we will immediately delete it from our servers.

    13. Legal Requests and User Notification

    We are committed to transparency regarding legal requests for user data:

    • User Notification: We will notify you before complying with any legal requests for your data, unless legally prohibited from doing so
    • Limited Data Available: Due to our privacy-by-design approach, we typically have minimal data to provide
    • Legal Challenge: We will challenge overly broad or invalid requests when legally appropriate
    • Transparency Report: We publish annual transparency reports detailing the number and types of requests we receive
    • Warrant Canary: We maintain a warrant canary to indicate we have not received certain types of secret legal requests
    • User Rights: You have the right to be informed about any data disclosure and to challenge such requests

    14. Data Breach Notification

    In the unlikely event of a data breach that affects your personal information, we will notify you within 72 hours of becoming aware of the breach, in accordance with applicable laws. We will also notify relevant authorities as required.

    15. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time. We will notify you of any material changes by email and by posting the new Privacy Policy on this page. We will also update the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

    16. Official Communications and Email Security

    To protect you from phishing and impersonation attempts, please note:

    • Official Email Domain: All official Khos emails will ONLY come from @team.khos.io addresses
    • Never from User Domains: We will NEVER send official communications from @khos.io addresses as those are exclusively for user aliases and not official communications. The Khos.io team took precautionary measures to prevent certain domain names from being used as user aliases to prevent confusion and potential phishing attempts. While we do own the domain name khos.io, we do not use it for official communications and it is not a part of our official email addresses.
    • Official Addresses: Our official email addresses include:
    • Phishing Protection: If you receive an email claiming to be from Khos from any other domain, it is likely a phishing attempt. Please report it immediately to [email protected]
    • Verification: Always verify the sender's full email address before clicking links or providing information

    17. Contact Us

    If you have any questions about this Privacy Policy or our data practices, please contact us: