Someone sat down one rainy Sunday afternoon and went through their password manager. They counted every service they'd ever created an account with. The number was 312.
Not 312 accounts they still actively used. 312 services that had, at some point, received their name. Their email address. Sometimes their physical address. Sometimes their phone number.
Shops from holidays years ago. Forums visited three times. Tools that shut down after six months but whose databases are still out there somewhere. Conference newsletter signups. Supermarket loyalty programmes. Gym memberships.
312 copies of one person, scattered across the internet.
How many do you have?
The problem with counting
The unsettling thing about that number isn't the size; it's that most of those 312 services have long since dropped off the radar. You're not using them anymore. You're not thinking about them. But they still have your data.
And if one of them gets breached tomorrow? Your real name shows up in a database for sale. Combined with your real email address. Then someone with a list cross-references that with last year's breach, and the one from three years before, and suddenly a total stranger has a fairly complete picture of you.
This is how data brokers operate. Not by acquiring one massive breach, but by stitching together small pieces of information. And every account you've ever created was a potential puzzle piece.
Why email aliases aren't enough
Maybe you already use email aliases. SimpleLogin, Relay, or something similar. You've solved one layer of the problem: your real email address stays hidden.
But think about what you're still handing over.
At most services, alongside your email you also provide:
- Your real name, because the signup form asks for it, and you fill it in
- Your real address, for shipping, billing, or just because it's requested
- Sometimes your phone number, for verification or account recovery
An email alias hides one field. But the other fields are still yours. And they're still identical across all 312 services.
A data broker linking two breaches together doesn't always do it via email addresses. They do it via names. Via name-and-address combinations. Via name and date of birth.
Your email alias misses exactly that part.
The missing half
What you actually want is what password managers did for passwords: unique per-site values for every identifiable field.
Not just a unique email per site, but a different name. A different address. A different date of birth where applicable.
Every service sees a different you. A consistent you, because you want a site to recognise you next time you log in, but a different you from the shop you used last month.
Data brokers can't link those two. There's nothing to link. The name in one breach doesn't match the name in the other.
This is the idea behind Masquerade: a unique persona per site (name, email alias, address) auto-filled at signup. One click. Like a password manager, but for your whole identity.
Your 312 copies become 312 masks. And you're not standing behind any of them.