All articles

Tech

My Email Was Exposed in a Data Leak. So I Built a Way to Stop Sharing It.

The story behind HyverMail, why I started building it, and why our real email address should not be something every website needs to know.

Share
hyver mail
hyver mail




For years, I looked at data leaks primarily from a cybersecurity perspective.

I work in cybersecurity, so exposed credentials, leaked databases, phishing attempts, compromised accounts, and personal information circulating online were not unfamiliar topics to me.

But at some point, the problem became personal.

I discovered that some of my own email addresses had appeared in leaked datasets.

That changed the way I thought about email privacy.

Suddenly, I was not analyzing someone else’s exposure. It was my own digital identity.

Why should I give my real email address to every website I use?

That question eventually became HyverMail.

The Problem Started With Something We All Do

Think about how many times you have entered your email address online.

A new application. An online store. A newsletter. A SaaS platform. A mobile app. A free trial. A website you might never visit again.

Most of the time, we enter the same personal email address without thinking about what happens to it afterwards.

Once we click Sign Up, we lose a large amount of control.

We do not always know how the service stores our address. We do not know which third parties may process it. We do not know how long it will remain in their databases. And most importantly, we do not know whether that company will still be secure years from now.

A company can have strong security today and still suffer a data breach tomorrow.

You cannot control the security of every company you interact with. But you can control how much of your real identity you give them in the first place.

My First Solution Was Not the Right One

The obvious solution was to create multiple email accounts.

  • One for personal accounts

  • One for shopping

  • One for newsletters

  • One for applications

  • One for services I did not completely trust

Technically, that reduces exposure. Practically, it creates another problem.

Now you have several inboxes to monitor, more passwords to manage, more recovery methods to maintain, and more accounts that need to be secured.

I did not want another inbox.

I wanted to continue using the email account I already had. I simply wanted a way to use it without exposing the actual address behind it.

That became the foundation of HyverMail.

What Is HyverMail?

HyverMail is a privacy focused email alias platform designed to sit between your real inbox and the services you use online.

Instead of giving a website your actual email address, such as:

yourname@gmail.com

you create a private email alias through HyverMail and use that alias instead.

The website sees the alias. Your real email stays hidden.

The important part is that you do not need to create another inbox or completely change the way you use email.

You can continue using Gmail, Outlook, Apple Mail, Yahoo, or another email provider you already rely on.

Messages sent to your alias can still reach your existing inbox. This includes OTP codes, verification emails, password reset links, order confirmations, account notifications, and other important messages.

No second inbox to constantly check.

No need to migrate your entire email history.

No need to expose your primary email address everywhere.

Hide your email. Keep your inbox.

One Inbox, Multiple Digital Identities

The more I worked on the idea, the more I realized that HyverMail was not only about hiding an email address.

The bigger idea was control over digital identity.

Imagine using one alias for online shopping, another for newsletters, another for applications, another for SaaS services, and another for a specific website.

All of them can ultimately lead back to the inbox you already use. But those websites do not necessarily need to know the real email address behind them.

This creates separation between your primary digital identity and the services you interact with.

If one alias starts receiving spam, you can control that alias. If one alias becomes exposed somewhere, you do not need to replace your primary email address. If an alias created for one particular service suddenly starts receiving unrelated messages, you also have a much clearer indication of where that address may have been exposed or shared.

Instead of allowing hundreds of services to share one permanent identifier, you can create controlled identities between yourself and those services.

Your Email Is More Important Than It Looks

An email address may seem like a simple piece of information. In reality, it is often one of the most persistent identifiers connected to someone’s digital life.

People change passwords. They change usernames. They replace phones. They delete accounts. But many people keep the same email address for years, sometimes for decades.

Over time, that single address can become connected to dozens or even hundreds of services.

Once exposed, it may appear in breached databases, marketing lists, spam campaigns, phishing operations, credential collections, automated reconnaissance systems, or other data aggregation environments.

From a cybersecurity perspective, this increases the user’s exposure surface.

This is why I do not see email aliases simply as an anti spam feature. For me, they are a way of reducing unnecessary exposure before exposure happens.

Privacy is not only about protecting information after you share it. It is also about deciding whether you needed to share it at all.

Building HyverMail From a Cybersecurity Perspective

Because my background is in cybersecurity, I did not want to approach HyverMail as only an email forwarding product.

If a platform sits between users and their communication, security cannot be treated as an optional feature. It has to be part of the architecture.

HyverMail is being built around privacy focused architecture, secure message handling, encryption, alias isolation, authentication protection, access controls, and user control.

Encryption is part of the security model used to protect sensitive information and communications where appropriate.

But I also believe security products should be careful with the claims they make.

There is an important difference between using encryption to protect data and claiming that an entire system is end to end encrypted.

Those terms should not be used interchangeably.

A privacy focused platform should clearly understand what is encrypted, where encryption is applied, what data is stored, and what the actual threat model looks like.

Trust should come from architecture and implementation, not from marketing terminology.

That principle has influenced the way I approach HyverMail from the beginning.

Security Should Not Make Life Harder

One of the biggest challenges in cybersecurity is usability.

A security product can be technically impressive and still fail if people find it too difficult to use. When security creates too much friction, users find shortcuts. They reuse information. They disable protections. They ignore warnings. They choose convenience.

I wanted HyverMail to take a different approach.

Keep your existing inbox.

Keep your existing email provider.

Keep receiving the messages you need.

Keep your normal workflow.

Add privacy around it.

For most users, the experience should remain simple. Create an alias. Use it instead of your real email. Receive the messages you need. Stay in control.

Privacy should work around people’s existing habits instead of forcing them to completely rebuild their digital life.

The Problem Is Bigger Than Spam

It would be easy to describe HyverMail as a way to reduce spam. But spam is only one visible consequence of a larger issue.

The real problem is uncontrolled identity exposure.

Every time you use the same personal email address on another platform, another database stores that identity. Another company processes it. Another system has access to it. Another potential breach may expose it.

An alias changes that relationship.

The website still gets an address it can use to communicate with you, but it does not necessarily receive the permanent email address connected to the rest of your digital life.

That is what makes the concept especially interesting to me from a cybersecurity perspective. It moves the user from passive exposure toward active control.

From a Personal Problem to a Product

HyverMail originally started because I wanted to solve a problem for myself.

I wanted to continue using my normal inbox while reducing the number of companies that knew my actual email address.

But while developing the platform, I started seeing a much larger opportunity.

There is a significant space between traditional email providers and advanced privacy tools.

Some privacy tools are designed mainly for technical users. Some require users to migrate to another provider. Others introduce enough friction that many people will never use them consistently.

I believe privacy infrastructure can be simpler.

It can be powerful without becoming complicated.

It can exist around the tools people already use.

And email aliases can eventually become a normal layer of digital identity rather than something used only by privacy enthusiasts.

That is the direction I want HyverMail to continue moving toward.

Building the Product Changed My Perspective

Building HyverMail also reminded me that creating a cybersecurity product is not only about security engineering.

A product like this involves many interconnected challenges: infrastructure, email reliability, deliverability, authentication, abuse prevention, privacy, user experience, performance, scalability, monitoring, and trust.

Security cannot come at the cost of usability.

And usability cannot come at the cost of security.

Finding the balance between those two is one of the most interesting parts of building HyverMail. It is also one of the reasons I still see the product as being at the beginning of its journey.

Where HyverMail Is Today

Today, HyverMail is live.

What started with discovering my own email addresses inside leaked data has become a working product and a much broader idea around email privacy and digital identity.

But there is still a lot I want to build.

· Better alias management

· More advanced security controls

· Stronger privacy features

· Better visibility for users

· More integrations

· Improved automation

· More control over how aliases behave

· Infrastructure capable of supporting the platform as it grows

My longer term vision is simple:

Using an alias should eventually feel as normal as using your real email address does today.

People should not have to expose a permanent digital identifier simply because a website needs somewhere to send an OTP code, confirmation message, or account notification.

There should be a privacy layer in between.

Why I Am Sharing This

I am sharing this story because I believe some of the most interesting products begin with problems we experience ourselves.

HyverMail did not start from a pitch deck.

It started from a question I genuinely wanted answered:

How can I keep using my email without exposing it everywhere?

So I decided to build the answer.

Today, HyverMail sits at an intersection that I find particularly interesting: cybersecurity, privacy infrastructure, digital identity, email technology, and SaaS.

There is still a long road ahead, and I am always interested in connecting with people who are building, researching, supporting, or investing in these areas.

Not only to talk about HyverMail, but also to exchange ideas about where privacy, identity, and online communication are heading next.

Try HyverMail

For now, HyverMail is completely free to use.

If you have ever wondered where your email address ends up after clicking Sign Up, maybe it is time to stop giving every website the real one.

Try HyverMail: https://hyvermail.com

Hide your email. Keep your inbox.

Built from a personal privacy problem. Growing into something much bigger.

Share