Privacy Policy
Masked is built so you don't have to hand over personal data to get things done. Here's exactly what we do and don't collect, across every part of the app.
Last updated: 20 July 2026
What we collect
- Your Telegram user ID – to authenticate you and tie orders to your account. We receive it from Telegram when you open the app.
- Your orders – for virtual numbers, the service and country you chose, the number assigned, the order status, and the verification code received.
We do not ask for your name, email, real phone number, address, or any identity document.
Virtual numbers & codes
Numbers are temporary and released after the verification window. Verification codes arrive from the upstream provider and are shown to you; we keep them as part of your order history so you can re-read a code you already received.
Temp Mail
Disposable inboxes are provisioned through an upstream email provider. The address and any messages it receives are temporary and self-destruct when the inbox timer ends; we don't tie them to your identity beyond what's needed to show the inbox to you in-app. Don't use a disposable inbox for anything you need long-term access to.
Breach Check
The password check runs on a privacy-preserving model called k-anonymity: your password is hashed in your browser and only the first five characters of that hash are sent to Have I Been Pwned's Pwned Passwords. Your password itself never leaves your device, and we never see or store it. The optional email check sends the address you enter to XposedOrNot to look up known exposures.
Fake ID
Generated identities are randomly assembled from generic components. They contain no real personal data and describe no real person, and we don't retain the identities you generate as part of a profile about you.
Payments
Payments are made in Telegram Stars and processed by Telegram. We never see or store card, bank, or other financial-instrument details. We retain the Telegram charge reference needed to issue refunds.
What we don't do
- We don't sell or rent your data.
- We don't build advertising profiles or run third-party ad trackers.
- We don't require identity verification (no KYC) to browse or buy.
Data retention
Order history is kept so you can review past orders and so we can handle refunds and reconcile payments. Disposable inboxes and generated identities are ephemeral by design. Aggregated, non-identifying operational logs may be retained to keep the service reliable and secure.
Third parties
To deliver the service we rely on a small set of providers, each processing only what's necessary to play its part:
- Telegram – authentication and payments.
- Upstream number providers – to source virtual numbers and their codes.
- Upstream email provider – to provision disposable Temp Mail inboxes.
- Have I Been Pwned – Pwned Passwords, for the client-side password check.
- XposedOrNot – to power the Breach Check email lookup.
Your choices
For questions about your data, deletion requests, or anything else, contact us via @GetMaskedBot.
Changes
We may update this policy as the service evolves (for example, when proxies launch). Material changes will be reflected here with a new "last updated" date.