Privacy and data

Privacy policy

This page explains what the MaskPilot website and desktop client process, why each category is needed, which actions stay on your computer, and the controls available to you.

Updated · 2026-09-06
01

Information we process

MaskPilot processes the information required to provide registration, sign-in, browser environments, proxy and extension management, team access, sync and recovery, and orders. Each feature uses a different data scope.

  • Account information: email, verification state, website sessions, and the result of a third-party sign-in method you choose.
  • Product configuration: account environment settings, fingerprint configuration, proxy and extension assignments, team allocation, and feature permissions.
  • Runtime and recovery state: whether an account is running, device sessions, sync summaries, recovery records, and necessary action results.
  • Order information: plan, term, payment channel, order status, and channel identifiers required to process payment. Payment secrets never enter the website or client build artifacts.
  • Website analytics: public pages other than sign-in and payment-result pages load Google Analytics to understand page visits and improve the site.
02

Actions that stay local

Proxy availability tests, multi-hop checks, exit-timezone validation before launch, and local AI assistant connections run in the desktop client on the current computer. The website does not test your proxies or run local AI tools for the client.

  • Local MCP listens on a local address by default and stops when MaskPilot closes.
  • Local Manifest V3 extensions and their account assignments stay on the current device and do not upload or sync.
  • The current device’s “Do not sync account data” setting does not follow the account to another device.
03

Sync, encryption, and recovery

While “Do not sync account data” is enabled, the current device does not upload local changes. When upload is allowed, the client prepares and encrypts account data after close, then uploads an encrypted package for later recovery.

Each account is encrypted separately. MaskPilot keeps the key needed to restore data on another device and therefore does not claim that the service can never decrypt account data.

  • The same account can run on multiple devices. Uploads check the cloud version; conflicts preserve local data without automatically merging it.
  • Deleting an account environment does not immediately remove records required for recovery, but no fixed retention period is currently promised.
  • Local changes that were never synced do not appear automatically on another device after restore or sign-in.
04

Third-party services

Except for the website analytics described below, information is sent to a third party only when the related feature is enabled and you choose to use it. Each provider processes information under its own terms and privacy policy.

  • Email delivery services send registration and sign-in verification codes.
  • Google or Microsoft sign-in is used only when operations has configured the provider and you select it.
  • The client presents payment channels currently available. Checkout pages, signature validation, and channel secrets are handled by the backend and the selected payment service.
  • Public pages other than sign-in and payment-result pages use Google Analytics.
05

Your controls

Existing website and client controls let you manage signed-in devices, device sync policy, account environments, teammate permissions, local AI, and local extensions. Some recovery and account-level requests require the account owner or support team.

  • Remove a signed-in device you no longer use or recognize.
  • Decide whether the current device can upload account data.
  • Turn off the AI assistant, reset the local Token, or remove a teammate’s AI permission.
  • Delete an account environment and use owner recovery while it remains available.
  • Contact the address on this page with the current account and a specific privacy or account request.
06

Policy updates and security boundaries

When product capabilities, third-party services, or data flows change in a way users can notice, this page will update its date. Network restrictions and application encryption do not replace operating-system updates, disk encryption, malware protection, or careful credential storage.

We do not display security certifications that have not been earned or cannot be publicly verified. Report security issues through the contact address with reproducible details and avoid exposing account data or Tokens in public channels.