legal

privacy policy

last updated September 2026

im is built to manage your identities, not to profile you. this page explains exactly what we store, why, and what we don't do with it.

what we collect

  • your email address, to sign you in and send account-related links
  • the identities you create: names, handles, and any notes you write
  • email aliases you generate and their forwarding address
  • a phone number, only if you choose to add one to an identity
  • vault entries you save: label, username, password, url, and notes
  • session metadata (browser, sign-in time) so you can see and revoke active sessions

we don't run analytics, ad trackers, or third-party tracking scripts on this site.

how it's protected

  • vault passwords and private notes are encrypted at rest; the key never leaves our server
  • sign-in and verification links are single-use and stored as hashes, not as usable links, so a database leak alone can't hand over a working link
  • sessions are signed and can be revoked individually from any device, anytime

who else sees it

only what each feature actually needs, and only when you use that feature:

  • Supabase hosts our database
  • Mailu delivers and forwards mail for your email aliases
  • Telnyx provisions phone numbers, only if you add one
  • Paddle processes payment, only if you buy pro or a number, and never sees your aliases, vault, or notes

cookies

one cookie: a signed session token required to keep you signed in. no advertising or tracking cookies.

your data, your control

export a full copy of your account or vault anytime from settings, emailed to you as a one-time download link. delete your account anytime, which permanently deletes every identity, alias, number, and vault item tied to it.

children

im is not directed at, and should not be used by, anyone under 16.

changes

if this policy changes in a material way, we'll update the date at the top of this page.

contact

questions about your data: [email protected]