BlogLaunch
Launch

We Built Masquerade Because Password Managers Solved the Wrong Half of the Problem

Every website knows your real name. Password managers protect your credentials, but they don't protect your identity. Masquerade does. Here's why we built it.

C
Cedric Gordon
April 16, 2026 · 5 min read
launchprivacyidentity

You probably use a password manager. You have unique, random passwords for every site. Excellent. No single breach can crack your other accounts. Password reuse is a solved problem.

But here's what your password manager doesn't protect: your name.

Every site you've ever signed up for has your real name, your real email address, and very often your real home address. Those three things, taken together, are you. And they travel freely through data brokers, marketing lists, breach dumps, and cross-site advertising profiles, long after you've forgotten the account even existed.

You've secured the key. You left the door with your name on it.


The data broker problem no one talks about

When you use the same email address at thirty different websites, those sites don't need to coordinate to build a picture of you. Your email is the stitching thread. It connects your DoorDash orders to your Reddit account to your gym membership to that random forum you posted on in 2019. Data brokers don't steal this. They're handed it, one signup form at a time, by you.

And when one of those sites gets breached (which, statistically, some of them will) the attacker doesn't just have one account. They have a thread. A name, an email, maybe an address, and a behavioral fingerprint they can use to correlate you across the rest of the web.

The problem isn't the breach. The problem is that every breach burns your whole identity, not just one account.


The thing we kept wishing existed

Email alias services help. If you use SimpleLogin, Firefox Relay, or DuckDuckGo Email Protection, you're already ahead. You can give a different alias to each site, and when the alias starts receiving spam, you kill it without exposing your real inbox.

But the alias is only half the picture. You still gave that site your real name. Your real address. A consistent set of profile fields that, when combined with a hundred similar profiles across other services, adds up to a very accurate portrait of you.

What we kept wishing existed was something that handled the whole identity, not just the email.

So we built it.


What Masquerade does

Masquerade is a browser extension and web dashboard that generates a unique persona for every website you sign up on.

Different name. Different email alias. Different address. Consistent across sessions, so if you log back into the same site, you're still the same person they know. But a different person than you are everywhere else.

The personas are realistic enough to pass standard form validation. They're not linked to real people; the name generator samples from frequency-weighted lists, the addresses are structurally valid but not real residences, the dates of birth are in plausible adult ranges. And they live entirely inside Masquerade. You can export all of them anytime, in JSON, and walk.

The email aliases route through Masquerade's relay. You can forward alias mail to your real inbox, or leave it inside the Masquerade dashboard and read it there. Reply-through means when you reply from the Masquerade inbox, the recipient sees the alias, not your real address.

At signup, the extension detects the form fields and fills them in one click. It feels like a password manager. Except instead of filling in your real name and a different password, it fills in a different you.


Why this is different from what exists

The alias services handle email. Masquerade handles the persona, and includes email aliases as part of it.

The key difference is anti-correlation. When Site A and Site B both have your email alias and your name, a data broker can still cross-reference you. When Site A has Alias A and Name A, and Site B has Alias B and Name B, there's nothing to stitch together. The thread is cut.

Breach containment is the other headline difference. When Site X leaks, only Site X's mask burns. You rotate the persona: generate a new one, update the alias, move on. The breach is contained to one mask, not your whole identity.


What Masquerade is not

It's worth being direct about this, because the category gets misread.

Masquerade is not a VPN. We operate at the identity layer, not the network layer. Your IP is your business. There are good products for network anonymity; Masquerade isn't one of them.

Masquerade is not a fraud tool. Personas are designed for signups at everyday consumer services: forums, newsletters, e-commerce, SaaS trials. The terms of service explicitly prohibit using Masquerade to defraud regulated services, impersonate real individuals, or do anything illegal. We built friction against obvious misuse into the product from day one: the persona generator doesn't touch banking domains or government sites, and there's no feature for generating government-format documents because that would be a crime, not a privacy tool.

Masquerade does not protect against state-level adversaries. If you need that kind of protection, if your threat model includes a well-resourced nation-state, this isn't the right tool for you at this version. We protect against trackers, data brokers, cross-site correlation, and breach fallout. That's the scope we designed for, and we'd rather be honest about it than overclaim.


What's in v1, and what's coming

Today's launch includes:

  • Chrome and Firefox extension with one-click persona autofill
  • Email alias relay with per-alias forwarding toggle
  • Masquerade inbox with reply-through support
  • Web dashboard for managing all personas and aliases
  • JSON export (your data is yours)
  • Free tier and one paid tier with Stripe billing

Coming in v1.1 (weeks after launch, not vaporware):

  • iOS and Android apps with system autofill provider
  • Safari extension
  • Bulk import from SimpleLogin, AnonAddy, and Firefox Relay
  • Custom domain aliases on the paid tier

We're not launching mobile because the browser loop needs to be proven first. We're not launching with import because the parsers are per-provider and we don't have enough real alias data yet to test them properly. Those are the honest reasons.


Try it

If this is the thing you've been waiting for, sign up here.

If you have questions about the threat model, the abuse-prevention architecture, or what happens to your data if you cancel, read the FAQ or email us. We wrote answers to the hard questions before launch specifically so you don't have to wonder.

The masks are waiting.


Masquerade is open about its scope. It protects against trackers, data brokers, and cross-site correlation. Not state-level adversaries. Questions? hello@email.masquerade.broker

Field notes, monthly

Smart thinking on privacy, in your inbox. Obviously, on an alias.

One email a month. Essays on privacy, the odd product note, and nothing else.

no tracking pixels · unsubscribe with one click

privacy is the defaultone user · many masksyou are not your email addressnothing traces backevery site gets a different youreal you · never leaves the roomnew mask · same youprivacy is the defaultone user · many masksyou are not your email addressnothing traces backevery site gets a different youreal you · never leaves the roomnew mask · same youprivacy is the defaultone user · many masksyou are not your email addressnothing traces backevery site gets a different youreal you · never leaves the roomnew mask · same youprivacy is the defaultone user · many masksyou are not your email addressnothing traces backevery site gets a different youreal you · never leaves the roomnew mask · same you