Security

How your data is protected.

See how data is stored, which actions stay on your computer, and what you still need to keep safe.

Protection in place

What MaskPilot protects today

These protections are already part of MaskPilot and are visible in everyday use.

Backups

Data is encrypted before upload

Account data is encrypted on your computer, so the cloud does not receive browser files that can be opened directly.

Also know this

Each account is encrypted separately. MaskPilot securely keeps the key needed to restore data on another device.

On this computer

Proxy and AI tools stay on this computer

Other devices on your local network cannot directly connect to these tools.

Also know this

AI still checks your identity and permissions. Closing MaskPilot also closes its local AI connection.

Signed-in devices

Remove devices you do not recognize

Sign-in information is protected and refreshed over time to reduce the risk of long-lived access.

Also know this

You can review signed-in devices and remove one you no longer use or recognize.

Deletion & recovery

Accidental deletion keeps a recovery path

Deleting an account does not immediately remove its recovery data, avoiding irreversible loss from one mistake.

Also know this

Only the account owner can view and use recovery options.

Updates

Only ready-to-use versions are public

Builds that are being tested or released in stages are not presented as stable public downloads.

Also know this

The website provides a SHA-256 value, and MaskPilot checks downloads for corruption or the wrong version.

Teammate access

Teammates only use assigned content

Admins choose which accounts teammates can see and whether they can manage proxies, share accounts, or use AI.

Also know this

AI follows the same access rules and cannot bypass an admin’s settings.

What you still need to know

These details also affect the safety of your data.

The service keeps the key needed for recovery

This is needed to restore data on another device, so MaskPilot does not claim the service can never decrypt data.

Large deployments need extra safeguards

Larger setups still need suitable gateways, monitoring, and shared team protections.

Device security still matters

Limiting network access does not replace system updates, disk encryption, or malware protection.

We do not show certifications we have not earned

Third-party security or audit badges appear only after they exist and can be publicly verified.

Paths you can check

Do not rely on a single “secure” claim.

Protections should map to data, user controls, and release behavior. These paths explain boundaries instead of replacing facts with certifications that do not exist.

See what is collected, why it is used, and what stays local.

The privacy page separates account information, browser environments, proxy and AI activity, device state, orders, and website analytics, then lists the controls available to you.

  • Sign-in and payment-result pages do not load website analytics
  • Proxy tests and local AI service run in the client
  • When sync is allowed, account data is encrypted before upload
Read the privacy policy

Recovery does not mean the service can never decrypt data.

The service must keep the key required to restore data on another device. The data lifecycle explains device upload settings, encryption, version conflicts, deletion, and recovery together.

  • Each device can stop uploading its local changes
  • Version conflicts preserve local changes without overwriting cloud data
  • The recycle bin does not promise a fixed retention period
See the data lifecycle

The download page only presents public stable releases.

The direct download and release metadata are separate. Available releases show version, date, file size, and SHA-256. When metadata is unavailable, the page does not invent version details.

  • Stable Windows x64 download path
  • Public releases provide a SHA-256 checksum
  • The client shows notes and validates an update before install
See the Windows download

Understand the boundaries first

See how data moves before deciding to use the product.

Read the privacy policy and data lifecycle first. If anything remains unclear, contact MaskPilot through the public support email.