# AliasVault: Open-Source E2EE Password & (Email) Alias Manager

**URL:** https://discuss.privacyguides.net/t/aliasvault-open-source-e2ee-password-email-alias-manager/24436
**Category:** Project Showcase
**Created:** 2025-01-28T09:53:48Z
**Posts:** 233

## Post 1 by @lanedirt — 2025-01-28T09:53:48Z

Hi PrivacyGuides!

I’m excited to introduce [AliasVault](https://www.aliasvault.com), an open-source password and (email) alias manager designed to protect your privacy online.

AliasVault combines password management with unique identity generation, including email aliases, to help you compartmentalize your online presence. This helps in preventing third parties (e.g. data brokers) from creating shadow profiles of you, a common issue when the same email address is used across multiple services. AliasVault is end-to-end encrypted, fully self-hostable, and designed with privacy-first principles at its core.

This project was recently mentioned by a [PrivacyGuides.net](http://PrivacyGuides.net) user in another forum section, and I’m happy to now formally present it here to gather feedback from privacy enthusiasts like you. Shortly about me: I’m Leendert, a software developer with over 15 years of experience and a long term privacy enthusiast myself. As an example of this I’ve been running [SpamOK.com](http://SpamOK.com), a free temp email service since 2013.

Over the past year, I’ve poured my heart into AliasVault, dedicating much of my free time to creating a tool that empowers people to take control of their digital identities.

AliasVault is completely free and open-source under the MIT license because I believe privacy is a right, not a privilege. While I plan to introduce optional convenience features for the cloud version in the future (for a small fee to cover upkeep and aid future development), the self-hosted version will always remain free and accessible.

I’d love your help, whether by trying it out, sharing it with friends, or simply offering feedback / advice.

#### Key Features:

- **Unique Identities & Passwords** : Generate unique email aliases and strong passwords for every service.
- **Self-Hosted Email Server** : Create and manage aliases without relying on third-party services.
- **Zero-Knowledge Design** : AES-256-GCM and Argon2id encryption ensure your data is secure. Your master password never leaves your device.
- **Open-Source & Self-Hostable** : Review, audit, and deploy AliasVault on your own infrastructure. Installation is quick with Docker (also supports ARM for Raspberry Pi).
- **Official Cloud Version** : For convenience, a fully-supported hosted option is available.

#### Try it Out:

- **Cloud Version** : [AliasVault.com](https://www.aliasvault.com)
- **Self-Hosting & Docs** : [GitHub](https://github.com/aliasvault/aliasvualt) | [Docs](https://docs.aliasvault.com)

I’m also proud to share that a community member created an independent in-depth review and self-hosting tutorial for AliasVault. Check it out on YouTube: [https://www.youtube.com/watch?v=T7IqvNj5b2M](https://www.youtube.com/watch?v=T7IqvNj5b2M)

#### Future Plans:

I’m working to meet all [PrivacyGuides’ recommended criteria](https://www.privacyguides.net) for listing, with the security audit being a top priority. Transparency, open-source availability, and privacy-first practices are core to AliasVault.

Here are some of the short-term priorities (\< 4-6 months):

- **Security Audit** : I’m actively exploring options with independent auditors and have applied for grants to support this effort. Hope to be able to share progress on this in the coming weeks.
- **Feature Roadmap** : The up-to-date roadmap is published on GitHub, but the biggest things being worked on right now are:
  - Creating browser extensions (Chrome/Firefox) with autofill mechanism. Already making good progress on this and it’s looking really nice, hope to have the first version out in the next two weeks.
  - Custom domain support on cloud version
  - Allow importing passwords from other password managers

Additional plans for the longer-term:

- Adding native mobile apps (iOS/Android)
- Team / organization features (sharing passwords/aliases)
- Integrating disposable phone number service for SMS confirmation

#### Feedback

I’d love to hear your thoughts:

- Would AliasVault fit into your privacy toolkit?
- What features or improvements would you prioritize?
- How can I make it easier for self-hosters and privacy advocates to adopt?

Your feedback will directly shape AliasVault’s development, so please share your thoughts. Thank you for taking the time to read about AliasVault, much appreciated! Looking forward to your input! :folded_hands:

---

## Post 2 by @Sectional2932 — 2025-01-28T12:29:31Z

It looks interesting, I’ll try it out. Is it also based in the Netherlands like your other project? I’d rather use something that’s under GDPR.

---

## Post 3 by @lanedirt — 2025-01-28T12:48:19Z

Thanks for giving it a try! Both of my projects are hosted on my own servers with Hetzner in Germany, so yes, they are fully compliant with GDPR data protection regulations.

---

## Post 4 by @ihateKYC — 2025-02-08T17:52:15Z

You’ve made a perfect solution! I can deal with the lack of TOTP support since I don’t recommend keeping it in your primary password manager anyways.

---

## Post 5 by @lanedirt — 2025-02-08T17:59:36Z

Thanks for your feedback :slight_smile:. I do hope to add TOTP support to the client in the near future, which shouldn’t be too hard as AliasVault already has TOTP functionality built-in for it’s own 2FA.

I’m also making good progress on the browser extension, I’m estimating I’ll have the Chrome version out somewhere next week. This will make using AliasVault a lot easier with smart autofill, and being able to create an alias + email for a website with just one click when you’re on the signup form. I’ll post an update on it when it’s available.

---

## Post 6 by @anon36940904 — 2025-02-08T20:01:05Z

Yay! for the new upcoming updates!

Please also release the .xpi file for Firefox at-least if Mozilla takes long to publish it for Firefox. Btw, I hope you will also make and release one for Firefox?!

---

## Post 7 by @Sectional2932 — 2025-02-09T12:59:10Z

How can the account be deleted? I wanted to delete the one I set up to try creating a different kind of vault from the beginning, but I can’t see how to delete the existing one.

---

## Post 8 by @anon36940904 — 2025-02-09T14:21:20Z

Yes, I second this. Being able to delete should be easy and one or two clicks at most - and be made available soon. I hope it is.

---

## Post 9 by @lanedirt — 2025-02-09T16:59:51Z

@anon36940904 Yes after the Chrome extension is done I’ll focus on adapting it to support Firefox next. If publishing on the app store takes too long I’ll make sure to publish the files separately too.

@Sectional2932 Good point! Account deletion is currently only supported on the self-hosted version through the admin panel. The cloud version does not have a self-delete option yet. There is already an issue for this on GitHub: [Add user delete account option to client app · Issue #373 · lanedirt/AliasVault · GitHub](https://github.com/lanedirt/AliasVault/issues/373). I’ll try to get this feature included on the next release which should be published in the next few days. :slight_smile: If you wish to have your account deleted on the cloud version immediately then feel free to send me a PM and I can do it for you.

---

## Post 10 by @Sectional2932 — 2025-02-18T19:35:07Z

It looks like that’s been in the backlog since December, so it might not be live anytime soon. I’ll send you a DM to delete the account, and I’ll consider it again when people can delete their own vaults.

I recommend adding an update here when account deletion is supported.

---

## Post 11 by @lanedirt — 2025-02-24T21:21:10Z

Happy to share that today AliasVault update 0.12.0 (and 0.12.1) have been released!

Updates:

- AliasVault now has it’s own browser extension starting with Google Chrome, enabling autofill on register and login forms. It’s currently pending review in the Chrome Web Store, which can take a couple of days up to three weeks. It is possible to install it manually in the meantime, see instructions here: [Release 0.12.0 · lanedirt/AliasVault · GitHub](https://github.com/lanedirt/AliasVault/releases/tag/0.12.0). I’m going to make a video in the coming days to showcase all the features of the browser extension. Will post that later.
- Adds account self-delete option to client
- Adds option to disable all authentication IP logging for self-hosted installs (was requested by another user)
- Additional interface / UI tweaks

@Sectional2932, as discussed previously in this thread, the account delete option is now available :slight_smile:.

Regarding the AliasVault browser extension: once the Google Chrome version has been accepted, I’ll begin work on porting it over to Firefox and other browsers.

---

## Post 12 by @anon36940904 — 2025-02-24T21:30:39Z

Fantastic news! Thanks for the continued work and update with improvements.

---

## Post 13 by @Sectional2932 — 2025-03-01T14:33:04Z

Thanks for the updates. I will create a new account and try out the updated version.

---

## Post 15 by @lanedirt — 2025-03-04T16:33:31Z

Thank you!

Yes, I’ve considered adding a travel/duress mode before, and I think it would be a valuable feature. I haven’t personally encountered a situation where I needed to show my phone or laptop while traveling, but from what I’ve read, this seems like an important addition to a password manager. I’d love to hear your thoughts, have you run into situations that made you (want to) use this feature, or do you have any suggestions on a good way to implement this?

---

## Post 17 by @anon36940904 — 2025-03-04T17:13:17Z

> [@Banter8905](#):
>
> a feature like this on a mobile device could provide a safety net to something as critical as our passwords.

I would rather have a fantastic web app working instead of an app in full. Something like how Cryptee does it. But I hear it could be a lot harder to ensure on mobile and an app is just easier to make relatively.

If there is an app, you can always delete it when you need to but if the phone is inspected, they can see what apps you had downloaded. That’s why a web app is better since you can simply delete all history and site data and you’re done.

---

## Post 18 by @lanedirt — 2025-03-21T09:05:41Z

Hi everyone, happy to share that after a lot of continued hard work the new update for AliasVault ([https://www.aliasvault.net](https://www.aliasvault.net)) is out now:

> AliasVault 0.14.0:
> 
> - **Browser extension available everywhere** : The AliasVault browser extension has been released and approved for all major browsers: Chrome, Firefox, Edge and Safari (macOS). It also works with all Chromium-based browsers such as Brave.
> - **Built-in 2FA authenticator** : AliasVault now includes a built-in 2FA TOTP authenticator which allows you to store and generate 2FA tokens straight from your vault. Generating 2FA codes works with both the web-app and browser extensions. (Compatible with Google Authenticator)
> - **Misc improvements** : there have also been a lot of smaller improvements made to the UI and user experience in general. Tweaks to the self-hosted setup experience, improved admin screen, improved documentation etc.

Next big thing I’m working on is a roadmap that will be published soon, which will include all the remaining work that will lead up to the 1.0 release. Major things in scope are native iOS/Android apps and improving alias/identity data structure to support importing passwords from existing password managers.

* * *

Also, as an update on the security audit side: I had a meeting with security auditors to discuss AliasVault, and they expressed interest in taking it on. I asked what a full audit of AliasVault’s scope might entail, and I’ve received estimates in the range of xx.xxx USD, which is quite a bit more than I expected. Since this is an open-source project, I don’t have the funds to cover that myself. That’s why I’ve applied for grants with NLNet and the OpenTech Fund a few weeks back. They’ve informed me there are some delays, and that the application is still being processed. I hope to receive a response within the next 2–3 weeks after which I can give a full update on this.

I’m again happy to receive your feedback / ideas if you had the time to give AliasVault a try. And also happy to answer any questions.

@ihateKYC: as you asked about it in one of your previous replies, happy to let you know TOTP support has now been added. :slight_smile:

---

## Post 19 by @anon36940904 — 2025-03-22T16:26:29Z

Thank you for the continued work and improvements. And glad to know more improvements are on the way!

For the audit cost, you can open up donations that can act as future subscription value for those who donate (A certain amount) to help you cover the costs. This may be logistically difficult to ensure but it’s possible. Just an idea.

Thanks again for providing a legitimate alternative for such a tool in the privacy space.

---

## Post 20 by @anon55464882 — 2025-03-22T16:54:14Z

It might be wise not to rush your security audit, especially since your service currently generates little revenue and remains in its early development phase.

Keep in mind that 1Password was released in 2006 and completed its first security audit in 2014, while Bitwarden waited two years before undergoing its first audit.

Given that you’re operating independently and your service is already open source, it may be best to conduct a third-party audit once you have sufficient revenue.

---

## Post 21 by @lanedirt — 2025-03-23T11:49:35Z

Thanks for your insights and suggestions!

@anon36940904, I appreciate your support and the idea about accepting donations as future subscription credits. That’s something I’ll definitely consider if the grant application won’t (fully) work out, especially as premium features and subscriptions come into play later from a business perspective.

@anon55464882, great point about the timing of security audits in relation to other projects like 1Password and Bitwarden. I wasn’t aware of 1Password and Bitwarden’s specific history regarding that, that’s good to know. My earlier discussions with the cybersecurity auditors do align with your suggestion: we’re aiming for the full security audit around the stable 1.0 release, when all major architecture, including datamodel refactoring and upcoming client logic for iOS/Android, is settled. When everything goes according to plan this could be somewhere near Q3/Q4 this year.

I’m however hopeful about the grant applications, as securing these funds would greatly enhance AliasVault’s security, benefiting all current and future users.

---

## Post 22 by @lanedirt — 2025-04-09T08:30:23Z

:rocket: **AliasVault 0.16.0 is out now!**  
Hi everyone, happy to share that a new update for [AliasVault](https://www.aliasvault.net/) is live!

Here’s what’s new since the last post:

> AliasVault 0.16.0:
> 
> - **Import Wizard** : You can now easily import credentials from other password managers with the brand-new import wizard. Currently supported: 1Password, Bitwarden, Chrome, Firefox, KeePass, KeePassXC, and Strongbox. (If you’re missing a service that you’re using now, please let me know!)
> - **Customizable Password Generator** : You can now set your own password generation patterns globally or per credential, respected by the browser extension.
> - **Streamlined UI for Username/Password Logins** : AliasVault now offers a cleaner and more intuitive interface for managing traditional credentials (just username + password). This is live across both the web app and browser extensions.
> - **Quality-Of-Life tweaks** : Create custom credentials directly in the browser extension, improved autofill, enhanced admin analytics & user management, improved loading status indicators to match AliasVault look & feel.

Also, the roadmap for v1.0 has been published on GitHub, which contains all the areas/features that will be worked on in the coming months: [AliasVault v1.0 roadmap · Issue #731 · lanedirt/AliasVault · GitHub](https://github.com/lanedirt/AliasVault/issues/731)

Over the coming weeks, my main focus will be R&D and development of the upcoming AliasVault native iOS and Android apps. These apps will enable seamless autofill of credentials across mobile platforms, making the AliasVault ecosystem one step closer in working everywhere :slight_smile:

---

## Post 23 by @TrashPanda — 2025-04-09T11:27:35Z

This looks marvelous, keep up the great work! :slight_smile:

---

## Post 24 by @anon36940904 — 2025-04-09T13:48:53Z

Hey

Thank you for the new updates!

I did see the import feature a few days ago but Proton Pass is missing. Please add that as an option too.

---

## Post 26 by @anonymous261 — 2025-04-14T23:38:08Z

This looks really cool, thanks for your work! Encrypted alias mail gives this an edge compared to SimpleLogin imo.

I noticed that the FAQ in the website states:

> 1. Email aliases are receive-only, meaning you cannot send or reply to emails from your aliases. This measure prevents potential abuse of the system for spam.

I think that having a reply feature like SimpleLogin’s [reverse aliases](https://simplelogin.io/docs/getting-started/reverse-alias/) would be really useful, but would potential abuse of the system still be a problem?

---

## Post 27 by @lanedirt — 2025-04-15T07:31:47Z

@Banter8905 Good suggestion, that would indeed be a valuable addition. I’ve added it to the v1.0 roadmap just now!

@anonymous261 Thank you! Yes, the implementation of a reply feature for email aliases is a heavily requested feature and therefore I made it part of the roadmap for version 1.0. Thanks for mentioning the reverse alias idea, that looks interesting. I’ll add it to my notes for comparing/researching how the system could work for AliasVault :slightly_smiling_face:

---

## Post 28 by @germless-omission — 2025-04-15T10:06:57Z

Some thoughts after looking at this service:

Exporting with something encrypted would be nice. Maybe a scheduler to auto export too?

Using other email aliasing services (e.g. duckduckgo, addy, etc) as part of the same automated interface would be nice

My current setup is KeePassXC with Syncthing and the only thing I feel is lacking with this service is an automatic email alias generation option built into KeepPass. Selfhosting an aliasvault seems like it would be nice but probably a little harder to setup than syncthing.

---

## Post 29 by @rescuer-phoniness — 2025-04-15T10:30:44Z

A native linux app with no need for a server would be good, it seems the roadmap only includes Windows and Macos though :thinking:

---

## Post 30 by @lanedirt — 2025-04-18T07:52:30Z

Happy to let you know that Proton Pass has now been added to the import wizard in the latest version 0.16.1.

@germless-omission Thanks for your suggestion! Encrypted mannual exports is a good idea, I’ve added an issue for it on GitHub.

@rescuer-phoniness Thanks for your idea. The current AliasVault design however relies heavily on having a server for receiving email, and to be able to sync the encrypted vault between devices (web app, browser extension, upcoming mobile apps). There are no plans currently for releasing AliasVault as a standalone client that relies on pure local storage. However I am going to look into native client apps, where I hope to be able to make it cross platform so Linux support should be possible too.

---

## Post 31 by @PurpleDime — 2025-04-18T09:18:54Z

I just watched the video on your website, and this looks promising. I personally think there needs to be more competition in the alias market, because Proton Pass / Simple Login has some serious limitations I am not comfortable with.

I also think Password managers like 1Password need to step their game up and offer an alias feature at no extra cost, or else they will eventually lose market share to Proton Pass.

**My questions for you are as follows:**

_1) Can I receive email to my aliases to an inbox address (e.g.: a Proton address)?_  
_2) Can I send emails from aliases?_  
_3) Can I create more than one alias for the same third party website (e.g.: 3 aliases for 3 Reddit accounts)?_  
_4) Can I choose the words in my alias (eg: [green.apple123@aliasvault.com](mailto:green.apple123@aliasvault.com)) ?_

It’s my understanding that Alias Vault is currently 100% free but that in the future, you plan to introduce a paid plan.

_5) Will you remove features that are currently free when you introduce that paid plan?_

This is one of my biggest issues with a lot of online service. IMHO, if a service needs to remove features that are currently free to compel users to move to a paid plan, it’s not worth paying for.

---

## Post 32 by @lanedirt — 2025-04-19T13:54:40Z

Thanks for watching the video and your interest in AliasVault :slight_smile:

I’m happy to answer your questions:

1. No, forwarding received emails to another email address is not currently supported. By design, as soon as emails are received by AliasVault, they are immediately encrypted and only stored in encrypted form. Emails can only be decrypted by the user themselves using a key that is stored in their own encrypted vault.

2. Replying to emails is not supported yet, primarily to prevent spam abuse in the cloud-hosted variant. This feature is however planned for the v1.0 roadmap, which I expect to have ready before the end of this year. But how exactly this feature is going to work requires some further research.

3. Yes, you can create multiple aliases for the same website. You can do this by simply creating multiple credentials for it. The autofill in the browser extensions will automatically detect this. So for example, if you want to log in to Reddit, it will show you all Reddit accounts/aliases that you created and stored in your vault.

4. Yes, you can choose your own email alias, as long as it hasn’t already been used by someone else. By default, when generating a random alias, it creates a matching email address (e.g., for the alias “Riley Meyers,” AliasVault may assign something like “[rileymyers61@aliasvault.net](mailto:rileymyers61@aliasvault.net)”). The exact email structure is randomized, but you’re also free to enter your own desired email address when creating the alias.

5. No, free features will not be removed. All current free features (and more are coming) will remain free. Future paid features that will be part of the AliasVault premium offering will be entirely new convenience features. Features such as connecting your own email domains to the AliasVault cloud offering, increased storage, automatic cloud backups, and possibly even a temporary mobile phone number service.

I agree with you that a premium offering should be distinctive and valuable in itself, adding real benefits for users rather than gatekeeping previously free features.

Also, as AliasVault is open-source, users are always free to self-host it, which comes without any storage limits and allows them to manage their own backups as they please. So in that sense, the future premium features will mostly focus on convenience, not necessarily essentials for security purposes.

If you have any further follow-up questions or ideas, feel free to share!

---

## Post 33 by @anon88979181 — 2025-04-19T14:16:28Z

I think your product/app/service is going to be come the new gold standard for what such a tool is and can do that provides a solid alternative to Proton’s offering. And the privacy tech space always needs more alternatives and options.

I do look forward to the continued development and any premium offerings to properly compete with others on the features and price fronts.

---

## Post 34 by @PurpleDime — 2025-04-19T14:28:22Z

Thank you so much for taking the time to respond. :grinning_face_with_smiling_eyes: I’m satisfied with your answers, and it makes me want to test Alias Vault.

**MULTIPLE ALIASES FOR THE SAME WEBSITE IS A MUST FEATURE:**

The ability to create multiple aliases for the same website is an indispensable feature for me. Most Proton users don’t know this, but **Proton Pass / Simple Login** only allows _one_ alias per third party website, which to me is ridiculous.

Many of us have multiple accounts with some websites, and we can’t use them with **Proton Pass**. Even if **Proton Pass** somehow allows you to create more than one alias for the same website, it is explicitly against their rules. I got a warning after creating a third alias for the same website. That’s how I found out about this limit.

I spoke to Proton Support, and they told me as much. I’ve had numerous conversations about this issue with them over time, and some customer support agents did not even know about this rule and learned it from me. I hope Proton changes this rule because it has security and privacy implications that I plan to write about in a future post.

I just have one last question:

**Why did you create Alias Vault? What compelled you to do so?**

I wouldn’t say that the email alias market is crowded, but there are already quite a few providers ( **Simple Login/Proton Pass** , **Addy** , **IronVest** , **Duck Duck Go** , etc…).

**Why did you feel there was a need for a new one?**

---

## Post 35 by @beaver — 2025-04-19T19:12:00Z

About the planned phone number feature, is it limited to two or three countries like US or available everywhere?

---

## Post 36 by @Youri — 2025-04-19T19:24:46Z

I see it is free to use (for) now, but are you thinking about pricing the service in the future and if so, do you already have some price points in mind?

---

## Post 37 by @lanedirt — 2025-04-20T11:17:07Z

@PurpleDime, On why I created AliasVault, that’s a good question :slight_smile:

I’ve been a privacy enthusiast for a long time. My journey began in 2013 with creating asdasd.nl, a Dutch temporary email service that later evolved into [SpamOK.com](http://SpamOK.com). Over time, I received more and more questions from users interested in more advanced features. Also two years ago when I added a name generator and saw how widely it was used, it got me thinking: why not build an integrated tool that combines alias identities, (temporary) email addresses, and login credentials, all in one system?

While there are other tools out there, they often rely on external services and lack a unified, self-hostable ecosystem. Also from a design and usability perspective, I like to keep things simple and have it “just work”. For those who like to self-host and keep things simple, having everything integrated just makes sense.

AliasVault has been a passion project from the very beginning, not just for myself, but for the wider community that values privacy and digital independence. After working as a freelance software developer for over 15 years and wrapping up a long-term client project last year, I felt it was the right moment to follow my intuition and invest my time into building AliasVault. My dream has always been to build and grow a product that’s not only sustainable, but genuinely useful to others. And seeing people using AliasVault, sharing it online and offering their feedback makes me very happy :slight_smile: .

For now I’m funding everything out of pocket myself, which is mostly my time. But when the basic feature set will be mostly done at the end of this year, I hope to make it more sustainable by adding the earlier mentioned premium options. I’m also considering future investment or crowdfunding opportunities, which could help with things like larger marketing efforts and expedited feature releases.

–

@beaver The planned phone number feature is intended to be available in as many countries as possible, while having to take into account the different jurisdictions and local legal requirements. My intention is certainly not to restrict it to just a few countries, but to make it as flexible and location-independent as possible. I’ll be sharing more details on this in the coming months.

–

@Youri I have not decided yet about the exact pricing points, but the goal is to offer something that’s competitive with existing services while remaining accessible and fair for users. It’s also worth reiterating in this case that the current features of AliasVault that are free will remain free, so any future premium options should be considered as additional extras, not paywalled essentials.

---

## Post 38 by @PaleCrow55 — 2025-04-20T13:54:00Z

> [@PurpleDime](#):
>
> **Proton Pass / Simple Login** only allows _one_ alias per third party website, which to me is ridiculous.

I don’t think that’s quite accurate? SL And Proton’s TOS both disallow “Abusive” use of aliases for third-party services, which SL clarifies to include “bulk signups,” but I don’t see any prohibition of “multiple” aliases for a single service.

Sources:

[SimpleLogin | Terms and Conditions](https://simplelogin.io/terms/) (Section 1, paragraph 9)  
[Terms of Service | Proton](https://proton.me/legal/terms) (2.11)

---

## Post 39 by @PurpleDime — 2025-04-20T23:10:35Z

> [@PaleCrow55](#):
>
> I don’t think that’s quite accurate? SL And Proton’s TOS both disallow “Abusive” use of aliases for third-party services, which SL clarifies to include “bulk signups,” but I don’t see any prohibition of “multiple” aliases for a single service.
> 
> Sources:

**Yes, and _abuse_ and _bulk_ sign-ups is any more than _one_ alias per third party website.** I exchanged directly with Proton support, and they’ve told me as much. Also, I got an automated warning after creating 3 aliases for the same website. And the third alias didn’t work. Proton has internal rules that may not be explicit in the TOS, but you can ask them yourself.

It sucks, but many online companies have weasel words in their TOS that they get to interpret however they want. Most of us would agree that if I bought 2 apples or 3 apples, I did not buy them in bulk. But to Proton, bulk is any more than one. I argued with them about this. That’s what they decided. Even if you were able to create 2 aliases for the same website, and they work, it’s not allowed. Hence, it’s a risk if you get caught.

Only one alias per third party website is allowed. Ask Proton. And when you ask them, ask them to confirm with their superiors, because as I said, some agents don’t know about this internal rule and assume that you can create as many as you want.

For context, in my situation, I was not signing up to any service. There is a website for which I have 3 accounts, and I have had those accounts for many years. All I wanted to do was replace the email for each account with a Proton alias. Even though signing up to a service is not the same as updating your email for said service, for Proton, that is irrelevant. I updated my emails within 2 hours and got a warning after the third alias.

---

## Post 40 by @PurpleDime — 2025-04-20T23:15:07Z

Thank you for sharing your story! I wish you success in your endeavor. Competition is healthy and necessary. I don’t know if it’s you or Proton that came up with the idea of combining password manager with aliases, but I think it’s fair that Proton popularized it. Either way, it’s a brilliant idea! IMHO, every paid password manager should copy this concept at no extra cost, or they will lose to competitors.

---

## Post 41 by @PaleCrow55 — 2025-04-21T17:27:30Z

> [@PurpleDime](#):
>
> any more than _one_ alias per third party website

If true (I haven’t inquired myself), then I do agree that that’s too strict. I understand not wanting users to spam third party services leading to them blanket banning all Proton/SL addresses, but there are legitimate cases for a single person needing alt accounts, like having personal vs business profiles on a social site.

---

## Post 42 by @PurpleDime — 2025-04-22T06:39:13Z

> [@PaleCrow55](#):
>
> there are legitimate cases for a single person needing alt accounts, like having personal vs business profiles on a social site.

Absolutely. Unfortunately, Proton doesn’t seem to appreciate this. Pretty much all other alias providers allow you to have multiple aliases for the same website, except Proton / SL, which is INSANE. **Carey Parker** from _Firewalls Don’t Stop Dragons_ shared on his podcast that he has 2 LinkedIn accounts. Although I don’t really use my LinkedIn account, I want to create a 2nd account so I can look at jobs and profiles anonymously. With Proton, that’s not possible.

**Millions of people use websites for which they have multiple accounts for whatever reason, and Proton refuses to make room for this extremely common reality.** I argued back and forth with them for weeks! One of the counterarguments they gave me is: “we’re not Google” i.e., we are not as widely accepted, so we don’t want to take the risk of allowing multiple aliases for the same website, even though every other alias provider does.

They say that, but at the same time encourage people to brag on social media about how many aliases they have.

---

## Post 43 by @Youri — 2025-04-24T07:49:37Z

Goed om te weten/ good to now about the pricing. It only makes it more interesting.

---

## Post 44 by @lanedirt — 2025-05-14T15:36:58Z

:rocket: **AliasVault 0.17.0 is out now!**  
Hi everyone! As hinted in my previous update from April, I’m excited to announce that the iOS app for AliasVault is now finally **live in the App Store**! :tada:

It took quite a lot of hard work… and a few rounds in the ring with Apple’s App Review team :boxing_glove: (spoiler: they claimed the first few rounds). But after tweaking the app and jumping through the necessary hoops, AliasVault is now live on iOS!

Download link to App Store: [AliasVault for iPhone](https://apps.apple.com/app/id6745490915).

(You can also build the iOS app yourself from source, all client apps are part of AliasVault’s [GitHub monorepo](https://github.com/lanedirt/AliasVault).)

The iOS app integrates with native iOS autofill capabilities and secures your encrypted vault contents with on-device biometrics (Face ID / Touch ID).

 ![iOS app preview as part of the new 0.17.0 release](//forum-uploads.privacyguidesusercontent.com/original/2X/3/3c3a13502d36b1f47972406435c4dcc3b59e2545.jpeg)

Here are the full release notes for this new release:

> AliasVault 0.17.0:
> 
> 1. **Native iOS App Launched!** : release 0.17.0 marks a major step forward by introducing the **official AliasVault native iOS app** , now available on the iOS App Store! :tada: This new app enables native autofill features for iOS and protects your vault contents with on-device biometrics. The app is compatible with **both cloud-hosted and self-hosted** environments.
> 2. **Browser extension improvements** : added extra setting toggles to the browser extensions which allow you to enable/disable the context menu and hide the autofill popup on a certain website for a specified time. Added support for shortcuts so you can trigger the autofill popup via a keyboard shortcut (works best in Chrome). Also improved autofill popup reliability so it works on more websites.
> 3. **Quality-of-life improvements** : various other smaller improvements in the web app and browser extensions to align how credentials are displayed to better match it on all platforms.
> 4. **License change to AGPLv3** : From this release forward, AliasVault is licensed under the AGPLv3, replacing the previous MIT license. This change is made to protect the intellectual property and long-term vision of AliasVault, while keeping it fully open and transparent. For end-users and self-hosters, nothing changes: you can continue to use, self-host, and customize AliasVault freely for personal or internal use. The new license only restricts commercial use by third parties who may otherwise profit from AliasVault without contributing back.

With this release AliasVault is now available on **all major platforms** : Web, Chrome, Firefox, Edge, Safari, Brave, and now on mobile starting with iOS!

I’m working on making the app available on Android next, which I expect will be ready somewhere in the coming weeks. :slight_smile:

---

## Post 45 by @anon57862721 — 2025-05-14T15:57:00Z

What a fantastic new update!

AliasVault is quickly turning out to become my go to recommendation after Proton Pass but before Bitwarden now.

Edit: I installed the app and logged in - very smooth for a brand new app. Will keep testing and using it more to see how it fairs.

---

## Post 47 by @lanedirt — 2025-05-15T08:29:28Z

@anon57862721 Thanks for your appreciation and support! Really means a lot to me and makes me smile to read that :slight_smile: ! If you run into any issues or hick-ups with the app or have ideas for improvement, feel free to let me know.

@Banter8905 Good point. I think it might be worth adding support for subscriptions through the app store for convenience options to the user. Although I’m not fully up-to-date on the current status in terms of how much % the App Store takes on sales and if referring to payment options outside the app (with a discount) are now allowed.

Do you have a personal preference on this? I.e. preferring to use in-app purchases for subscriptions vs. doing it via the website of the service (if offered)?

---

## Post 49 by @PurpleDime — 2025-05-16T19:08:55Z

Hi! I finally got around to creating an **AliasVault** account so I could try it out. Looking forward to playing with it.

---

## Post 50 by @dramsay1 — 2025-05-17T15:07:50Z

@lanedirt, do you have a backup plan for the [aliasvault.net](http://aliasvault.net) email domain someday being blocked for new registrations by certain websites? Like protonmail users and some other email domains are currently experiencing?

---

## Post 51 by @lanedirt — 2025-05-17T15:32:29Z

Good question! Yes, AliasVault already supports multiple private email domains under the hood. For the official cloud-hosted version, it currently offers only **[aliasvault.net](http://aliasvault.net)** for aliases. But if this domain ever gets blocked or added to blacklists, I’ll roll out additional domain variations that users can switch to seamlessly. The software already supports this (and for self-hosted installs, people can already configure multiple domains for themselves).

The reason I didn’t launch [aliasvault.net](http://aliasvault.net) with multiple private domains right away is mainly due to cost, as maintaining many active domains can quickly get (relatively) expensive. For example, with **[SpamOK.com](http://SpamOK.com)** (the predecessor to AliasVault), I started with 10+ domains which seemed like a fun idea at the time, but now it costs me hundreds of euros yearly just to keep them alive because users started to rely on them. Depending on how you look at it, it might not sound like much, but as I’m running that site for over 10 years already, it does add up. :slight_smile:

So in short: AliasVault is designed to scale to dozens or even hundreds of domains in the future, but my current approach is to add them incrementally, based on need. This keeps things more sustainable while still ensuring continuity for users if any single domain gets blocked.

---

## Post 52 by @dramsay1 — 2025-05-17T23:16:55Z

That’s great! You are all over this rollout. I don’t think I’ve ever seen anyone as responsive as you to a privacy project. Kudos!

---

## Post 53 by @PurpleDime — 2025-05-18T06:10:33Z

Where did Proton aliases get blocked?

---

## Post 54 by @dramsay1 — 2025-05-18T16:16:09Z

Ticketmaster, Playstation and Chime to name a few. If you can stand going over to Reddit (the fart of the internet, I hate Reddit with a passion) you can see many people discussing this.

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonMail/comments/1kobl37/services_not_allowing_use_of_protonmail/)**

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonMail/comments/1jmm5wv/what_are_known_websites_that_block_proton_mail/)**

---

## Post 55 by @arise1984 — 2025-05-18T17:40:50Z

Netlify also blocked proton, sl and addy address. Free privacy respecting email and alias service would obviously be abused and being treated as suspicious by sites and services. Its a neverending cat and mouse game if to keep buying new domain until it eventually be abused and be blocked again, plus unsustainable monetarily. You’d end up with 1000 domains in no time. Proton and addy resorted to allow users to report such sites to them and they’ll contact the site owner to persuade them to allow their domain on the site. Plus they specifically forbid multiple accounts creation on the same site by the same user on their tos.

---

## Post 56 by @PurpleDime — 2025-05-18T17:47:57Z

Wow. I expected it to take much longer for Proton to get blocked. This is why it’s important to have a wide range of domains.

---

## Post 57 by @PurpleDime — 2025-05-18T17:57:32Z

> [@arise1984](#):
>
> Netlify also blocked proton, sl and addy address. Free privacy respecting email and alias service would obviously be abused and being treated as suspicious by sites and services. Its a neverending cat and mouse game if to keep buying new domain until it eventually be abused and be blocked again, plus unsustainable monetarily. You’d end up with 1000 domains in no time.

Proton’s alias service is not free. But I get your point. Unless it’s companies with a lot of brand name recognition, I don’t necessarily think it’s a good idea for Proton to plead with them. Especially when it’s companies whose entire business model is surveillance capitalism. I also personally question how pervasive the so-called “abuse” is.

Companies get to define abuse however they want. Case in point for Proton, having more than one alias per third party website is abuse. Also, companies get away with abusing their users privacy and consumer rights daily, but they get away with it because it is often legal.

> [@arise1984](#):
>
> Plus they specifically forbid multiple accounts creation on the same site by the same user on their tos.

I am so glad somebody else is finally recognizing this. As I’ve previously said, it it is one thing for Proton to have this very impractical rule, and it’s another to hide it, and not state it clearly upfront.

Because let me remind everyone here, this rule is not clear and explicit in their TOS. The TOS is vague. You only learn about the explicit details of the rules when you disobey them.

---

## Post 58 by @arise1984 — 2025-05-18T18:16:52Z

Multiple domains won’t do anything since dns records are public info. Theres even some service that outright block registration via custom domain added to sl or addy by inspecting the domain mx records.

Sl tried to be smart via the 2 or 3 premium domain only for paid users hoping there won’t be much abuse with it but they got blocked either way due to blanket ban on sl mx and ip.

---

## Post 59 by @lanedirt — 2025-05-18T19:17:35Z

Yes I can confirm that some websites or blacklists tend to blanket ban all domains that are on the same IP. I’ve had that happen with SpamOK too, where a certain blacklist that LinkedIn was using simply added all domains that were also using the SpamOK IP to their blacklist. This caused the website of my consulting company and various other services to be blocked as well as they were all sharing the same IP. Even though these other websites had nothing to do with the SpamOK service itself.

One idea I have to combat this with AliasVault is to also have certain premium “hidden” domains only available to certain segments of paying users. Then I want to host these domains on entirely separate IP’s not affiliated with AliasVault, and let these mail servers proxy all emails to the main AliasVault server. This would prevent third parties from being able to link domains based on MX DNS or IP. But as was mentioned before, in the end this unfortunately is and stays a cat and mouse game and will cost (more) money.

We’ll have to see how this plays out exactly, but my vision is to do have these kind of mitigating measures in place as long as it’s financially feasible, and as long as (certain) users accept the premium.

---

## Post 60 by @cupcake — 2025-05-18T20:03:16Z

I mean if both you and paying users are fine with the added cost to allow them using the alias comfortably, segregation via combination of premium domain, separate mx, separate ip and proxying sounds superb. Even proton and addy doesn’t go that far.

---

## Post 61 by @anon57862721 — 2025-05-21T01:26:36Z

Okay. So I have been using AliasVault fully for the past week on macOS on Brave via the extension and on iOS via the app. Here are all my thoughts and experiences thus far as the app/product stands:

Right off, I want to mention what I want to see absolutely and immediately improve:

1. Please, please, please - I need the ability to change/amend/edit/etc details on any entry of any account/alias via and within the extension itself. Having to log in on the website and clicking more things than really needed is just so frustrating when you’re trying to update very important, sensitive and time sensitive info (that may be autoremoved from your clipboard if you don’t paste it fast enough). Not having this is kinda stressful to be honest. It feels like a major part of the product functionality is missing.
2. When popping out the extension in a new window/web app like window, I want to continue to see the ability to edit any and all entries including a better and a more window filling email view so the email renders bigger and better for easy viewing.

These two are most important as I see it now from a usability and user experience POV.

More feedback/views/issues/recommendations/etc:

1. Software passkey support (literally how Proton Pass does it, ideally) is much needed. This means, being able to add and use passkeys when websites prompts and the extension pops up for you to add the passkey should all work as it does on and with Proton Pass.
2. Import functionality can be significantly improved. All entires from Proton Pass are added but in an imperfect manner. Ideally, you want it to be 1:1 import but it looks a little haphazard after import is completed in AliasVault. I had to manually change a few things on all my entries which is not a good import experience and could turn some people away as soon as they begin to try it. Giving specifics would be too much to say here but I’ll say this - if a Proton Pass entry has username, email, password, 2FA, note, etc - I want to see the same in the same manner in AliasVault too with the right title for each item within each entry. I know, no import feature of any mature password manager app is this good but this is or should be the goal. And given the FOSS nature of AliasVault and Proton Pass, this is surely doable. This is not time sensitive as it may require a lot of work but as long as it is done before a full stable release with paid options, this level of “maturity” would be fantastic to see.
3. Being able to turn off (but not delete) Alias email of any entry/account would be a great addition. But in this case, not like how Proton Pass does it. It want the email alias to appear within the entry details along with other details - unlike how Proton Pass has it where the email alias appears separate from the account details of that alias. This would truly be a unique functionality with such an implementation because no other password manager does this. So, I hope you seriously consider this.
4. Email view improvements - when viewed in a new pop up window, I want the email to appear as it does with any other email view from any other email. This means, email list of the left, email content on the right (1:3 ratio of window size of each section.. if this makes sense) and other toggles for delete, read, unread, etc options on the bottom.
5. Being able to resize the extension pop up to you liking would be great! (not to be confused with a separate window but just clicking on the extension on the top right and the pop up that appears)
6. Passkey authentication on iOS (and Android when the app comes out or when the app begins to mature on Android) within apps or on the web just like you can do on/through Proton Pass would be the smoothest way to go about it. Please replicate the user experience from Proton Pass with this one on AliasVault.
7. Improve autofill recognition on web: here’s the issue. AliasVault currently identities any entry field and shows its icon on the side of the entry field. This is incredibly annoying and distracting when you’re filling out your address details or any other details when shopping online because the pop of on each text box blocks what you have actually typed and you can’t see anything. It also shows up on the side of all drop down menus (so when I am editing a doc online on OnlyOffice for example, it shows up on the each down down menu option of the ribbon up top on the font size, font, formatting options, etc. In other ways, AliasVault needs to better identity what are authentication text boxes (that is username, password, and 2FA) and what are other non sign in/sign up/authentication text boxes on the web. I hope I have explained the issue with this clearly. This is really annoying right now.
8. Ability to add other entry items in any account is also much needed. I may have notes or any other details I want to add but cannot via the extension. I think the lesson with all my points here to consider the extension as the main app on desktop and it needs all the functionality an app would have. One should not be forced to open AliasVault on the web to do select things if they exclusively want to use the extention only. And this consequently means, the extension needs to significantly improve with how it functions and with the number of features it has.

–

Please take all my comments are constructive criticism. I have only expressed what I have and the way I have in an honest manner from a user experience and usability POV. I know AliasVault is still pretty new and is under active development and most if not all of the things I have mentioned will eventually end up happening in time. So I am not holding any shortcomings against you or the product.

I had fully turned off Proton Pass and gave AliasVault and complete and honest try for all that it can do today so these views come from that experience. This practically makes these “opinions” objective facts for what AliasVault is, how it works, and what doesn’t/is missing. I only say this because anyone (as I write this) can run the same user experiment I did and come to same conclusions. None of what I have said is really wrong or false.

@lanedirt - I hope these comments, suggestions, recommendations are useful to you and I sincerely want to see it become as good as Proton Pass is (from its usability and user experience POV atleast) if not better (if you can come up with better ways).

Please reach out here or privately if you have any follow up questions with specificity in case you don’t fully follow anything I have said above.

That’s my review of AliasVault as of today. Thanks! I continue to look forward to new improvements. But please fix the first two as soon as you can.

---

## Post 62 by @lanedirt — 2025-05-21T07:39:40Z

Hi @anon57862721,

Thanks a lot for your very detailed feedback and for giving AliasVault a full try! I really appreciate your effort and honesty, this really helps a lot for me to improve AliasVault! I’m glad to say that a lot of your suggestions are already in scope for the 1.0 roadmap (published on [GitHub](https://github.com/lanedirt/AliasVault/issues/731)), and I wanted to quickly highlight the ones that match your suggestions:

:white_check_mark: **Already included in the v1.0 roadmap** :

- Full client capability for the browser extension (to match the main app, being able to edit credentials etc.)
- Passkey support (storage + usage)
- Improved import functionality
- Ability to group credentials (folders)
- Passkey login on mobile apps (iOS & Android)
- Platform-specific improvements, including browser extension resizing, more responsive layout, email view UI enhancements.

I completely agree with your point on making the browser extension a fully functional client with full edit capabilities. For context: the iOS app (and the upcoming Android app, which should be ready in ~2 weeks) share a lot of tech with the browser extension and already support full editing. Once the Android version is out, I’ll be focusing on bringing these capabilities to the extension so it can function as a complete standalone client. This work is already on the roadmap and will be prioritized after the Android release.

### Quick clarification needed:

**1. Improve autofill recognition on web:**  
The browser extension uses a custom algorithm to detect username/password/email fields, but unfortunately many websites implement things in non-standard ways which makes this pretty complicated. There’s also the added complexity where AliasVault tries to both detect traditional username/password fields (for login/signup), but also standalone email fields (e.g. signing up to newsletters).

I already maintain a growing test suite with ~20 website variations that the algorithm is tested against on every build. I’m extending this test suite as we go along and (new) issues are detected. Would you be able to (privately) share which websites (besides OnlyOffice) are giving you issues with field detection or annoying overlay icons? That would help a lot in improving this feature for everyone.

**2. Turn off (but not delete) email aliases:**  
When you say you’d like to “turn off” an alias, would you expect:

- The alias to still receive emails silently in the background, and show them when re-enabled?
- Emails to be **hard rejected** with a bounce-back message to the sender?
- Or, just **silently dropped** — not stored in AliasVault but also not alerting the sender?

Thanks again for taking the time to give AliasVault a full try with your workflow, and taking the time for sharing your feedback! It really helps a lot in improving AliasVault and helps me to better understand various usecases people might have.

AliasVault has already come a long way in terms of improved and new features in the last few months. And I’m positively hopeful to have the v1.0 release ready before the end of this year with all of the aforementioned features, which include your suggestions, included. :slight_smile:

---

## Post 63 by @Regime6045 — 2025-05-21T09:50:05Z

Are you planning to create support for an emergency contact? In Bitwarden, you can nominate another account (e.g. your partner) to be your emergency contact. In case you lose access to your vault (forgotten password, lost 2FA token) they can request access to your vault and then you get an email notification and unless you say “no” they will get access after x days (you can set the time). This still works despite E2EE.

---

## Post 64 by @anon57862721 — 2025-05-21T16:05:16Z

Thanks for responding and sharing what the updates and what you think. I appreciate it.

> [@lanedirt](#):
>
> ### Quick clarification needed:
> 
> **1. Improve autofill recognition on web:**

I see. I didn’t know this was the case. So, if this is how it is - sure, I can try doing this but don’t you think the problem will still continue to exist for a long time? There are so many websites with so many text boxes that are not for authentication. And because ALiasVault icon/suggested entry box is showing on every drop down option or text box on the web, wouldn’t you have to fix a “million” websites where this could occur such that it only shows when it needs to? Proton Pass really fixed this issue quickly and I don’t know how they did it. Your approach could be different and I’m willing to help but there’s only so much I can let you know about.

If you still want me to - I will but I’ll want to do this privately since I don’t want to name websites publicly in this thread. I am DM you here if you’re okay with it. Please let me know.

> [@lanedirt](#):
>
> 1. Turn off (but not delete) email aliases:

Hmm. In this case with the options you have, there are several ways you can go about it.

When I say “turn off” - I normally mean I don’t want that alias to receive emails until I enable it again, like how Proton Pass and others do it. But if you can provide multiple options for what “turn off alias” means, that would be a new and unique functionality/feature set for AliasVault that others are not providing thereby differentiating AliasVault more.

Option1: not receiving emails until turned back on  
Option2: auto archiving any emails being received (in a new archived emails list/folder  
Option3: hard reject with ALiasVault itself auto clicking the unsubscribe option that the email may have or sending a bounce back message about unsubscribing. I’m not sure what the best option is here from a privacy perspective so please ensure you use and develop the best private way to go about it. I’m guessing the emails received are also E2EE? Can you confirm/clarify?  
Option4: any other option you may think about or come up with in order to provide the user with all options along with others

–

Thanks for the getting back with the updates. I have an Android too - I use GrapheneOS. It would be fantastic if your Github or website has a direct Obtainium link for people using GOS to directly add it and install it via Obtainium so we get the fastest updates as soon as you publish it.

I will keep using AliasVault (as imperfect as it is for everyday use, practically speaking) and will keep updating you on my experience with perhaps some specifics as and when I encounter “issues” or issues with my usage.

Thanks again. Please let me know.

---

## Post 65 by @lanedirt — 2025-05-22T07:50:20Z

@Regime6045 Yes that’s a good point. I do want to implement some kind of fallback access to the vault, in case the primary master password has been forgotten and/or not accessible anymore. An emergency contact feature could fit well in to this. I’m not sure what this will look like but certainly is something I’d like to have for v1.0. I’ve added it to the roadmap as a to-do just now. Thanks for raising this point!

@anon57862721

1. The way the autofill detection for AliasVault _should work_ is that it only activates and shows the icon/suggested entry box for fields where it _thinks_ they’re part of a registration/login form. The issue that you’re describing sounds like the algorithm is a bit too broad and is activating in places where it should not.  
So yes, if you can, please share the (list) of websites that you’re having issues with privately via DM. Then I’ll investigate which part of the algorithm is triggering on that certain website and see if I can improve it and make it more robust. These kind of changes to the algorithm are very high-level, so if it works for one website it’ll work for all similar websites too. If I had to guess I think having +/- 50 different website variations in the test suite will make it work on 99.9% of all websites. So we’re already halfway there. The current challenge is more about finding those website variations, so all user feedback is very welcome. :slight_smile:

2. Gotcha, thanks for your insights. Leaving the option to the user how they want to handle disabled aliases is interesting. I’ll give this some thoughts on how this could work. And to answer your question on E2EE: yes the contents (from, body, headers, etc.) of all received emails on AliasVault aliases are fully end-to-end encrypted as soon as they’re received by the server. So they’re never stored in plain-text and no one can read the contents except you. The private key for decrypting email contents is automatically stored in your personal (encrypted) vault.

I’ll also look into Obtainium. I myself am a iOS user primarily, so I’m not super familiar with the full Android ecosystem. But I’ve had suggestions by other users for publishing the app to alternative app stores too such as Accrescent and F-Droid, so I’ll add this one to that list for further research as well. Thank you!

---

## Post 66 by @ihateKYC — 2025-05-22T17:00:36Z

Does iOS app save encrypted db to phone for self hosted vault? Or is it only accessible when logging in (with internet). Not sure if I’m wording this right.

---

## Post 67 by @lanedirt — 2025-05-23T08:55:04Z

Yes, once you log into the app for the first time, the encrypted database is saved locally on your iOS device in the app’s secure filesystem. The app also supports a basic offline mode where if you open the app while not having internet connectivity, it will still allow you to open the (cached) encrypted vault on your phone.

Also for security reasons, when the app is active, the vault is decrypted in memory only. Once you close the app or it goes into the background for longer than your configured auto-lock timeout (default is 1 hour, but you can change it to something shorter like 5 seconds), the decrypted data is automatically wiped from memory for security. When opening the app afterwards, it will ask you again for your biometrics or your password to decrypt your vault again.

So if I understand your question correctly: yes you can securely access your vault offline without internet after the first login.

---

## Post 68 by @anon57862721 — 2025-05-27T22:36:11Z

Hey

Sorry for the late response here. I did not forget but I wanted to think on this more and continue testing ALiasVault in some other ways before I gave you more of my opinions and share my experience.

So, following up from your comment.

1. I’m torn here. It’s literally every website field with a text box I am coming across is what the extension is prompting on. I started making a list but it became too much to keep adding. So, I’ll soon share (privately) what I can and make of it what you want to but I assure you, it is every website and field/text box where I am seeing this. My suggestion here is to make the changes on your code end such that it doesn’t auto pop up on any text field or drop down but only activates if you mouse click on the field. I think this would mitigate and bypass the issue instead of you altering the algorithm and we manually try to make it work as well as we want it to. What do you think? I am not technical so I don’t know if this is possible but I am hoping. Please met me know.

–

More feedback and FYIs:

1. The autofill works wonderfully! And every time. Its not instant but its quick enough. For a beta product, this is nice to see and is what makes it actually usable.
2. The generate new/add new alias on a new account creation page and the auto fill for all options available works really well too. Its actually faster for me to make aliases and accounts with AliasVault than it is with Proton Pass. This adds to my satisfaction of using the tool thus far.
3. As mentioned in another comment in another thread, I do want you to improve the email part of the product as well. I reiterate what I said earlier and feel compelled to say it again because I have noticed in new ways why and how this will be useful. Being able to better view and filter emails on the website atleast (but within the extension itself would also be a nice to have improvement) such that the email text/other elements renders well and fully so its easy to read and follow the email content. The viewing box of the email should not be small and tight is what I mean. The way I see using AliasVault is - for many of the accounts I have, I do want their emails but I don’t want them to clutter my main personal/Proton inbox. So this means, I can always open AliasVault and view the emails I want for the accounts I want whenever I want or whenever I need to see any of the key emails I get with codes or confirmation emails/etc. Hope this makes sense.
4. The extension stopped working today for an hour for some reason. I had to disable it and re-enable it after trouble shooting because it logged me out and would refuse to accept my master password. It did open on the web which was odd. This freaked me out a bit and made me worried. I have since made an export but please see to the reliability on your end if there’s an issue.
5. The inability to edit anything and everything that one should ideally be able to in the extension pop up in the browser is still killing me. I know its on the way after the Android release (hopefully next week or so?) and I am impatiently waiting for it. Being able to make the same extension pop up larger in size (by dragging and extending the pop up window while still connected to the extension icon that appears on the top right is also a much needed UI/UX improvement. I only reiterate to drive in the importance of this to me (and I’m sure others too when they begin to use it).

–

That’s it for now. Will write back with more as and when I have more to say. And please let me know if there’s anything unclear with my exposition above. Thanks! I look forward to trying out the Android app when you release it soon.

---

## Post 69 by @anon57862721 — 2025-05-28T17:18:09Z

@lanedirt

Hey, a couple more things I noticed yesterday after I posted my last comment I think you ought to know:

1. The iOS app is not recognizing email for account pages on websites that has email and password or username and password. In other words, if an account page has “email” and “password” - ALiasVault will only fill out “email” and “password” even if I have “username” as a separate name or don’t. What would work I feel is, if a website has “username”, AliasVault should accurately identity “username” and fill in username from the account details. If username is not present, then it should default to “email” directly and automatically as for the username on the website. For example: you can test this out on [letterboxd.com](http://letterboxd.com) (if you want to text out and see what I mean).
2. I’m starting to feel the pain of not being able to autofill credit card credentials and other details when online shopping. I hope this is already on your rador for improvements? (TBH, I am not following your GitHub yet so I mention this explicitly here)

Thanks again!

I don’t think I’ll have more notes for you until some more updates and improvements are released for me to try. I’ll be in touch. And as always, please let me know if of any follow up questions.

---

## Post 70 by @lanedirt — 2025-06-01T09:31:55Z

:rocket: **AliasVault 0.18.0 and Android app available!**  
Hey everyone, I’m super happy to share that after continued crunch time during the last 2,5 weeks, release 0.18.0 is now also available, and with it AliasVault for Android!

Also proud to share: yesterday (31st of May 2025) when 0.18.0 was released, it was exactly 1 year, 365 days, since I made the first commit for AliasVault. I’m proud on everything that was accomplished in the last 12 months, and very positive towards the next. :slight_smile:

Download link to Google Play: [AliasVault for Android](https://play.google.com/store/apps/details?id=net.aliasvault.app).

The APK is also available for download in the GitHub release assets for manual installation: [Release 0.18.0 · lanedirt/AliasVault · GitHub](https://github.com/lanedirt/AliasVault/releases/tag/0.18.0)

I’ll look into publishing the AliasVault app on alternative Android app stores too such as F-droid and Accrescent in the coming days.

 ![Android app preview](//forum-uploads.privacyguidesusercontent.com/original/2X/0/0807c1076426d24d04c3ea9fa16176db3f65eff0.jpeg)

Here are the full release notes for this new release:

> AliasVault 0.18.0:
> 
> 1. **Native Android App Launch!** : release 0.18.0 launches the **official AliasVault native Android app** , now available on the [Google Play Store](https://play.google.com/store/apps/details?id=net.aliasvault.app)! :tada: This release marks a major milestone, as AliasVault is now available on all major platforms: web, browser extension and mobile (iOS + Android). This new app enables native autofill features for Android and protects your vault contents with on-device biometrics.
> 2. **Quality-of-life improvements** : various smaller improvements to e.g. the browser extension which should make the autofill popup now trigger only on login related fields and get less in the way. Also fixes across all platforms to prevent UI overflow for credential details, and extra admin panel options.

Read more about this release on the AliasVault blog: [AliasVault 0.18.0 Released | AliasVault](https://www.aliasvault.net/news/aliasvault-0.18.0-released)

@anon57862721 I’ve also looked into your feedback and did some testing on my end for (quick) improvements for the browser extension on e.g. the OnlyOffice website which you mentioned. I have now updated the browser extension logic so it should trigger the autofill popup only on login related (username/email/password) fields. I tested it on various websites and I think this makes for a more correct default setting. I plan to be able to include your other suggestions regarding editing in the browser extension, improving email features etc. in the next release.

–

Now that AliasVault is finally available on all major platforms, the focus for the coming months will be shifted towards improving general usability and password management features across the board, as I’m going to work towards the v1.0 stable release.

I would appreciate it if Android users here could give the new AliasVault app a test drive and let me know what you think :slight_smile:. There might be a few issues that I’ve missed as there are a lot of Android devices and different biometric feature sets across the board between brands. But any issues that might pop-up, I’ll look into and try get them fixed asap.

---

## Post 71 by @anon57862721 — 2025-06-01T14:47:05Z

Yay!!

Will keep testing and trying in the coming weeks and will get back as and when I have substantial feedback on the same.

Thank you for taking my advice/suggestions/improvement requests seriously and delivering on it. I continue to look forward to extension improvements as it is likely the most used version of AliasVault even compared to mobile apps.

---

## Post 73 by @anonymous261 — 2025-06-06T00:30:43Z

Quick question: would there be anything that would prevent AliasVault from theoretically using the AGPLv3 in a quasi-proprietary way, as stated below?

> [@Introducing SoftwareCompare: Objective data to find software that fits your needs!](https://discuss.privacyguides.net/t/introducing-softwarecompare-objective-data-to-find-software-that-fits-your-needs/21520/22):
>
> (I’m not a lawyer and this is not legal advice) could be interpreted by some as committed to protect a free philosophy in their product. That would be a misinterpretation. Copyleft and permissive licenses are both foss and both permit users the same freedoms required under FOSS definitions. slight_smile Also, the AGPLv3 in particular, while still FOSS, can be used in a quasi-proprietary way in practice. [https://keygen.sh/blog/weaponized-open-source/](https://keygen.sh/blog/weaponized-open-source/) But I feel that a copyleft license co…

---

## Post 74 by @lanedirt — 2025-06-06T09:35:49Z

Thanks for the question! The primary reason I switched AliasVault from MIT to AGPLv3 is to prevent commercial entities from profiting off it without giving anything back. To prevent for example what happened with Elasticsearch and Amazon.

As far as I’ve seen, AGPLv3 has also become somewhat of a standard among similar tools. I’m not a lawyer, but after reading about how permissive licenses like MIT can be abused, it felt like the right thing to do at this point.

My goal is to keep AliasVault as open as possible. As long as people share their improvements, even if they build a business around it, everyone benefits. The AGPLv3, as far as I’m aware, helps keep it fair for everyone.

---

## Post 75 by @anonymous261 — 2025-06-06T16:27:31Z

> [@lanedirt](#):
>
> The AGPLv3, as far as I’m aware, helps keep it fair for everyone.

The quote I previously linked highlights how the AGPLv3 with a CLA specifically, is frequently used in an unfair way. It also mentions how AliasVault has both of these, and could potentially easily turn unfair.

---

## Post 76 by @lanedirt — 2025-06-06T17:06:39Z

Yes I did add a Contributor License Agreement (CLA) template to the AliasVault GitHub after switching to AGPLv3, but I don’t believe it’s the type being criticized in that article (?).

The CLA is there to ensure outside contributors have the rights to the code they submit. For example, that it’s original work and not copied from another project with a different license which could get AliasVault in trouble. So by agreeing to the CLA they state that their contributions can be included under AliasVault’s AGPLv3 license. It also explicitly states that all contributions remain under AGPLv3 (or any later version of the same license family).

Having said this, it’s mostly theoretical at this point. There haven’t been any significant outside community contributions yet in terms of code, aside from small fixes like typos. I’m open to reviewing or adjusting the CLA if there’s a better approach. But for now, it’s just a standard placeholder I copied from an existing template.

---

## Post 77 by @anonymous261 — 2025-06-06T22:22:10Z

The CLA goes as follows:

> You grant the Project maintainers a perpetual, worldwide, non-exclusive, royalty-free license to use, modify, distribute, and sublicense your contribution as part of the Project and any derivative works.

Maybe you could change the CLA to limit the sublicensing to somehow only be AGPL and other copyleft licenses?

---

## Post 78 by @anon7592771 — 2025-06-07T08:50:08Z

When I try to access [Log in to your vault](https://app.aliasvault.net/user/login), it takes quite a while for the login page to appear. Specifically, after I open the website, it takes about 3 minutes in Firefox and Chrome before the credentials login section is finally displayed. This delay happens every time I try to log in, and it feels unusually slow compared to most other websites.

I’m not sure if this issue is unique to me or if other people are experiencing the same slow loading times on this site. If anyone else has faced similar problems, I’d be interested to hear about your experience.

---

## Post 79 by @lanedirt — 2025-06-07T10:57:39Z

@anonymous261 Thanks for your input. I’m going to read up more on this to better understand the implications and what the best approach would be. I do think it would be great for AliasVault to set a strong example of openness. From quick research into large competitors, I can see that Bitwarden follows the same AGPLv3+CLA model (with additional custom Bitwarden license), while Proton Pass has actually closed-sourced it’s server side, and 1Password is entirely closed-source so there are different strategies (while all of these are recommended by PrivacyGuides). I’m going to read up on this some more, review the current license and CLA and update them if needed so it matches with AliasVault’s vision. If you or anyone else have thoughts about what you think would be a good model for AliasVault when compared to other password manager solutions out there, please feel free to share!

–

@anon7592771 Thanks for your comment! Yes a delay can be expected when opening the web app (for the first time), however 3 minutes is quite drastic.

The AliasVault web app is built using somewhat new/exotic .NET WebAssembly technology, making it run .NET code entirely in your browser. This is required for making E2E encryption work. WebAssembly comes with upsides, but also comes with some downsides, where one of them is that it requires a kinda hefty download (in the order of multiple megabytes) for the first load.

Load speed is therefore dependent on your internet connection and also your device’s CPU for compilation. E.g. on my Macbook Pro M4 it loads within 2 seconds, but on a slower Android phone it can take around 6-10 seconds. Could you perhaps share your device specs and/or avg. internet speed?

Honestly, if I could go back in time and create the web client from scratch, I probably wouldn’t choose WebAssembly again because of the slow load times. Improvements to download sizes and load speeds are promised though by Microsoft in upcoming versions of .NET, so hopefully it will get better as-is too.

---

## Post 80 by @anon7592771 — 2025-06-07T17:38:52Z

I’m attaching some screenshots of the page load time on my end.

[First try](https://img.adminforge.de/OW2jEJjr/Z7AImv3d.png)

 ![1](//forum-uploads.privacyguidesusercontent.com/original/2X/2/20fc45e1c3fa508daa6bb1310abcf60c41336c4f.png)

[Second try](https://img.adminforge.de/ErCUxJFd/im9pFyvR.png)

 ![2](//forum-uploads.privacyguidesusercontent.com/original/2X/d/dd90549fa07f0f29c6bccede349e188391e06eab.png)

---

## Post 81 by @anon52856436 — 2025-06-07T22:48:13Z

I’ve tried the Android app for a bit, and I’m impressed! I have a couple suggestions:

- I would appreciate the option to group emails received per alias, like one email folder per alias.
- The default (and unchangable) user icon appears to be the old AliasVault logo, and I like the new AliasVault logo much better. I would prefer it if you could change the user icon to different colors of the new AliasVault logo.

---

## Post 82 by @lanedirt — 2025-06-08T10:36:59Z

@anon7592771 Thanks for the screenshots. That indeed is very slow. How fast is your local internet connection? Also, normally, the loading of 33MB of files should only happen on the very first load. Refreshing the page afterwards should use the locally cached files.

For reference below screenshots when loading it via my Macbook Pro M4 and a 1-gigabit internet connection. Both with and without cache it loads within 1 sec for me, but of course that won’t be for all users with slower connections.

 ![First-time load, 33MB of data and finished in < 1sec](//forum-uploads.privacyguidesusercontent.com/original/2X/1/1af7bf77ba6c2f802fece0582d6ed79f45e0d489.png)

 ![Subsequent loads with cached data, 718KB of resources and finished in < 0.5sec](//forum-uploads.privacyguidesusercontent.com/original/2X/8/84f5097bdeaa1db507549c40ad65b2517292d738.png)

–

@anon52856436, thanks for trying out the Android app and sharing your feedback! I do hope to improve the email view across all clients in one of the next releases. I’ll look into how folders per alias could be integrated in this. Also good point around the user icon, it’s indeed a static one right now that I added as a placeholder. I’ll look into making this more dynamic too and making it part of the login flow as a better indication of what account you’re accessing. :slight_smile:

---

## Post 83 by @anon7592771 — 2025-06-09T10:09:59Z

Perhaps because my network connection is slower (100Mbps) and my location is distant from your server. However, at 100Mbps, 33 MB only takes roughly 3 seconds, or at most 60 seconds for numerous tiny files.

I really don’t understand why

---

## Post 84 by @lanedirt — 2025-06-17T13:42:15Z

Hi everyone, happy to share that the new version 0.19.0 has just been released and with it quite a few nice platform usability improvements. :smiling_face_with_three_hearts:

The stand-out new feature which was requested by multiple users (including @anon57862721) is that the browser extension is now capable of full vault mutation, this means you can now easily create and edit credentials right in the browser without needing to login to the web app.

This release also contains various other usability tweaks to the web app and mobile apps which were requested by readers here and on Discord. :slight_smile:

 ![0.19.0: browser extension now supports full vault edit capabilities](//forum-uploads.privacyguidesusercontent.com/original/2X/c/c6afbc6233a21327c5786ffb63ec6aee581adb04.jpeg)

> AliasVault 0.19.0
> 
> 1. **Browser extension mutation capabilities** : The browser extension now supports full vault mutation: create, update, and delete credentials directly in the extension UI. This feature, backported from the iOS and Android apps, removes the need to log into the web app for everyday credential management, making the browser extension significantly more powerful and independent.
> 2. **Quality-of-life improvements** : various improvements across the platform, such as adding long-press support for quick actions to the mobile app, improved loading animations in the web app, update app icons for better contrast, and more.
> 3. **Security enhancements** : This updates enforces new HTTP security headers in the nginx reverse proxy docker image to improve out-of-the-box hardening for self-hosted users.

Read the full release notes on the AliasVault blog: [AliasVault 0.19.0 Released | AliasVault](https://www.aliasvault.net/news/aliasvault-0.19.0-released)

The coming releases will focus on better on-boarding for new users, improved email interface capabilities, and datamodel improvements to make AliasVault more flexible in terms of the types of data it can store and autofill (including Passkey support).

Thanks again to everyone for trying out AliasVault and for your suggestions on how to improve it even further!

---

## Post 85 by @anon57862721 — 2025-06-17T16:11:44Z

Hey!

A few more things I’ve been meaning to update you on but I was waiting for a new update before doing that hoping they’d be fixed. But having tested this new updated a bit this morning, here are some more existing issues that I feel require an immediate fix (as it is more closely related to the fixes and improvements you have just made and are currently making, so I hope you can prioritize this).

1. When within an account on the extension and you’re editing/copying details, I want the extension to remain open on that page/account in the same state as I leave it after I copy and go elsewhere to paste things. I don’t the extension to “close” and force me to find the account again and go back to the same state I had it in when doing whatever account management I need to do. Persistent state of the extension is what I need. Hope all that makes sense. I’m not sure what the right phrase or word to use here is.
2. I still cannot view my TOTP seed token/code in the extension when I want to edit any account details. Why? It makes little to no sense for me/anyone to not have access to their seed token. Please see to this and ensure one can edit, add, manage TOTP/2FA seed codes within the extension as it is on Proton Pass/1Password/Bitwarden. This inability actually annoyed me a lot a week ago. I had to manually manage with so many clicks on the web version and even then the way it was set up did not make sense from a usability POV. Hope you see and understand what and how I mean.
3. Thanks for adding a notes section within each account. However, it’s implementation is perplexing. When editing, the notes appear at the bottom of the page to add any notes. But when you do and save, it appears on top of all other account details. ?? I’m confused why this is. I feel it should still appear at the bottom where it was showing when editing. It going from the very bottom to the very top is a weird design choice if you ask me. Please rethink on this.
4. There are a few more improvements that are missing but I’m guessing you surely do have it noted on your end to make happen so I wont repeat them again but only to let you know to also focus on email viewing/management part of AliasVault on/with/through the extension AND on the web version. This would make actually using email aliasing (and not just password management) with AliasVault more worth it.

Thank you for the update! I have already noticed some of the tiny improvements being made (that I did not explicitly mention) and the extension also feels a little more stable.

As always, let me know if you have follow up questions from any of the aforementioned. Thanks again.

---

## Post 86 by @lanedirt — 2025-06-19T08:01:58Z

Hi @anon57862721, thanks for your continued testing, I really appreciate it!

I released bugfix version 0.19.1 yesterday which addresses a few minor bugs, and also adds improved functionality for points #1 and #3 you mentioned:

- The browser extension now remembers the last page you were visiting before it closes, and will automatically go back to that page when the browser extension reopens (within a certain time). It now also remembers form edits in progress for credential creation and editing. So this should make it a lot easier for multiple copy/pastes during data entry.
- Notes section in browser extension and mobile app is now shown on bottom in view mode, to match the edit mode.

For your last point, yes I have noted all issues that have been reported before (including email management improvements). Some of these require additional changes to other systems before they can be fully implemented. Therefore each of the next releases will group related changes together so they can all be addressed and tested properly.

There’s still plenty of work to do, but I do think it’s exciting to see how much progress has already been made in the last few months, and many more progress will be made in the coming weeks/months. :slight_smile: So thanks again for your persistence in using and testing AliasVault, great suggestions that really help shape AliasVault and makes it better for everyone!

---

## Post 87 by @anon57862721 — 2025-06-19T18:55:33Z

Thank you so much for getting back. I truly do appreciate the improvements. I should have explicitly mentioned that in my last comment. And I’m glad to see AliasVault improve as much and as quickly it is which underscores your efforts for the same.

I’ll keep testing as you keep improving and will get back when I have more substantial things to talk about. Thank you again.

---

## Post 88 by @anon7592771 — 2025-06-20T04:19:33Z

I keep my AliasVault (_AV for short_) credentials in KeePass. But right now, in order to log in to AV, I have to copy both my username and password (for example, UUU—PPP), paste them into the AV username field (_UUU—PPP_), and then cut/paste the password (_PPP_), then delete ‘—’ (without ’ ') from username field to put them into the AV password field. This is not a good security measure.

I think a good number of people use password managers for this as well.

Can you allow AV open in a new window? You can check this [https://community.bitwarden.com/uploads/default/original/3X/7/8/78b813dd74283290db9c3e7077804dae4c5fae82.png](https://community.bitwarden.com/uploads/default/original/3X/7/8/78b813dd74283290db9c3e7077804dae4c5fae82.png)

Thank you.

---

## Post 89 by @iluvprivacy — 2025-06-20T04:52:52Z

I’m sorry, but I don’t understand the point of this tool. Why would I need it if I already have SimpleLogin and Bitwarden?

---

## Post 90 by @anon57862721 — 2025-06-20T05:05:02Z

Because this tool is offering what that combination is offering all in one tool. Also, more options are always a good thing and we need competition in the privacy space with similar and different tools.

Also, the way you say it implies that you’re following a faulty logic to say the least. It’s like asking, why do I need to eat different kinds of food when one kind of food exists. Silly, no?

---

## Post 91 by @lanedirt — 2025-06-21T12:48:06Z

Hi @anon7592771,

Thanks for your suggestion. I assume you’re talking about the browser extension for the login process, correct? Assuming you do, I agree it’s a good idea to add an “open in new tab” button to the login page. This button already exists for the credential and email detail pages to “pop out” the extension. But having it on the login page too so autofilling multiple fields from a different password manager makes sense. I’ll include this in the next release. :slight_smile:

---

## Post 92 by @RoyalOughtness — 2025-06-24T07:18:45Z

You may find this article interesting as it covers the issues with Copyleft+CLA: [Redirecting to: /concerns/copyleft-cla](https://isitreallyfoss.com/issues/copyleft-cla/)

It’s arguably worse than being closed source in some ways, because it creates a significant power imbalance with the illusion of openness. Closed source on the other hand is at least upfront about the power imbalance and makes no illusions.

Copyleft without a CLA on the other hand is a much more balanced playing field. The project owners must abide by the terms of the license (say the AGPL) for external contributions, and reciprocally, external contributors must abide by the terms of the license for contributions from the project owners.

---

## Post 93 by @lanedirt — 2025-06-24T09:19:28Z

Hi @RoyalOughtness and @anonymous261, thanks for your feedback and suggestions regarding AliasVault’s open-source license and use of a CLA (Contributor License Agreement).

I did some more reading on this topic, and agree with the sentiment that a CLA sends the wrong message and can create power imbalances. I have now updated the [CONTRIBUTING.md](https://github.com/lanedirt/AliasVault/blob/006f89b6b7bc849895b84a306f8ba2002c6e4cf6/CONTRIBUTING.md) to remove the CLA template entirely and clarify that no CLA is required for AliasVault contributions:

> License and Contributions  
> AliasVault is licensed under the GNU Affero General Public License v3.0 (AGPLv3). By submitting code, documentation, or other contributions to this project, you agree that:
> 
> 1. Your contribution will be licensed under the same AGPLv3 license as the project
> 2. You have the legal right to grant this license (e.g., you are the author, or have permission)
> 3. You understand that your contribution will be made public under the AGPLv3 terms
> 4. You are not expected to provide support or warranties for your contribution
> 
> :white_check_mark: There is no Contributor License Agreement (CLA) required. We believe in a balanced open source model where all contributors are treated equally under the terms of the AGPLv3.

By using **AGPLv3 without a CLA** , AliasVault remains fully open and fair for everyone: all contributors (including myself) are equally bound to share any changes under the same license, ensuring true software freedom and transparency.

I’m proud to say that with this, **AliasVault is one of the only fully open-source password managers** (both client and server) that is 100% licensed under **AGPLv3** with **no CLA strings attached**.

Unlike:

- **Bitwarden** – AGPLv3 but with a CLA
- **Vaultwarden** – no CLA, but only server-side; Bitwarden’s clients are still required which are under their own CLA
- **Proton Pass** – open source client apps, but closed source server
- **1Password** – fully closed source

I’m committed to position AliasVault as a genuinely open, transparent, and user-respecting alternative and to set an example going forward. Thanks again for the feedback!

---

## Post 94 by @mangomango — 2025-06-25T22:05:51Z

Hey ! First of all thank you for working on this project ! Still did not try it but if I understood correctly it brings something new to other PM (aliases integrated with password manager).  
Edit: verified and yes Bitwarden can create aliases through others services’ APIs but yours wholly integrates both ! :+1:

> [@lanedirt](#):
>
> I hope to receive a response within the next 2–3 weeks after which I can give a full update on this.

Do you have updates on this ?

I think this is the only hard requirement AliasVault does not fulfil before we start considering it.

Best regards

---

## Post 95 by @mangomango — 2025-06-25T22:10:45Z

Also : what will happen to AliasVault if you can’t keep working on it tomorrow ? You seem to be the only person running AliasVault (the hosted version)

Another comment : Thrilling, love that after showing AV’s strenghts compared to SimpleLogin, you also point out two weaknesses of AV compared to SL. GOAT. Love this.

Oops : I was about to try your service but I saw that AliasVault aliases can’t be used to reply or send emails… This is a serious issue for me.

I see that you plan to add phone numbers aliases. Can you precise wdym ? One-time phone numbers or phone numbers rentals ? Would it be similar to [SMSPool.net](http://SMSPool.net) ? To say the least, this type of business doesn’t run itself and you seem alone on AliasVault. So if you plan to do email aliases, phone number aliases, password manager, password generator, identity generator, … won’t it be too much ?

This would be like combining [strongphrases.net](http://strongphrases.net), [Addy.io](http://Addy.io), Bitwarden ans SMSPool.:sweat_smile: Alone.

---

## Post 96 by @lanedirt — 2025-06-26T10:18:17Z

Hi @mangomango,

Thanks for your questions and your interest in AliasVault! You asked multiple questions, so let me try and address your points one by one:

**1. Security audit update**  
Yes a few weeks ago I mentioned I’d be able to share an update soon. In the meantime I did receive feedback: and unfortunately, AliasVault was not selected for the grant that would’ve funded the audit. That said, my goal is still to have a proper third-party security audit completed before v1.0 is released (planned for end of this year). The main challenge now is funding, and I’m actively exploring alternative ways to secure that. I’ve already reached out to several other parties so I hope something will come out of that.

**2. Email reply/send support**  
Yes, replying or sending emails via AliasVault aliases isn’t possible yet. This feature is however on the roadmap for v1.0 and will be implemented in the coming weeks/months. Email sending and delivery is quite delicate though, especially for self-hosting in terms of IP reputation, so this requires some more attention for how it can be properly introduced.

**3. Phone number aliases**  
This feature is still in the concept phase. I see value in both one-time/burner numbers (e.g. for account verifications) and longer-term, privacy-friendly number rentals/reservations. It could end up similar to services like SMSPool, but whether this becomes a tightly integrated AliasVault feature or a separate service is still under consideration. Various countries have different rules about anonymous phone numbers, so that may also affect regional availability. I’ll be coming back on this.

**4. Solo vs. big team**  
AliasVault is indeed run by myself for now. Sustainability is a fair concern, but it’s worth remembering that many popular services from big companies have been abandoned too. For examples in the email/domain space, think of Google Inbox, Google Domains, Firefox Send, etc. The size of a team or company isn’t a guarantee of longevity. In fact, VC backed companies might be forced to shut down or pivot if their product isn’t showing multi-digit growth YoY. Being smaller has it’s benefits allowing for more flexibility and fewer external pressures.

For context: my other free service [SpamOK](https://spamok.com), a temporary email platform, has been online and maintained for over 12 years already.

But for anyone that is concerned about long-term availability of a hosted service: that’s exactly why I decided to make AliasVault fully open-source and easy to self-host. Unlike some alternatives that either don’t offer self-hosting or make it unnecessarily complicated, AliasVault gives you full control and flexibility.

And as the project grows, or if like-minded people with the right skills who believe in its mission want to get involved, I would be very happy to bring them on board. But regardless, I’m staying focused and continuing to push AliasVault forward. :slight_smile:

---

## Post 97 by @anon7592771 — 2025-07-03T15:31:49Z

Hi @lanedirt

If you could include a Fill & Submit option, that would be fantastic. This saves us one click. And because many people dislike this, I propose making it optional.

I’m now utilizing RoboForm due of its excellent auto-fill and submit feature. Simply select the item you require, and it will automatically access the website and enter your credentials before clicking submit, log in, sign in, or something similar. You’re logged in with only one click.

Hope you take the time to consider this. Thanks.

---

## Post 98 by @anon57862721 — 2025-07-04T15:25:33Z

Hi again

Here’s another update from me from my experience using it thus far after the recent updates. These are my wishlist items so please fit them in your list of priorities as you work on improving the tool.

1. While AliasVault is now more than a MVP, I’m starting to feel the need to more and more want some polish all around - from a design POV and workflow POV. And while the new update did make it more “usable”, I still feel it lacks more stability with snappy actions and quick saves and faster opening of the web version.
2. I’m now really starting the feel the need for better email management. Atleast once if not twice I week I have the need to response to emails I receive but I can’t just yet. Please also focus on improving the email side of things. This primarily includes, better email management all around, replies via aliases, and custom names that one can set to each alias when you reply to the receiver sees that name. In other words, incorporate the features and functionality that Simplelogin has. Reverse aliasing would be fantastic too.
3. When within an account, you see a very short list of recent emails on that alias. I want the ability to expand and view all emails sent to that particular alias within account details page view itself. Right now, I have to go hunting for it manually in the main Email view which is annoying to say the least.

I think more and more of the smaller improvements and features are becoming a noticeable issue now - as I have been using it and if one is to continue only relying on AliasVault.

Please see to these as best and soon as you can. And get back should anything be unclear. Thanks again!

---

## Post 99 by @lanedirt — 2025-07-07T15:07:31Z

@anon7592771 Thanks for your suggestion. I’ll check how RoboForm has implemented this and look into if this could also work for AliasVault. I’ve added it to the list. :slight_smile:

@anon57862721 Thanks for testing the recent updates! Re:

1. I agree, some things might still be rough around the edges, but with every release things are improving, and I’m working as fast as I can to push improved features out. The slow loading of the web version on some clients is a known issue and, in hindsight, a downside of the used WebAssembly technology. Not that much that can be done at this time to improve this except a full rewrite (which can happen in the future, but will take quite some time). If you have any specific ideas or examples of where you feel the experience could be more polished (beyond what’s already on our roadmap), I’d love to hear them.
2. The replying to email feature will probably take a bit of time before this can be rolled out, as there are quite a lot of contingencies that need to be dealt with for it to work properly. I’m estimating this will become available near the v1.0 release later this year.
3. Being able to load more emails on the credentials page should be a quick fix and will indeed make it more useful, I’ll try and get that included with the next release! :+1:

–

Furthermore as a general update, last week **AliasVault version 0.20.0** has been released with the following updated features:

> 1. **LastPass and generic CSV import** : Added support to import credentials from LastPass password manager. Additionally a generic CSV import has been added which provides a template file, enabling bulk importing data from any third-party system into AliasVault.
> 2. **Email view improvements** : The email view in the web app has been improved for desktop (large) screens, which now adds a sidebar. This makes it easier to browser through received emails. The email page now also auto-refreshes when new emails have been received.
> 3. **Self-host improvements** : the `install.sh` script has been updated with automatic dependency checks, ensuring smoother installations and quicker detection of any issues in self-hosted environments. Also the official installation instructions have been updated to provide more details and troubleshooting steps.
> 4. **Misc tweaks** : Updated admin panel with more statistics and filter options. Add identity generator `gender` setting, allowing you to specify an explicit gender for newly generated aliases. Several smaller tweaks to browser extension and mobile apps.

I’ve also been working on publishing the AliasVault Android app on the F-Droid app store. It initially took some time to set up the repository to meet F-Droid’s requirements, but after some tinkering the submission was finally accepted two days ago. So I expect AliasVault to be available on F-Droid somewhere later this week and will update this thread once it’s published. :cowboy_hat_face:

---

## Post 100 by @anon7592771 — 2025-07-07T15:25:43Z

@lanedirt  
Thank you for noticing and adding this to the list. I’ve also discovered that the offer to launch browser extensions in new windows has been implemented in the latest release.

---

## Post 101 by @lanedirt — 2025-08-01T12:20:48Z

Hi everyone,

Happy to share that after lots of ongoing effort, AliasVault 0.21.0 is out now, and the updated browser extension & mobile apps are available in the stores!

 ![0](https://forum-uploads.privacyguidesusercontent.com/original/2X/a/a3904c91920db60ed58a6c200832e268d7557089.webp)

What’s new in version 0.21.0:

> 1. **Multilanguage** : All client apps (web app, browser extension, mobile app) are now fully multilingual, and AliasVault is now officially available in English and Dutch. Translations are managed via [Crowdin](https://crowdin.com/), and we’re looking for contributors to help add more languages like German, French, and Spanish and more. Want to help? Learn how and get in contact: [https://github.com/lanedirt/AliasVault/blob/e830b9c482ff6243e58a7bf44857d49fac59dba2/CONTRIBUTING.md](https://github.com/lanedirt/AliasVault/blob/main/CONTRIBUTING.md)
> 2. **Advanced password generator** : Advanced password generator options are now available in the browser extension and mobile apps. Now you can control the generated password length and complexity on-the-fly when creating a new credential through the apps.
> 3. **Attachment improvements** : You can now upload/download attachments via the browser extension and mobile apps. The mobile app also features a preview for images and text files, allowing you to securely view images from inside your encrypted vault without having to store them locally on your phone.
> 4. **Self-host improvements** : Added improved checks to self-host installation such as OS platform detections. Also fixed issues with false-positive warnings showing up in the logs, making troubleshooting when any local issues occur easier to do.
> 5. **Misc tweaks** : Improved credential search and filtering across all apps to make it easier to find the correct credentials. Add “load more” button to recent email blocks in all apps (thanks for the suggestion @anon57862721 !) Add more statistics to admin page. Add option to “reset” vault on import/export page in web app. Also fixed a number of reported bugs.

Additionally, I’m happy to share that the AliasVault Android app is now available on the F-droid store as well: [https://f-droid.org/packages/net.aliasvault.app/](https://f-droid.org/packages/net.aliasvault.app/ "https://f-droid.org/packages/net.aliasvault.app/") (new 0.21.0 release can take a few days before its published on F-Droid).

My aim for the next release is to update the core data model to support additional credential types such as identities, credit cards, and more. And also to lay the groundwork for introducing passkey support. And it goes without saying that there are lots of other (smaller) things on the roadmap and todo list as well that have been proposed by users, which will get looked at as well.

Thanks everyone for your ongoing support!

---

## Post 102 by @unseen — 2025-08-02T17:18:55Z

Hi! I just registered my Alias Vault today. I’m excited to explore it!

The first thing I tried is creating a new credential/alias for my Privacy Guides account, but the confirmation email just never arrives sadly, so I had to go back to using my other email address. Why could this possibly happen?

I have a few feedbacks after exploring the app:

1. The difference between private domains and public domains is such an important detail (everyone can access the emails sent to the addresses using the provided public domains as long as they know the address) that should be displayed and explained clearly in the General Settings instead of being buried under multiple clicks (+ New Alias \> Create via advanced mode \> Select Email Domain).

2. On iPhone, the service URL part should recognize URL without https:// or add it automatically. Sometimes, it’s more convenient to type the short and memorable URL there, like [facebook.com](http://facebook.com), than having to go back to the browser to copy the URL (or if I’m using an app, there won’t even be URL to copy). It could be simple for those who are familiar with computer to sense what’s wrong when the ‘Invalid URL format’ error shows up then try adding https://, but it could be frustrating for someone who’s not (my uncle, who I suggests him use this app for more security, for example).

3. On iPhone, in Add Credential \> Manual, the alias (email) domain is not there for the user to choose, so one would have to manually memorize and type the whole domain if I want to use Alias Vault’s alias service. That’s not so user-friendly in my opinion.

4. I really like the Generate Random Alias feature which generates even first name, last name, gender, birthdate for me. It would be even better if there’s an option to generate an username using a random word (similar to Bitwarden’s username generator).

Apart from that, I have a few questions:

1. Since your aliasing service doesn’t forward the emails to users’ real email addresses, but store the emails on your server, does that make you technically an email service provider (like Proton Mail, Tuta, Gmail)? If true, it means it’s possible you’re going to receive user data requests from the governments in the future once your service is big enough. How do you plan to deal with that?

2. This is just my guess, so please let me know if it’s correct or not. Although it is stated that everything is end-to-end encrypted, but due to the nature of email, an email sent to an user’s alias is unencrypted and can be read by Alias Vault when Alias Vault initially receive it on Alias Vault’s server. Alias Vault then encrypt the email for the user, after that, the email is encrypted at rest and Alias Vault cannot access it (zero-access encryption). As far as I know, Proton Mail and other email providers that claim “end-to-end encryption” all work like that. So does Alias Vault work the same way?

Finally, one thing I love about Alias Vault is it allows me to use multiple aliases per service, unlike SimpleLogin’s strict 1 alias per service (and they don’t even openly talk about that, just send warning after it happens and threaten to ban users or immediately ban users)

---

## Post 103 by @lanedirt — 2025-08-03T18:09:21Z

Hi @unseen,

Thanks a lot for trying out AliasVault and taking the time to write up your ideas and suggestions! I appreciate it a lot!

Re: email sent by PrivacyGuides not being received on aliases: I’m not sure why this doesn’t work for you. Some websites due utilize block lists where they classify “temp” or “alias” email addresses as “bad”, and therefore don’t send emails to them. I’m not sure if PrivacyGuides is doing this too. Currently all cloud aliases are using @aliasvault.net, I’ll add more domains later on (the software already supports it) to make them available to users and which should improve deliverability.

In response to your feedback:

1. Good point, will indeed be a good idea to add some more explanation on the settings page to explain the differences between private and public domains. The difference is already described in the installation docs for self-hosted use, but not for cloud-hosted users. I’ll add this to the list!

2. Makes sense too to prefill the https suffix or not require it to make adding new credentials quicker. Thanks for the suggestion, adding it to the list too.

3. +1, good to make this behavior in browser extension and mobile app the same as how the web app does it already with a domain chooser.

4. Glad you like it! Thanks for the suggestion, I’ll look into the random word input for if/how this could be integrated into AliasVault.

5. and 6) Yes AliasVault could indeed be technically classified as an email service provider due the built-in alias feature. You’re correct about how the encryption works. When AliasVault receives an email its in plain text (due to how SMTP works), however directly upon receiving the email contents are immediately encrypted in memory with the users public key (private key is part of the users encrypted vault itself), and then saved to the database. After this, no one can read the email contents except the user themselves. If governments or other official bodies would demand that AliasVault hand over certain data, then the full vault including email contents itself is safe as its unreadable how its stored.

I’ve (unfortunately) already had experience with government data requests through my other public email service SpamOK. For AliasVault, my core privacy principle is simple: I cannot disclose what I don’t have or what doesn’t exist. Since AliasVault is designed to maximize privacy and minimize stored user data and avoid unnecessary retention, even if requests come in, we aim to have nothing meaningful to hand over.

---

## Post 104 by @paulrudy — 2025-09-02T00:40:32Z

@lanedirt I’ve been following the updates to AliasVault and just wanted to say I’m happy to see that you [implemented changes](https://github.com/lanedirt/AliasVault/issues/1142) related to the [clickjacking](https://discuss.privacyguides.net/t/zero-day-clickjacking-vulnerabilities-in-major-password-managers/30278) vulnerabilities in various password managers that were recently disclosed.

Looking forward to there being enough momentum for AliasVault to be able to get a security audit in the future. I know it hasn’t been feasible just yet.

---

## Post 105 by @lanedirt — 2025-09-02T07:34:12Z

Hi everyone,

After a few more weeks of steady progress, I’m excited to announce that **AliasVault 0.22.0** is now live. This update brings new features, security improvements and other general improvements that make using AliasVault even easier day-to-day. I’m also happy to give you an update on the usage numbers so far, which are growing each month:

- 1.3k+ GitHub Stars
- 4k+ Cloud user registrations
- 20k+ Email aliases created (on cloud version)
- 14k+ Self-hosted downloads

**What’s new in version 0.22.0:**

 ![0.22.0](https://forum-uploads.privacyguidesusercontent.com/original/2X/8/86e3aee4fbeec156a990f1b8ff72c2df6bc3c72f.jpeg)

> - **Multilanguage** : AliasVault is now available in 6 languages (English, Dutch, German, Finnish, Italian, Simplified Chinese). This is thanks to our amazing community contributors on Crowdin. The translations are available across the web app, browser extension, and mobile apps. Want to help make AliasVault available in your native language? [Learn how here](https://github.com/lanedirt/AliasVault/blob/2b19d2790223aa303af54bbb917301f11ce77497/CONTRIBUTING.md).
> 
> - **Security** : Added clickjacking protections + automatic clipboard clearing across web, extension, and mobile.
> 
> - **Self-host:** New optional all-in-one Docker image, improved admin panel with username changes, better logs, and stats.
> 
> - **Usability:** Added Dropbox Passwords importer, improved KeePass CSV imports, new auto-lock options, better autofill detection, and alias domain chooser on iOS.
> 
> - **Improvements:** Service URL input more flexible, reorganized extension settings, updated UI styling, and better error messages for self-host users.

–

@paulrudy Thanks for staying up-to-date and noticing, the update with additional protection measures against clickjacking went live yesterday indeed :-).

For an update on the security audit: I have been continuing efforts to secure sponsorships for an external security audit as we’re approaching v1.0. Some of my earlier attempts a few months back didn’t succeed due to high demand in those programs, but I’ve reached out to more parties last week and plan to re-apply for certain grants in the coming weeks. The goal is still to have the audit done around the time v1.0 is ready. If anyone has suggestions for organizations or initiatives that are open to support open-source security projects like AliasVault, I’d be very interested to hear them.

–

Thanks also to @unseen for your feedback: 0.22.0 implements your suggestions: #1, #2 and #3 (clearer public vs private domain explanation, improved URL handling, and iOS/Android alias domain selector)

–

To everyone: your support and ideas keep driving AliasVault forward. Looking forward to hearing your thoughts on this release.

---

## Post 106 by @anon57862721 — 2025-09-02T07:49:30Z

Thanks for sharing the update. I just updated the add on. And while I have since moved back to Proton Pass after trying AliasVault for a month or two there (and sharing all my feedback and suggestions) - I continue to look forward to all improvements including to the ones still pending (though I am hoping they are coming soon).

---

## Post 107 by @btcenigma — 2025-09-08T03:27:37Z

Great project ! I would like a few features:

- Configuration to auto delete email after a time period like 7 or 14 days
- Does the chrome extension auto detect and fill up the activation codes received from the websites. That would be very cool cause lots of time is wasted on copy / pasting the activation code
- Login using passkey
- Shared accounts / team members - In small companies people do share SAAS product subscriptions like Zoom so this will be very useful. We need a way to remove ppl no longer in the company from access and also reset password sometimes

---

## Post 108 by @anon57862721 — 2025-09-08T07:21:10Z

> [@btcenigma](#):
>
> Does the chrome extension auto detect and fill up the activation codes received from the websites. That would be very cool cause lots of time is wasted on copy / pasting the activation code

Wouldn’t this mean AliasVault having full read access to your emails? And would this not be a privacy violation for you? Don’t think this would be a good idea.

---

## Post 109 by @btcenigma — 2025-09-08T07:49:37Z

It need not have read access. The chrome extension on client can detect the activation code after decrypting the email.

---

## Post 110 by @anon57862721 — 2025-09-08T07:51:23Z

I’ll let @lanedirt explain this. I’m still skeptical of the necessity of this feature.

---

## Post 111 by @lanedirt — 2025-09-08T08:36:52Z

@btcenigma Thanks for the suggestions and feedback, really valuable to hear what people would like to see!

- **Auto-delete emails:** At the moment, AliasVault stores emails indefinitely. For self-hosted setups, there are already admin options to auto-delete emails after X days (globally or per user). For the cloud hosted service, this could become more relevant once premium features with storage limits are introduced. I am curious though, in what cases would you personally want emails auto-deleted after a certain time if not technically necessary?

- **Passkey login:** This is already on the roadmap and will be added in the coming weeks.

- **Shared accounts / team members:** AliasVault is primarily focused on individuals and families rather than businesses, but sharing credentials between accounts (in family settings) may well become part of the family/team offering. This is also in part already included in the roadmap.

- **Activation code autofill:** This has come up before (see [GitHub issue #1049](https://github.com/aliasvault/aliasvault/issues/1049) for OTP codes). Technically, the browser extension (once the vault is unlocked) can decrypt email contents client-side and attempt to extract activation codes for autofill. The server would never see or process these codes, so nothing changes in the data model or privacy guarantees.

@anon57862721, you raised a valid point. Since all of this happens client-side, the server doesn’t gain access to email content. But I’d love to hear more about your concerns: is it the _principle_ of a password manager reading email content, even locally, that feels uncomfortable? Or more the risk of accidental overreach?

Personally, I could see it as a potentially useful and unique feature, especially for quick alias sign-ups. It would be kind of unique as other password managers with non-built in email aliases won’t be able to do this as easy. But whether it’s actually pleasant and wanted in terms of privacy is something I would like to learn from users here :slight_smile:

---

## Post 112 by @anon57862721 — 2025-09-08T08:45:09Z

> [@lanedirt](#):
>
> But I’d love to hear more about your concerns: is it the _principle_ of a password manager reading email content, even locally, that feels uncomfortable? Or more the risk of accidental overreach?

I think both. But it’s also me not knowing if this is even possible all while maintaining and privacy and security in the best way possible. Also, I wonder if this will actually work that well seeing how different services, providers, etc. have different ways they share their one time codes in their emails so the app should be able to recognize the right numbers/code for this to work, again, in the most privacy respecting manner. For example: sometimes a service will send more details than just the code like your IP address along with the requested code so the user can decide based on the IP address and the request for the code if the email is indeed legitimate. So.. it’s kinda all those things/factors.

But if made or done well, it will indeed be useful if it works well. I’m just not sure it will with all the variables in play.

---

## Post 113 by @lanedirt — 2025-09-18T08:14:05Z

Hi everyone,

The new **AliasVault 0.23.0** release is out now! This release makes the new all-in-one Docker image fully available, improves mobile apps with new backup and customization options, and brings a lot of UI and usability upgrades across all platforms. Plus, AliasVault has officially moved to its own GitHub organization!

Website: [https://www.aliasvault.net/](https://www.aliasvault.net/)  
GitHub: [GitHub - aliasvault/aliasvault: Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.](https://github.com/aliasvault/aliasvault)

**What’s new in version 0.23.0:**

 ![0.23.0](https://forum-uploads.privacyguidesusercontent.com/original/2X/0/04e3e6efea7d7eaf852c2066e3b2d59b3cbfa195.jpeg)

> - **All-in-one Docker Image** : The new all-in-one Docker image which was heavily requested by the selfhosted community, is now fully available. Perfect for NAS setups (QNAP, Synology), simple Docker/Docker Compose installs and for integrating with existing Docker hosts. You can find the updated install instructions here: [https://docs.aliasvault.net/installation/](https://docs.aliasvault.net/installation/ "https://docs.aliasvault.net/installation/").
> 
> - **New GitHub Organisation + OpenCollective:** AliasVault has migrated from _lanedirt/AliasVault_ to _aliasvault/aliasvault._ This affects selfhosted users as new Docker image releases are now published under the aliasvault organization. AliasVault is now also on OpenCollective: [AliasVault - Open Collective](https://opencollective.com/aliasvault) which enables ongoing support with transparent donations.
> 
> - **Mobile app upgrades:** Offline CSV export for backup, migration or emergency access. Works even when you don’t have a connection to the server. Configurable password generator (configure length, complexity, etc. right from the app). Improved touch & trackpad handling for smoother interactions.
> 
> - **UI & usability improvements:** Standardized font sizes in browser extension, added password visibility toggles to login forms. Improve email preview UI in browser extension to make better use of the available space. Added alphabetical sorting to credential dashboard in web app. Show app version on login page. Improve responsive design of admin panel for improved accessibility on mobile devices.

You can find the full changelog of this release here: [https://www.aliasvault.net/news/aliasvault-0.23.0-released](https://www.aliasvault.net/news/aliasvault-0.23.0-released "https://www.aliasvault.net/news/aliasvault-0.23.0-released")

—

Number one priority for next couple of weeks is to include the highly requested support for passkeys, as well as continue tweaking the app based on user feedback and working through the general backlog of improvements (which include many ideas suggested in this topic :grinning_face: ).

Thanks for your continued support! I’m really proud to see that the project keeps growing, with increasing visibility and increasing active user counts week over week!

---

## Post 114 by @nblke72 — 2025-10-20T17:35:14Z

@lanedirt it seems not possible to use Tor when trying to register? AT least not when Tor is used in medium/safest security mode?

Also - will it be possible to start conversations/emails from an alias?

---

## Post 115 by @lanedirt — 2025-10-20T17:51:05Z

Hi, thanks for trying out AliasVault! I have not tested registration via Tor, but I don’t know of any reason in particular why it wouldn’t work. The only thing is that the web app is built in WebAssembly and it requires a modern browser to run.

Do you get any specific error when using Tor with the settings you mention?

Functionality for replying to emails received on aliases will be added in one of the next releases. I’m currently busy on wrapping up the 0.24.0 release which will include support for long requested Passkeys. It’s already finished for browser extension and iOS app, currently doing latest touches for Android. Email reply features and other improvements will be looked at after this.

---

## Post 116 by @nblke72 — 2025-10-21T09:02:34Z

@lanedirt Thank you for your reply! I am very interested in your project and would love to help in any way by providing feedback.

Yes, the WebAssembly is what I meant. When you use Tor in medium/safer mode and try to register, you get the error:

> AliasVault requires WebAssembly, which this browser does not support. Try using a more modern browser that supports WebAssembly.

Great to hear that you will be adding the reply-to ability, but what I meant was that you can actually start an email conversation from an alias to someone you have neve had contact with before. A lot of times there are no contact forms to enter your alias, so the only way to start a conversation is by sending an email.

---

## Post 117 by @anon7592771 — 2025-10-21T14:42:20Z

Hi @lanedirt

I am currently experiencing the error shown in the screenshot. Some emails are encountering this error even though I have received emails through that address normally before.

[](https://img.adminforge.de/gallery#SriEMBri/x0wDYNLE.png,fFSJyBWQ/gTPdJmrU.png)[External Image](https://img.adminforge.de/gallery#SriEMBri/x0wDYNLE.png,fFSJyBWQ/gTPdJmrU.png "Image hosted on another site. Click to open in a new tab.")

–

[https://img.adminforge.de/fFSJyBWQ/gTPdJmrU.png](https://img.adminforge.de/fFSJyBWQ/gTPdJmrU.png)

–

 ![x0wDYNLE](https://forum-uploads.privacyguidesusercontent.com/original/2X/f/f95e088379c78685118b3be9bb055722e3583a75.png)

---

## Post 118 by @lanedirt — 2025-10-21T14:53:28Z

@nblke72 Yes sending emails from aliases (so initiating it yourself, without replying) will also be included in that same feature update. For that WebAssembly error, I’m guessing then this has to do with the security settings of the Tor browser itself where it might disable WebAssembly support (for whatever reason). Not much I can do for that unfortunately.

@anon7592771 That’s strange, thanks for reporting. That error does not seem familiar to me, but perhaps its a client side issue.

1. Are you on the cloud-hosted or self-hosted environment?
2. Which browser and OS do you use?
3. Does it happen for all email aliases, or just some? If only some, are they always the same, or does it look to be random?

---

## Post 119 by @anon7592771 — 2025-10-22T07:52:10Z

> [@lanedirt](#):
>
> - Are you on the cloud-hosted or self-hosted environment?

I use [https://aliasvault.net/](https://aliasvault.net/)

> [@lanedirt](#):
>
> - Which browser and OS do you use?

I use Brave, LibreWolf on Windows IoT 2021 LTSC

> [@lanedirt](#):
>
> - Does it happen for all email aliases, or just some? If only some, are they always the same, or does it look to be random?

Just some, always the same.

Temp solution: generate another email for those accounts which are effected can fix (not sure)

---

## Post 120 by @lanedirt — 2025-10-23T09:18:36Z

Hi @anon7592771, thanks for the additional details! I’ll try and reproduce this on my end and see if I can apply a fix for this. I’ve had some other reports about edge cases where the web app did not always render emails correctly, so I’ll try and make this mechanism more robust to prevent such errors.

Thanks for testing and reporting issues, much appreciated! :slight_smile:

---

## Post 121 by @Bumbashirovich — 2025-10-25T12:33:48Z

Hello, is it possible to disable (block) tracking pixels in the form of images and tracking links in emails, like it is done in Proton Mail, for example?

---

## Post 122 by @lanedirt — 2025-10-25T12:51:29Z

Hi @Bumbashirovich,

That’s a good idea, thanks for your suggestion. This could certainly be added in one the next releases! I have created an issue for this on the AliasVault GitHub: [[Feature Request] Block tracking pixels in received emails · Issue #1290 · aliasvault/aliasvault · GitHub](https://github.com/aliasvault/aliasvault/issues/1290) .

---

## Post 123 by @lanedirt — 2025-11-10T19:03:09Z

Hi everyone,

I’m happy to announce the new **AliasVault 0.24.0** release which is out now! This update introduces the long-awaited **passkey support** , expands **language options** , and includes new of **cross-platform improvements** for smoother everyday use. It also includes several important bug fixes and performance updates across all apps.

Website: [https://www.aliasvault.net/](https://www.aliasvault.net/)  
GitHub: [GitHub - aliasvault/aliasvault: Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.](https://github.com/aliasvault/aliasvault)

**What’s new in version 0.24.0:**

 ![0.24.0](https://forum-uploads.privacyguidesusercontent.com/original/2X/c/cd694eb8845ae7712b332278842a58a4c3cf08b2.jpeg)

> - **Passkey support (WebAuthn Level 2):** AliasVault now supports creating and logging in with **passkeys** on websites and apps. Passkeys are supported via the AliasVault browser extension, iOS app and Android app. Passkeys are safely stored in your encrypted vault and automatically synced across your devices. If you come across any bugs or issues when using passkeys, please get in contact via Discord, create a issue on GitHub or leave a reply here on PrivacyGuides.
> 
> - **New language options:** AliasVault is now available in **Brazilian Portuguese, Russian, and Polish,** making it a total of (11) languages so far! A warm thank you to our contributors on Crowdin! Do you want to help improve translations and/or make AliasVault available in your native language? Check out the AliasVault project on [Crowdin](https://crowdin.com/project/aliasvault/) and apply.
> 
> - **General improvements:** Implemented iOS app quick autofill support, showing suggested credentials right in the iOS keyboard. Improve Android app dark mode support. Explicit open vault in offline mode on mobile app if server takes too long to respond. Improved credential search logic. Added image zoom support for attachment previews on mobile. Improved UI for custom URL settings in browser extension.
> 
> - **Bugfixes:** Fix email decryption errors in web app. Improved autofill behavior in all apps. Fix Safari clipboard clear behavior. Fix handling of multiple private email domains in self-hosted instances. Update iOS 26 layout margins.

You can find the full changelog of this release here: [https://www.aliasvault.net/news/aliasvault-0.24.0-released](https://www.aliasvault.net/news/aliasvault-0.24.0-released)

Note: This release includes a _client vault model update_. After upgrading, your vault can only be opened by v0.24.0+ apps. So make sure you update the AliasVault app on all platforms. And if self-hosting, make sure to update your server too. Instructions for how to upgrade a self-hosted server can be found in the docs: [https://docs.aliasvault.net](https://docs.aliasvault.net)

—

The next release(s) will focus on usability and datamodel improvements like PIN unlock, custom fields and to support more credential types like identities, addresses, creditcards etc.

–

@anon7592771 the email decryption issue you reported should now be 100% solved with this update.

If anyone has any questions or runs into any issues, feel free to let me know and I’ll happily look into it! Thanks for your continued support and feedback!

---

## Post 124 by @anon7592771 — 2025-11-11T04:00:27Z

That’s great to hear. I check your GitHub almost every day, hoping for a new version. I’ll try this.

---

## Post 125 by @anon57862721 — 2025-11-11T14:33:56Z

@lanedirt

Excellent news and update. It’s been several months since I’ve used Aliasvault fully so I’m starting again now and will get back with feedback like I did earlier. So, stand by for that.

But a quick question for now - will there be a native app for desktop OSs for better credential and email management?

---

## Post 126 by @lanedirt — 2025-11-11T17:08:10Z

Hi @anon57862721, that’s great, I appreciate it a lot! As a FYI: larger improvements to the email interface you mentioned before are still pending, but will be looked at in one of the following releases as we’re nearing v1.0. :slight_smile:

> But a quick question for now - will there be a native app for desktop OSs for better credential and email management?

Native desktop apps are on the 1.0 roadmap for further consideration. There are quite a few benefits in having them, especially for better autofill in native apps, however it will also mean more maintenance. So I am still weighing the options on pros/cons on when would be feasible time to prioritize and start work on this. Do you have specific usecases that you use (other) password manager desktop apps for?

---

## Post 127 by @anon57862721 — 2025-11-11T17:56:22Z

Thanks for getting back and explaining.

> [@lanedirt](#):
>
> Do you have specific usecases that you use (other) password manager desktop apps for?

Well, when email management becomes better, then having the app makes it easier for everything and I imagine would be better than the website. But if the website and the native app can have the same functionality and feature sets, then the website should be enough. I guess it then depends on which version of Aliasvault is best to work work and view your info in to manage your data.

---

## Post 128 by @nblke72 — 2025-11-17T07:11:45Z

@lanedirt this has probably been suggested before but I would greatly appreciate the ability to sort/organize credentials, for example with tags.

---

## Post 129 by @lanedirt — 2025-11-19T11:11:23Z

Hi @nblke72 thanks for your suggestion. Yes organizing credentials with tags/folders, and more sorting options will be added in one of the next releases that focuses on the datamodel and usability improvements. It’s on the roadmap, so I expect this to be added in a month or so. :slight_smile:

---

## Post 130 by @nblke72 — 2025-11-20T06:51:30Z

@lanedirt thank you so much! Also, it would be great to have the option for emails to be displayed as plain text by default instead of HTML (security purpose).

---

## Post 131 by @anon57862721 — 2025-11-20T12:40:56Z

@lanedirt

So here is my feedback as I continue to test the new improvements and updates from months ago. I’ll have more feedback later but thought I’d let you know these right away as they feel easier to resolve.

1. Request: I need multiple service URL options for multiple links. Please add this.
2. Request: I need custom options that I can make with additional info within each account to add more details you may have related to the account. I don’t want to simply use the Notes section for this as I want the option for the text to be hidden.
3. Request: It would be nice to have the options for generating password to also include Latin characters and letters to make a password with overkill strength (similar to how Strongbox provides this option). This is not necessary but would be cool to see.
4. Issue: When trying to add software passkeys on iOS from a website directly, AliasVault app is not recognizing the credentials/account of the same website and is creating a new credential for passkey. This leads to duplicate listings of the same account. Please see to this.
5. Issue: I use a strong and long password as my master password. And on Android (Graphene OS) there isn’t an option to use a PIN code to quickly log in after your first initial sign in after the download. It would be nice to simply enter a 4 to 6 or custom PIN quickly to log in to copy what you want when trying to sign in to websites and apps. It’s annoying to enter the super long strong password every-time you enter the app. This is for me the biggest point of friction and is discouraging use of AliasVault on my GrapheneOS. Please see to this. This should be a request but is very annoying and hence is an issue to me.
6. Request: A niche request to have a “clean slate” option where if you enable it, your AliasVault account will be wiped clean with all credentials deleted permanently such that you have a brand new account. I would also like to have this wipe out log in history and whatnot with this option. I do have a use case for this but I’d rather not share. I don’t want to delete the entire account every time I want a clean slate.
7. Issue/Request: When signed in to the web app, it should sign you out after a period of inactivity. It currently does not. Please add this option in for enhanced security in case you leave your laptop/computer open.

For now, these are it. I await your improved email management as that’s the only major part that I feel is lacking AliasVault from becoming a lot more viable of an option for your credential management needs and as an app that that works with all the functionality and features you’d normally expect from such a service.

I will continue to test and will get back with more feedback. Thanks for all your improvements thus far - the app and extension is a lot more stable now from my last testing. And as always, let me know if any feedback is unclear.

---

## Post 132 by @lanedirt — 2025-11-21T05:27:51Z

Hi @anon57862721, awesome, thanks for trying out and testing the updated version of AliasVault again! I appreciate your time and getting back to me with your detailed feedback.

–

1 & 2: Both options are being worked on and will be included in the 0.26.0 release most likely as part of the (larger behind-the-scenes) datamodel change update.

3: Interesting, I’ll check how Strongbox does this and add this as a feature request to the GitHub backlog.

4: That’s a really good idea! Having the ability to manually merge passkey credentials with normal credentials has actually been requested a few days ago on Discord. But having the passkey flow detect any existing credentials and suggesting to save it there from the get-go would be even better. I’ll look into this!

5: I’m happy to say that PIN unlock support has been worked on for both browser extension and mobile app this past two weeks, and work on the feature was finalized yesterday. So this will be available very shortly and included in the next 0.25.0 release :slight_smile: .

6: In the web app when you go to Menu \> Import/Export and scroll down there already is an existing option for resetting your vault, without having to (re)create your account. Does this cover your usecase?

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/c/a/cae906eb10b21d94c35b60799ec5c5016c8d452f.png)

7: Good idea, I’ll add the auto-lock timeout feature to the web app too. It’s already available on the other platforms, makes sense to have it everywhere.

–

Email UI improvements are indeed still on the todo list, and will be looked at together with other requested email features like email forwarding, optional integration with existing mailservers etc. I’ll post an update here when there is more news to share on this front. :slight_smile:

---

## Post 133 by @anon57862721 — 2025-11-21T10:01:13Z

Thanks for letting me know the Reset Vault option. I had not seen it surprisingly. Or maybe didn’t remember this. Yes, this works for me!

---

## Post 134 by @herr — 2025-11-21T11:11:18Z

This seems like a great idea. I gave it a trial via the android App. Unfortunately, it didn’t work out as expected. Here’s why:

I created a Facebook account and a Twitter (sorry X) account. However neither of these accounts sent me the expected verification emails. Is it possible that Facebook and X are blocking aliasvaults emails to prevent anonymous signups?

---

## Post 135 by @anon57862721 — 2025-11-21T12:05:24Z

> [@herr](#):
>
> Is it possible that Facebook and X are blocking aliasvaults emails to prevent anonymous signups?

That is absolutely possible. But social media platforms are also notorious for shadow blocking access to their service with a VPN or other proxies so that could be another reason if you’re using a VPN.

---

## Post 136 by @EchoVerse_9292 — 2025-11-21T12:26:31Z

Never expected to see you on this forum. Nice to meet you. I have been using AliasVault since the last couple months and have been loving it a lot. This is my very first Alias service I have ever used and is working great!

---

## Post 137 by @lanedirt — 2025-11-21T12:42:44Z

Hi thanks for trying out AliasVault. I just tested it, for me creating a Facebook account works fine (from a mobile 5G connection). I just received the email confirm email in AliasVault. So perhaps it has something to do with other things like @anon57862721 suggested.

Of course there is always the chance that services may start blocking AliasVault domains in the future, but in case that happens structurally I’ll make more domains available to choose from.

---

## Post 138 by @lanedirt — 2025-11-21T12:44:06Z

Hi @EchoVerse_9292 that’s great to hear! I’m glad that you like it! How did you find out about AliasVault if I may ask? :smiley:

---

## Post 139 by @Robin1e — 2025-11-21T16:07:53Z

Thankyou for the android app.

Few things missing in the android app that [I think] have not been mentioned.

1. Generate passphrases.
2. No option to add 2FA TOTP. Available on web.
3. A toggle to bring the search bar to bottom. (Nice to have feature)  
[Settings \> Appearance \> …]
4. A toogle to “Block Screen Recording”, which also hides app-contents on recents page.  
[Settings \> Security \> …]
5. Option to block Auto-fill on some websites/applications  
[Settings \> Autofill \> …]
6. Option to automatically open search + keyboard when app is opened. (Nice to have feature)
7. Credentials directly get deleted. I think there needs to be a move-to-trash option.
8. When clicking on plus button it directly goes to Random, an option to select the default behavior to open Manual would be nice.
9. Some suggestions -  
i.) “Vault Unlock Method”, “Autolock Timeout”, “Clear Clipboard” and “above mentioned point 4.” could be moved under “Security” section.  
ii.) A new section named “Appearance” could be introduced at the very top which will include “Theme”, “above mentioned point 3.” along with “Language”.

Once again thankyou for this app.

---

## Post 140 by @herr — 2025-11-22T07:47:42Z

> [@anon57862721](#):
>
> That is absolutely possible. But social media platforms are also notorious for shadow blocking access to their service with a VPN or other proxies so that could be another reason if you’re using a VPN

I’m unsure how my VPN could block a signup process which is initiated and handled by AliasVault.

Am I missing something?

---

## Post 141 by @anon57862721 — 2025-11-22T07:59:18Z

Because the website also recognizes that you are using a VPN and they don’t like that you are using a VPN because they want your info from the get go of who and where you are.

---

## Post 142 by @nblke72 — 2025-11-22T08:09:35Z

@lanedirt not sure when the replying-from-alias function will be possible, but would you then also be able to reply to emails which you already received now? Or will this only be possible for emails that you received after this feature was added?

---

## Post 143 by @anon7592771 — 2025-11-22T14:01:37Z

@lanedirt It would be great if we could select multiple emails/credentials to delete at once.

---

## Post 144 by @lanedirt — 2025-11-24T10:45:21Z

@Robin1e

Thank you for using AliasVault and for your feedback and suggestions! That’s greatly appreciated!

For #2: I’m happy to say that 2FA TOTP management will be included in the next 0.25.0 release which I expect to publish later today or tomorrow.

I have took note of your other suggestions. I agree that adding appearance and usability customization would indeed be a powerful feature in the app. Some current defaults might not be the most convenient for everyone. I’ll look into these while preparing work for the (large) datamodel and UI improvements, where these kind of changes could also be included in.

–

@nblke72

> not sure when the replying-from-alias function will be possible, but would you then also be able to reply to emails which you already received now? Or will this only be possible for emails that you received after this feature was added?

Yes when the reply feature will be added, the goal is that it will work for all aliases that the user has, both existing and new ones.

–

@anon7592771

> It would be great if we could select multiple emails/credentials to delete at once.

I’ll look into this as part of the next release, thanks for your suggestion. :slight_smile:

---

## Post 145 by @anon57862721 — 2025-11-25T08:51:11Z

@lanedirt

A few more things:

1. Request/Issue: I want to be able to add my credit cards/other banking account details and whatnot. Please develop different account types to add the type of details you want. This will immediately become a tool for more than your account and alias management so I hope you have plans to get this included too. This also includes other types of info like how Proton Pass and 1Password has options for. But please get the banking account type added first (and quick if possible).
2. Request: Perhaps an option to make a completely custom account details page where you add everything - type of info, hidden or text, etc. Like a blank template where you make your own. This gives even more freedom to add any info you want.
3. Request: Different account type icons - different ones for logins, and other types of accounts you add to better visually separate the them. This is not necessary but is nice to have.
4. Issue: When logging into a new website, the extension is not auto recognizing that the credentials for the website don’t exist in the vault and is not prompting to add them. Please see to this.

These are what I have observed and thought about this week. Will keep testing and get back with more. Thanks again!

---

## Post 146 by @lanedirt — 2025-11-25T16:20:26Z

Hi @anon57862721, thanks for the additional feedback. I’ll look into the points mentioned!

For #1 as clarification: could you elaborate on your usecase for the banking account details. How should this work? In my home country The Netherlands most online payments happen through an online account with the bank, which in the end is just a username and password. Credit cards is clear to me in terms of autofill purposes, but how would banking account details need to work? Do you mean just the ability to store the data in a separate category, or also do you expect the autofill to recognize this?

---

## Post 147 by @lanedirt — 2025-11-25T16:25:36Z

Hi everyone,

I’m happy to announce the new **AliasVault 0.25.0** release which is out now! This release now allows you to login to the web app and browser extension using the AliasVault mobile app, which alleviates the requirement of entering your full master password every time you login on or want to unlock another device.

Furthermore this release adds **PIN unlock support** to the browser extension and the mobile app, adds **2FA management** directly in browser extension and mobile apps, and **identity generator enhancements** including age preference and German language support.

Website: [https://www.aliasvault.net/](https://www.aliasvault.net/)  
GitHub: [GitHub - aliasvault/aliasvault: Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.](https://github.com/aliasvault/aliasvault)

**What’s new in version 0.25.0:**

 ![0.25.0](https://forum-uploads.privacyguidesusercontent.com/original/3X/8/e/8e88f9eb02f5b069e2794141fa89b3f578a0a1de.jpeg)

> - **Login with mobile device:** You can now login to the web app and browser extension using your AliasVault mobile app. This new authentication method provides a secure and convenient way to access your vault without typing your master password on every device. Simply scan the QR code displayed on the web app or browser extension with your native smartphone camera or from within the AliasVault app. The login process is fully secure with end-to-end encrypted data exchange between your mobile device and browser
> 
> - **PIN unlock support:** This release adds **optional PIN unlock** to the browser extension and mobile apps, giving you more flexibility in how you access your vault. Ideal for users who cannot or prefer not to use biometric unlock on their mobile device, especially relevant when traveling to countries that are known to do searches.
> 
> - **2FA management in all apps:** By popular request from the community, you can now add and edit 2FA (TOTP) codes directly from the browser extension and mobile apps, making two-factor authentication management more convenient than ever.
> 
> - **Identity generator enhancements:** Set a preferred age range for generated birthdates, giving you more control over the identities you create. This is useful when you want the aliases that AliasVault generates to match a specific age requirements. Also added German language support to the identity generator (thanks to our community!).

You can find the full changelog of this release here: [https://www.aliasvault.net/news/aliasvault-0.25.0-released](https://www.aliasvault.net/news/aliasvault-0.25.0-released)

---

## Post 148 by @anon57862721 — 2025-11-25T16:30:36Z

Clarification:

Well, for online payments, auto recognition and auto-fill would be fantastic. But not a deal breaker as I can copy paste things just as well. For banking details, I just want to store these details safely. It’s not for any auto-fill purpose.

> [@lanedirt](#):
>
> Do you mean just the ability to store the data in a separate category

Yes

> [@lanedirt](#):
>
> or also do you expect the autofill to recognize this?

Not necessary

> [@lanedirt](#):
>
> I’m happy to announce the new **AliasVault 0.25.0** release which is out now!

Yay!

> [@lanedirt](#):
>
> **What’s new in version 0.24.0:**

Small typo.

–

Thanks again! I’ll update the app and continue testing.

---

## Post 149 by @EchoVerse_9292 — 2025-11-27T07:42:14Z

I discovered it on F-Droid. Back then, I just found out about Alias. So I was searching for which ones to use and which ones are the best among the free options and that’s when I discovered it on F-Droid. I discovered it by searching up “Alias" on F-Droid search bar.

---

## Post 150 by @nblke72 — 2025-12-05T11:24:04Z

@lanedirt I have noticed several emails not going through to aliasvault, even though the inital sign up process on the website/service works. What could be the cause?

---

## Post 151 by @lanedirt — 2025-12-05T14:56:25Z

Hi @nblke72, I am not seeing any issues with email deliverability in general for aliasvault, so it might have something to do with the specific service, i.e. they could be blocking the aliasvault domain.

Or it might be related to what JG mentioned earlier:

> But social media platforms are also notorious for shadow blocking access to their service with a VPN or other proxies so that could be another reason if you’re using a VPN

If the service you’re using is publically available, you can always share it with me in a PM and I’ll happily test if I can see if anything is being blocked.

---

## Post 152 by @nblke72 — 2025-12-07T15:39:21Z

@lanedirt I messaged you :slight_smile:

---

## Post 153 by @unseen — 2025-12-14T09:10:41Z

Hi! I’ve been using AliasVault web version and enjoy it a lot so far. Is there any way I can turn off the loading of remote content when I check the email? I’d like to prevent certain sites from knowing my IP address. My current workaround is to turn on VPN whenever I check emails on AliasVault, but it would be awesome if I can just turn off remote content completely.

---

## Post 154 by @anon57862721 — 2025-12-14T09:17:13Z

> [@unseen](#):
>
> My current workaround is to turn on VPN whenever I check emails

Is there a reason you can’t always have it on? That’s what I suggest doing unless its a deal breaker somehow for you.

---

## Post 155 by @unseen — 2025-12-14T09:58:11Z

> [@anon57862721](#):
>
> Is there a reason you can’t always have it on? That’s what I suggest doing unless its a deal breaker somehow for you.

Thanks for the suggestion, I think I can do that but I will need to tweak my current setup a bit, so the split tunneling and my different browsers/profiles work as I want. There are sites I use that will block me if I use VPN no matter what server choose. Or sites I would get into trouble if I use VPN, for example, I recently got flagged as spam and banned on reddit just because I use VPN, although the account is 10 years old and I rarely comment or post.

I still think being able to turn off remote content is going to be a huge plus for AliasVault, because not everybody can afford or is willing to pay for a paid VPN subscription to have split tunneling (it’s usually a premium feature in my experience).

---

## Post 156 by @lanedirt — 2025-12-14T15:50:02Z

> Is there any way I can turn off the loading of remote content when I check the email? I’d like to prevent certain sites from knowing my IP address.

Hi @unseen, thanks for using AliasVault, and happy to hear you are enjoying it!

Currently when opening emails they render in HTML, which indeed also loads any tracking pixels in case emails have them. A feature to configure whether to open emails by default in HTML or plain text mode has been asked before, and a issue exists for this on GitHub: [[Feature Request] Add default email formatting option to all client apps · Issue #1378 · aliasvault/aliasvault · GitHub](https://github.com/aliasvault/aliasvault/issues/1378)

So I’ll try and get the “open in plain text” (by default) option included in one of the next releases.

Currently a lot of work is being done on improving the core data model of AliasVault, which when finished will add support for multiple URLs, custom fields, field history, full offline mode including offline mutations in browser extension and mobile app, being able to recover deleted items and more. So it can take a few weeks before the next release is ready, but after that these feature requests will be looked at. :slight_smile:

---

## Post 157 by @lanedirt — 2025-12-23T15:56:36Z

Hi everyone :grinning_face: ,

Just in time before the end-of-year holidays, I wanted to share an update on AliasVault’s progress so far and what’s coming next.

**2024 in numbers:**

I’m very happy about the growth that AliasVault has seen this year, and am looking forward to 2026! This year:

- GitHub stars grew from under 50 in beginning of January to 1.8k+ now
- ~10k users on the cloud-hosted server
- 45k+ email aliases created
- 30k+ self-hosted downloads
- Monthly active users and self-hosted deployments continue to grow every month

**What’s coming next:**

A major update is in the works that includes significant architecture improvements. Here’s a preview:

 ![happy-holidays-datamodel-preview](https://forum-uploads.privacyguidesusercontent.com/original/3X/1/1/115e13fe2cc3336478cfc8e2b0b6124b99eca978.jpeg)

- Full offline mode with offline editing capabilities
- Folder organization for credentials
- Custom fields support
- Additional credential types
- Field-level history tracking
- Recently deleted items (trash/recovery)

You can find more details in the blog post I just published: [https://www.aliasvault.net/blog/upcoming-major-update](https://www.aliasvault.net/blog/upcoming-major-update)

Thanks to everyone who has tried AliasVault, provided feedback, or contributed. Wishing you all happy holidays!

---

## Post 158 by @lanedirt — 2026-02-02T10:30:21Z

Hi privacyguides,

After almost three months of continued hard work, I’m proud to announce the latest **AliasVault 0.26.0** release! This is one of the biggest releases yet with a **major architecture upgrade** that unlocks long-requested features by the community like **custom fields** , **folders** , **new item types** , **history tracking** , **recently deleted items** , and **true offline vault access and editing** with automatic vault merging. This new architecture will also allow us to more easily add new features in upcoming releases.

Alongside these major additions, this release includes security improvements, performance optimizations, and many community-requested fixes. And as a cherry on top: we also just yesterday crossed the mark of over 2.000 GitHub stars! :smiling_face_with_three_hearts:

Website: [https://www.aliasvault.net/](https://www.aliasvault.net/)  
GitHub: [GitHub - aliasvault/aliasvault: Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.](https://github.com/aliasvault/aliasvault)

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/d/0/d0d46b808056c2953ed0de60a6a5f352345502be.jpeg)

> - **New vault architecture** that now enables: item types, folder support, custom fields, field history tracking and recently deletd items
> - **Full offline mode** for the browser extension and mobile app: view and edit your vault completely offline, changes automatically sync when you are connected again
> - **New language options:** AliasVault is now available in a total of 14 languages thanks to our amazing community and contributors!
> - **Improved autofill accuracy** thanks to a new cross-platform Rust core library that makes sure autofill works the same on all platforms.
> - **And many more community requested tweaks, general security hardening and other bugfixes**

You can find the full changelog of this release here: [https://www.aliasvault.net/news/aliasvault-0.26.0-released](https://www.aliasvault.net/news/aliasvault-0.26.0-released). Happy to hear your thoughts and also happy to answer any questions!

---

## Post 159 by @PurpleDime — 2026-02-02T11:06:06Z

Just want to thank you for all the wonderful work that you do. :smiling_face_with_three_hearts: :smiling_face_with_three_hearts: :smiling_face_with_three_hearts:

Although I have been using AliasVault sporadically, it has been extremely useful to me when encountering websites that reject the domains of most aliasing services. I worry that, once your app becomes more popular, some of the websites I use with it will block it. Right now, I feel like I am part of a privileged secret club that gets to enjoy this gem, but I am sure that will change eventually because you’re doing good work. I just don’t want to see more websites block you.

**I remember reading you were working on the ability to send emails. Is that still planned? If yes, how do you intend to make it work when not email address are linked to our AliasVault accounts?**

---

## Post 160 by @anon80329175 — 2026-02-02T11:47:21Z

I would love to see an Obtanium link on the website so one can directly use that source to install apps without an account.KYC/etc on their Android or GrapheneOS.

I hope this is a simple enough thing to add so hope you do soon. Thank you!

---

## Post 161 by @lanedirt — 2026-02-02T20:04:01Z

> [@PurpleDime](#):
>
> I worry that, once your app becomes more popular, some of the websites I use with it will block it.

First of all thank you for your kind words and being an AliasVault user! Yes email domains getting flagged is a real thing, and a bit of a cat-and-mouse game at that. However the system already technically supports having multiple email domains, so I will make available new domains in case the current ones get flagged (too much). Also the idea is that later, as part of the optional premium features, users can either buy their own domain and connect it to the AliasVault cloud, or get access to “VIP” alias domains that only get assigned to a low amount of users and are not publicly listed, hence reducing the risk of them getting flagged at all.

So solutions for this are already standing by, and will be activated when they’re needed. :grinning_face:

> [@PurpleDime](#):
>
> I remember reading you were working on the ability to send emails. Is that still planned? If yes, how do you intend to make it work when not email address are linked to our AliasVault accounts?

Yes, this is still planned as part of the 1.0 roadmap. The exact way of how this is going to be implemented technically is still up for investigation. In order for this to work properly there may be need for extra failsafes and perhaps things like account verifications to prevent spam and abuse. However nothing is set in stone yet, so once more details are available I will share it here.

> [@anon80329175](#):
>
> would love to see an Obtanium link on the website so one can directly use that source to install apps without an account.KYC/etc on their Android or GrapheneOS.

I’ll look into this! AliasVault already publishes the Android .APK in every GitHub release assets, and also you can download the latest browser extensions and .APK’s via the official AliasVault downloads subsite: [Index of /releases/](https://downloads.aliasvault.net/releases/). So integrating this with obtainium should be feasible. Thanks for the suggestion!

---

## Post 162 by @PaleCrow55 — 2026-02-03T00:31:32Z

> [@lanedirt](#):
>
> AliasVault already publishes the Android .APK in every GitHub release assets

That’s all you need to do to “support” Obtainium.

---

## Post 163 by @jerm — 2026-02-03T02:41:16Z

I think they want a button like [this](https://github.com/inventory69/simple-notes-sync?tab=readme-ov-file#clean-offline-first-notes-with-intelligent-sync---simplicity-meets-smart-synchronization)

> <https://github.com/ImranR98/Obtainium/issues/1287>
>
> **Prerequisites**
> 
> 
> 
> - [x] https://github.com/ImranR98/Obtainium/issues/918 …
> 
> 
> **Describe the feature**
> 
> 
> When providing download links for the apps I've written, I often use a download badge for each store 
> 
> It would be awesome to have a download badge similar to the get from play store/ fdroid/ GitHub etc 
> 
> I'd be very happy to submit a pr for this 
> 
> **Describe alternatives you've considered (if applicable)**
> 
> 
> **Additional context**
> 
> 
> See an example of existing badges 
> 
> ![ResizedImage_2024-01-14_14-15-15_2558](https://github.com/ImranR98/Obtainium/assets/41634689/07f57485-d212-4e1e-b7be-17b42e8a9789)
> 
> 
> Related to https://github.com/ImranR98/Obtainium/issues/147

---

## Post 164 by @LongPenne — 2026-02-08T11:02:44Z

Dear lanedirt,

I intended to write you an email. But this community seems awesome and committed, so maybe my ideas can be used/destroyed by the whole community.

First, what you are doing is awesome, by its breadth (visuals, communication, website, front-ends) and its depth (from hosting to browser plugins). I wish there were more IT professionals of your caliber. But I guess you’d get bored to death if you had to do the sort of tasks that many IT people have to do, maintaining legacy stuff in corporate constrained environments :wink:

Anyway, I fail to really see how AliasVault fits in the landscape, and wonder if it’s as safe as we’d like. I guess you didn’t need to know that I don’t use your tool yet. But maybe my point of view can be of interest to some users, and to you to define your “market”/target and maybe even prepare that future security audit.

So, AliasVault emphasizes things like  
“End-To-End Encryption. Your data is fully encrypted on your local device before backed up online. Your master password is never transmitted to the server. No one, except you, can see inside your vault.”

All this might be true. But you do get unencrypted emails from websites. So, all that technology only makes sense if we trust your promise that  
“Email Contents: When emails are received by the server, their contents are immediately encrypted with your public key before being saved. Only you can decrypt and read them with your private key.” I’m not sure how that architecture would be assessed in a security audit.

You seem to have an excellent track record. Spamok seems to be “old” and reputable. But E2EE is meant to create an environment where, if I trust the client, I don’t need to trust the backend. That reliance on those unencrypted emails mean that, if I don’t trust your back-end, then the whole system is not OK. Also, even if the back-end was OK in the past, if it/you go rogue, then because any future received email indicates a sender and a recipient; a “password reset” flow could be started at the site and the password that was so wonderfully protected by encryption can simply be replaced.

I understand that spamok (or YOPmail) has users, even though those emails are almost “public”. So maybe that’s not a big concern for many people. But unless special circumstances, I never felt confortable with that approach. I have used spamgourmet since almost 20 years though. They could have been rogued too and kept the emails. But their promise was to simply forward and destroy the email. I was more confortable with that behaviour/promise.

Also, while people might be OK with the trade-off for some accounts, I feel that AliasVault somehow aims to be a solution that would replace Bitwarden and apply to all accounts. And I wouldn’t like to have that sort of mix between my high value accounts (for which the alias on your own controlled domain [aliasvault.net](http://aliasvault.net) would not be desirable in my eyes), and low value accounts. Probably I’m not forced to have an alias for all accounts, but I don’t feel confortable with that sort of mix.

Anyway, I hope I’m just being paranoid/stupid, and your solution can be greenlighted by real security professionals, and liked by many users.

Best regards

PS: I also really appreciate you’re making it open source and self-hostable. Although self-hosting would only alleviate my fears if email was using another domain, not the [alaiasvault.net](http://alaiasvault.net) domain that is controlled by you. And I’m not sure how it could integrate with a real email provider. (I have Fastmail in mind because that’s what I use.)

---

## Post 165 by @lanedirt — 2026-02-08T12:02:50Z

Thank you for taking the time to write this out. Also thank you for the kind words and compliments! Happy to answer your questions and address the questions and points you raise below.

To get to the core of your point: email, as it exists today, is fundamentally a weak link: it’s largely plaintext, server-handled, and outside the user’s control. Aside from niche PGP setups (which remain fragmented to an extent), there’s simply no way to send or receive email without it transiting through a server in readable form at some point (where you don’t know whether they keep backups or not). That part of the threat model can’t be eliminated, only constrained. What AliasVault aims to do is try to reduce exposure as close to the user’s end as possible: emails received by the AliasVault server are only ever stored on disk in encrypted form. Only the recipient can actually access the contents, even if they haven’t synced their mailbox yet.

However you’re absolutely right about the core E2EE principle: ideally, trust should not need to be placed in any backend at all. That’s exactly why AliasVault is fully open-source (therefore auditable) but also offers class-A support for self-hosting. If you don’t want to trust the cloud or any AliasVault provided email domain, you don’t have to, including for email handling.

**A few clarifications that may help:**

1. Email contents are encrypted in memory immediately upon receipt, before any storage. This flow is intentionally simple and auditable in the codebase. This can be assessed and verified relatively simply in any (security) audit. Relevant lines are here: [aliasvault/apps/server/Services/AliasVault.SmtpService/Handlers/DatabaseMessageStore.cs at 5d7af1d1232b3a278e0a20551bf58a8d8cb2c376 · aliasvault/aliasvault · GitHub](https://github.com/aliasvault/aliasvault/blob/5d7af1d1232b3a278e0a20551bf58a8d8cb2c376/apps/server/Services/AliasVault.SmtpService/Handlers/DatabaseMessageStore.cs#L346)
2. Email aliases are optional. AliasVault can be used purely as a password manager vault, alongside your own existing email addresses. You can choose if and when to use an alias: e.g. only for obvious throwaway accounts, or not at all.
3. When self-hosting, you can use your own email domain, with no dependency on [aliasvault.net](http://aliasvault.net) infrastructure.
4. For the hosted version, we’re working toward allowing custom email domains as well, so users can connect their own domain names to use for aliases, which also allows them to take their domains with them if they want to no longer use AliasVault anymore.

**So rather than asking users to fully trust us, the goal is to provide real choices:**

1. Full convenience: Use the fully managed AliasVault cloud, with end-to-end encryption that can be audited and verified. Aliases are optional.
2. Convenience and control: Use the AliasVault cloud but connect your own email domain: (support for this is coming in one of the next releases)
3. Full control: self-host AliasVault and maintain your own hardware, software and email domain(s).

> [@LongPenne](#):
>
> Anyway, I hope I’m just being paranoid/stupid, and your solution can be greenlighted by real security professionals, and liked by many users.

I don’t think you’re being paranoid at all :). A healthy sense of skepticism is really a strength in the privacy/security world. AliasVault is designed to be open-source and community-driven, so we actively try to learn from feedback and address any questions people might have. Questions, suggestions and improvements to the core security model are also always appreciated.

If you have any follow up questions, feel free to let me know!

---

## Post 167 by @lanedirt — 2026-02-08T13:34:45Z

Thanks @anon80329175 for the suggestion. And thanks @jerm for the example. It took a bit of time before I could get around to it, but I have just now added the Obtainium download option to the AliasVault GitHub and website :grinning_face: :

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/e/8/e878bcee667bca6ba95f6af1d94ded410110fa9a.png)

---

## Post 168 by @LongPenne — 2026-02-08T18:59:24Z

Dear,

Thank you for the comprehensive and convincing answer.

I probably overlooked a bit that aliases are completely optional; and that there is some flexibility on the domain (now for self-hosting; later for the hosted version). Maybe I got pumped up by the statement “generating alternative identities, passwords and email addresses for every website you use” appearing about AliasVault on the website of SpamOK.

My grudge about “disposable/temporary adress” is actually a general/principle thing indeed. YOPmail or SpamOK are not my cup of tea. For those that are OK with them, AliasVault is built to offer better security and convenience than YOPmail or SpamOK anyway. And when I come to think of it, I do trust my own email provider anyway (Fastmail), and this is not so different from trusting the entity receiving the emails at the alias/disposable/temporary adress (like [AliasVault.net](http://AliasVault.net)).

FYI  
When I look at my actual usage (not using AliasVault), I have like 400 aliases managed at my mail provider. Maybe 50 with my mail provider domain; and 350 with a domain I own. (Not to mention over 750 at [spamgourmet.com](http://spamgourmet.com) (over almost 20 years) which I don’t use anymore.) I never pushed my kids or relatives in that direction, because it’s doable but can become cumbersome. Historically, my own preference was “less integration” for those matters. But an integrated solution like AliasVault might actually be/become a good fit for them.

BTW: Sometimes I like to remember how an account was created (Maybe I declared a different birthdate for instance.) I didn’t dig much in it, but it seemed like a cool feature already available in AliasVault.

Thanks again for the project, and the informative and convincing feedback

Best regards  
Beste groeten vanuit Belgie

O.

---

## Post 169 by @autfernandez1987 — 2026-02-11T13:36:34Z

Hi, after reading this entire thread I decided to give AliasVault a spin. Even though I don’t tend to put all my eggs in one basket, this service seems like a great alternative to BitWarden, SimpleLogin and (in the near future?) SmsConfirmed. So color me impressed! I also love the agility of the project and the close ties with the community. Being a fellow developer, I appreciate the amount of time and energy put into it.

One question that arose so far: I’m using the Firefox addon ATM, and I’m wondering why the password length has been restricted to 64 characters (BitWarden allows for 128 chars).

Cheers, and keep up the good work! It’s much appreciated.

---

## Post 170 by @lanedirt — 2026-02-11T13:52:31Z

Hi, thanks for trying out AliasVault! Happy to hear!

> [@autfernandez1987](#):
>
> One question that arose so far: I’m using the Firefox addon ATM, and I’m wondering why the password length has been restricted to 64 characters (BitWarden allows for 128 chars).

The password field itself actually has no limit. However the password length slider was added in a recent release and indeed only goes up to 64 (was chosen as a sane default). But there’s no reason why this couldn’t be 128 or 256 instead.

So good point, thanks for addressing! I’ll create a todo for this to increase the max. length value with the next release, so users will have more freedom in configuring their password lengths. :grinning_face:

---

## Post 171 by @autfernandez1987 — 2026-02-14T12:10:09Z

Hi there,

After setting up 2FA, I noticed some small room for UX improvement. Using the Firefox addon, when I have to enter a 2FA code I’m switching focus to the Yubico Authenticator app (in order to copy the current code). However, when I switch back, the popup window belonging to the addon has closed. When opening it again, I have to enter my credentials, prior to getting the OTP prompt. I guess that wouldn’t have been much of an issue had I known my AliasVault password by heart, but when that one has been generated as well, it becomes quite cumbersome (though not impossible :)).

Speaking of Yubico Authenticator: I think it would be neat if AliasVault could be added to the Aegis Simple Icons Pack ( [GitHub - alexbakker/aegis-simple-icons: Icon pack for Aegis Authenticator based on simple-icons](https://github.com/alexbakker/aegis-simple-icons) ), if only because several “competitors” are in there already. The default Aegis Icons Pack seems to have been abandoned ( [GitHub - aegis-icons/aegis-icons: Unofficial 2FA entry icons for open source Android authenticator Aegis.](https://github.com/aegis-icons/aegis-icons) ), so I wouldn’t bother with that one. Anyway, it would be a nice cherry on the cake, I’d say.

---

## Post 172 by @nblke72 — 2026-02-14T17:03:03Z

I just wanted to thank @lanedirt for this project, the effort he puts into it and that he actually listens to everyone’s input and tries to implement as many feature wishes and suggestions as possible :slight_smile:

---

## Post 173 by @lanedirt — 2026-02-15T09:10:39Z

@autfernandez1987 Thank you for your suggestions! Adding a persist/restore for the login process in the browser extension when needing to enter your 2FA code would indeed make for a nice improvement. I’m looking into this to add in the next release as well. :slight_smile:

I’ll also look into adding AliasVault to the simple-icons library, thanks for the tip!

> [@nblke72](#):
>
> I just wanted to thank @lanedirt for this project, the effort he puts into it and that he actually listens to everyone’s input and tries to implement as many feature wishes and suggestions as possible :slight_smile:

Thank you, that really means a lot! I’m very happy with all of the testing, feedback and suggestions, together we make AliasVault better each day! :smiling_face_with_three_hearts:

---

## Post 174 by @lanedirt — 2026-02-17T09:37:47Z

Hi @autfernandez1987,

Happy to share that the latest AliasVault release 0.26.4 was published yesterday, and it includes two of your suggestions as improvements:

> - Increase password generator length slider to max 256 chars by **[@lanedirt](https://github.com/lanedirt)** in [#1702](https://github.com/aliasvault/aliasvault/pull/1702)
> - Remember 2FA state after popup close/reopen during browser extension login by **[@lanedirt](https://github.com/lanedirt)** in [#1708](https://github.com/aliasvault/aliasvault/pull/1708)

I have also created a pull request to add AliasVault’s icon to simple-icons based on your suggestion:

- [Request: AliasVault · Issue #14362 · simple-icons/simple-icons · GitHub](https://github.com/simple-icons/simple-icons/issues/14362)
- [Add AliasVault icon by lanedirt · Pull Request #14363 · simple-icons/simple-icons · GitHub](https://github.com/simple-icons/simple-icons/pull/14363)

However as you can read in the issue comment by the maintainer, the simple-icons library has certain requirements regarding to the popularity of the website, which AliasVault does not meet (yet). So feel free to upvote the issue/PR in order to show interest. :grinning_face: The work is already done in terms of preparing the icons, now it’s just a matter of time before AliasVault will have reached the numbers they want to see.

---

## Post 175 by @autfernandez1987 — 2026-02-17T14:51:51Z

Thank you! I can confirm the improvements are working as expected.

I share your confidence that the site/service will become popular enough to get the icons in there (I didn’t realize that was a requirement). In fact, once AliasVault is out of beta I’m sure you’ll hit the ground running.

---

## Post 176 by @autfernandez1987 — 2026-02-18T08:42:16Z

Just in case you didn’t happen to stumble upon it:

> **[Password managers less secure than promised](https://ethz.ch/en/news-and-events/eth-news/news/2026/02/password-managers-less-secure-than-promised.html)**
>
> Researchers from ETH Zurich have discovered serious security vulnerabilities in three popular, cloud-based password managers. During testing, they were able to view and even make changes to stored passwords. 

Report:

> **[058.pdf](https://eprint.iacr.org/2026/058.pdf)**
>
> 1154.28 KB

I image this could be useful to know.

---

## Post 177 by @lanedirt — 2026-02-18T10:00:36Z

Thank you for sharing! Yes I also got a similar question on AliasVault’s subreddit regarding this published research. I commented on this yesterday, sharing it here as well for context:

> We did review the ETH Zurich paper (which was published yesterday, 16th of February). AliasVault was not part of that research, however we did compare the findings against AliasVault’s architecture. One specific issue they found: “field swapping / ciphertext substitution” fortunately does not apply the same way to AliasVault.
> 
> In contrast to many other password managers, AliasVault stores the entire vault as a single encrypted blob, not as separately encrypted per-field entries. That means the server can’t swap URL/password fields or tamper with individual parts without breaking integrity checks, making the client reject it.
> 
> That said, we do take all security publications seriously. We actively review each one to see whether anything is applicable and apply hardening where needed. In fact, the latest AliasVault release 0.26.4 (released yesterday) already includes security improvements to the mobile login flow (public key verification) which was specifically mentioned by this research.
> 
> As security is an ongoing process, questions like this are always welcome. Also if anyone believes they’ve found a potential issue with how AliasVault works or is designed, we also have a responsible disclosure process in place:  
> [https://www.aliasvault.net/responsible-disclosure](https://www.aliasvault.net/responsible-disclosure)

---

## Post 178 by @Aflame-Blighted — 2026-02-22T12:53:06Z

Hi @lanedirt,

I have just begun playing around with AliasVault and have a question - after entering and saving my 2FA secret key, I can’t seem to see the secret key when going back in to edit the item - it only lets me delete the existing key or add a new key.

If someone wanted to, for example, move away from AliasVault, how would they find the 2FA secret key?

When editing an item in Proton Pass it shows me the secret key and I can copy and paste it into a different password manager to generate the TOTP.

Keep up the good work.

---

## Post 179 by @lanedirt — 2026-02-22T13:13:13Z

Hi @Aflame-Blighted,

Thanks for checking out AliasVault!

The 2FA secret key is indeed not shown currently in the interface after entering it. Other users have requested this feature as well (issue exists on GitHub), so being able to see the secret in the UI will be added in one of the next releases.

> [@Aflame-Blighted](#):
>
> If someone wanted to, for example, move away from AliusVault, how would they find the 2FA secret key?

When you export credentials from AliasVault via Import / Export –\> Export to CSV, all 2FA secret keys will also be included in the CSV file. So the data is there and accessible, just not shown currently in the UI.

---

## Post 180 by @lanedirt — 2026-02-28T12:29:20Z

Hi everyone,

Happy to share that the new AliasVault 0.27.0 release is now available!

This release focuses on improving the day-to-day usage: it adds various new features to the browser extension like automatically saving credentials while you browse and enabling autofill of 2FA TOTP tokens. This release also contains several bugfixes and misc. tweaks to the other AliasVault apps.

Website: [https://www.aliasvault.net/](https://www.aliasvault.net/)  
GitHub: [https://github.com/aliasvault/aliasvault](https://github.com/aliasvault/aliasvault)

 ![0.27.0](https://forum-uploads.privacyguidesusercontent.com/original/3X/7/d/7d655c07d6f35753378fcddea5eb91cc90baeca1.jpeg)

> - Browser extension: Automatically prompt to save credentials and/or update URL when (manually) logging in to a new website.
> - Browser extension: You can now autofill 2FA TOTP tokens
> - Edit 2FA TOTP tokens after creation and view secret QR code (applies to all apps
> - Add 2FA TOTP codes in mobile app via new built-in QR code scanner
> - Improve search across all apps
> - Improve self-hosted installation, fixing issues where services were not starting automatically on fresh installs

You can find the full changelog of this release here: [https://www.aliasvault.net/news/aliasvault-0.27.0-released](https://www.aliasvault.net/news/aliasvault-0.27.0-released)

–

@Aflame-Blighted this release also includes your suggestion as a new feature: 2FA secrets can now be edited and re-shown (including QR code) from the web app / browser extension / mobile app interfaces.

---

## Post 181 by @parkerchandler1979 — 2026-03-09T15:35:19Z

Hi,

Been using AliasVault in my secondary browser profile regularly now (on Helium Browser). And I have some feedback and requests for changes & improvements.

(I have not read this entire thread)

1. I’m still getting emails from accounts/aliases I deleted. I do not know why. It’s kinda annoying as I have to manually clean everything up.

2. I’d like the ability to mass delete emails. Better email management is sorely needed the more I use it full time.

3. Ability to create aliases not solely based on names. Incorporating random usernames like how [https://strongphrase.net/](https://strongphrase.net/) this website has the ability to would be added. It’s more neutral when no name is attached to it. I used AliasVault to create this account here to post this. So, please think about this.

4. I’d like to see the delete icon next to the edit icon itself. It’s not always clear where and how one can go to delete the account credential/alias in fill. Please make it more obvious.

5. Ability to disable alias such that you can’t receive email until you re-enable it would be a a massive plus too.

6. Bug: When I was creating an account here, I wanted to edit the name of the account but as soon as I started typing “PG Community” when it originally auto named it as “Guides Community”, the extension would just close and collapse. It doesn’t seem like the add on is able to handle the edit of the name while creating it. Please see to this as well.

Hope to see fixes soon. Thank you for making AliasVault. I’m loving this tool. It’s quicker to use than other alternatives. Snappy, is the better word.

---

## Post 182 by @lanedirt — 2026-03-10T09:21:53Z

Hi @parkerchandler1979,

Great to hear you’re using AliasVault, and thanks for your feedback and suggestions.

I’ll look into the alias disable and extension collapse issues you mentioned, and add the feature suggestions to the list as well.

At the moment work is being focused toward **AliasVault v1.0** , with a strong focus on stability and bug fixes, and on completing some remaining core features such as vault sharing / family sharing. Because of that, smaller improvements and UI tweaks may take a bit longer to get to, but feedback like this definitely helps to prioritize.

Also thanks for the kind words about the extension being fast, glad to hear it’s working well for you overall. :grinning_face:

Feel free to keep sharing suggestions or possible bugs in case you come across more areas for improvement, I appreciate it a lot!

---

## Post 183 by @BLOOD — 2026-03-18T13:57:23Z

Hi @lanedirt, app looks very cool and prommisisng, I testing it as long time bitwarden user.

I miss one future in extension (didnt read all topic sorry).

its lock by master password after browser reboots. I like PIN future for convience as I set autolock after 1 minute and open by PIN, but after browser reboot I want to have master PW.

Next is do you plan to have also “real” alias/name + address? I dont use browser autofill, but I saved my identity in BW for name, address, phone, mail, etc. Aliases are great fro privacy, but sometimes, you need to use real one :slight_smile:

thanks!

---

## Post 184 by @lanedirt — 2026-03-19T10:04:02Z

Hi @BLOOD,

Thanks for using AliasVault, and thanks for your feature suggestions! I appreciate it a lot!

> [@BLOOD](#):
>
> its lock by master password after browser reboots. I like PIN future for convience as I set autolock after 1 minute and open by PIN, but after browser reboot I want to have master PW.

Thanks for explaining your usecase. I’ll look into if this is feasible to add, I have added this to the todo list to investigate further.

> [@BLOOD](#):
>
> Next is do you plan to have also “real” alias/name + address? I dont use browser autofill, but I saved my identity in BW for name, address, phone, mail, etc. Aliases are great fro privacy, but sometimes, you need to use real one :slight_smile:

Yes, this feature is already planned as part of our [v1.0 roadmap](https://github.com/aliasvault/aliasvault/issues/731) and will be added in one of the next releases. With this improvement you will be able to add one or more “real” identities, which the apps can then use for autofilling forms with your name, address etc. This can then be used for more official purposes like government things, online banking etc.

If you have any more feature suggestions for improvements, feel free to let me know!

---

## Post 185 by @anon25722375 — 2026-03-29T12:00:22Z

Hi,

Small quality of life improvement request:

On iOS, the auto lock times go from 5 sec to 30 sec. That’s a big jump. Can I have 15 or 20 sec options as well? This is when you have to manually copy things from the app to another so you can easily swipe and switch apps without having to rick the app auto locking soon.

Better yet, a custom option where we can select how long it should take to auto unlock would be even better.

Please consider this. Thanks!

---

## Post 186 by @tooinfinity — 2026-03-29T14:03:54Z

Not saying you are wrong, but in practice i have many logins for some websites/services that i manage multiple accounts for. Could it be the free tier is different to a paid one, as i have a paid plan

---

## Post 187 by @tooinfinity — 2026-03-29T14:23:48Z

Ok just downloaded this to play with an i am very impressed immediately. Proton is my primary password manager right now and i am very happy with it, but always on the look out for new tools. Been playing with pearpass too which i like the idea of but it is riddled with bugs right now.

---

## Post 188 by @PurpleDime — 2026-03-29T18:37:25Z

> [@tooinfinity](#):
>
> Not saying you are wrong, but in practice i have many logins for some websites/services that i manage multiple accounts for.

Not sure what you mean here. You seem to be saying that there are websites for which you have multiple accounts. I do too. There is nothing wrong with that. Many of those websites allow you to have multiple accounts with them. Instagram allows you to have 3 Instagram accounts. Same for Reddit, Twitter, Google, etc.

What is not allowed by Proton is to have aliases for multiple accounts with the same website.  
Meaning that you can have 3 Instagram accounts, but only one of those account is allowed to be registered with a Proton Pass alias.

> [@tooinfinity](#):
>
> Not saying you are wrong, but in practice I have many logins for some websites/services that i manage multiple accounts for. Could it be the free tier is different to a paid one, as i have a paid plan

ToS is the same regardless of if you’re on the free or paid tier. And for the record, I’m on the paid tier. I was reprimanded while being on the paid tier. Just because you may be getting away with it now, doesn’t mean that your account is not at risk for doing this.

At any point Proton can decide to disable your entire Proton account because of this ToS violation, at which point not only can you lose the multiple accounts that you have with the same website, but ALL the online accounts you have registered with a Proton Pass alias are also at risk.

---

## Post 189 by @tooinfinity — 2026-03-29T18:55:45Z

perhaps i am misunderstanding then so to clarify, i can create alias A and use that on websites 1,2 and 3. I can also have alias a,b and c and use that on website 1. Neither have created issues my end.  
Are you having trouble with one of the scenarios above or something else adjacent but similar sounding?

---

## Post 190 by @PurpleDime — 2026-03-29T20:42:21Z

> [@tooinfinity](#):
>
> perhaps i am misunderstanding then so to clarify, i can create alias A and use that on websites 1,2 and 3.

Yes, you can use the same alias for your Instagram, Twitter, and Reddit account if you so wish. It’s not against’s Proton’s ToS.

> [@tooinfinity](#):
>
> I can also have alias a,b and c and use that on website 1.

It depends on what you mean by this. If you only have one Instagram account, you can register it with alias A in 2026. If for whatever reason alias A gets compromised, you can delete it, and use alias B for the same account.

What you are allowed to do is have 3 Instagram accounts, with aliases A, B, C for each account. That is against Proton’s ToS. You may have been able to do so, but it doesn’t change the fact that it is against Proton’s ToS, and you get reprimanded for it at any point.

---

## Post 191 by @Aflame-Blighted — 2026-03-30T10:27:51Z

> [@PurpleDime](#):
>
> What you are allowed to do is have 3 Instagram accounts, with aliases A, B, C for each account. That is against Proton’s ToS. You may have been able to do so, but it doesn’t change the fact that it is against Proton’s ToS, and you get reprimanded for it at any point.

Not to derail this thread too much, and please-eli5, but if everything in Proton Pass (or insert any password manager here) is E2EE (or zero-knowledge blah blah marketing) how can Proton know how many accounts you’re making and for which websites?

Why would we use a password manager that knows this information?

---

## Post 192 by @Grapeg — 2026-03-30T10:57:37Z

The emails’ from and to addresses are not encrypted.

---

## Post 193 by @lanedirt — 2026-03-30T11:29:14Z

> [@anon25722375](#):
>
> On iOS, the auto lock times go from 5 sec to 30 sec. That’s a big jump. Can I have 15 or 20 sec options as well? This is when you have to manually copy things from the app to another so you can easily swipe and switch apps without having to rick the app auto locking soon.

Hi, thanks for using AliasVault! I agree that adding an additional in-between option for the auto-lock timeout indeed makes sense for the described usecase. I’ll look into including this in the next release! :slight_smile:

---

## Post 194 by @PurpleDime — 2026-03-30T11:53:07Z

> [@Aflame-Blighted](#):
>
> Not to derail this thread too much, and please-eli5, but if everything in Proton Pass (or insert any password manager here) is E2EE (or zero-knowledge blah blah marketing) how can Proton know how many accounts you’re making and for which websites?

When you use Proton Mail to send E2EE messages, they still know that _[harry@pm.me](mailto:harry@pm.me)_ emailed _[sally@pm.me](mailto:sally@pm.me)_, even they don’t know the content of the message. It’s similar with aliases. If you register an alias with Instagram, Proton knows that alias belongs to you. If you register a 2nd alias with a 2nd Instagram account, they pick up on the fact that this is you 2nd alias for Instagram. They recognize Instagram’s domains, and they know that two of your aliases received notifications from IG.

> [@Aflame-Blighted](#):
>
> Why would we use a password manager that knows this information?

Proton Pass is primarily a password manager, but it’s also an alias manager. Most password managers don’t manage aliases. In fact, Proton Pass is the only one.

---

## Post 195 by @Aflame-Blighted — 2026-03-30T14:34:45Z

Are you able to link me to where it says this is against the terms of service for either Proton or SimpleLogin?

Isn’t the entire purpose of SimpleLogin (with or without Proton integration) or Addy that if an alias starts receiving spam you disable it and create a new one? Therefore having multiple aliases for the same provider.

To bring this on topic, how does AliasVault view this? The terms say that mass account creation for abusive purposes is prohibited, but 2 or 3 or 4 can hardly be counted as mass. Many people have multiple social media accounts for personal and business etc.

FYI, none of this concerns me as I haven’t used social media since 2010, but interested in the limitations and restrictions nonetheless

---

## Post 196 by @TotemPoll — 2026-04-01T01:57:41Z

I can only view the first page of received emails. Pressing next just loads page for a bit and i am back on the first page. Doesn’t seem like something that should be happening at this point.

Also kindly add a multi-select tool, delete all read or anything to bulk delete emails without painstakingly opening each one then deleting then confirming.

Same for mobile app except you also can’t even view past a certain number of emails. Kindly add pagination (or infinite scrolling) so we can view all recieved emails inside the app.

Great work. Thanks

---

## Post 197 by @lanedirt — 2026-04-01T06:53:07Z

> [@Aflame-Blighted](#):
>
> To bring this on topic, how does AliasVault view this? The terms say that mass account creation for abusive purposes is prohibited, but 2 or 3 or 4 can hardly be counted as mass. Many people have multiple social media accounts for personal and business etc.

AliasVault’s ToC indeed prohibits mass account (alias) creation for abusive purposes. The philosophy behind this is that AliasVault is meant for personal use.

For the mentioned examples in previous replies: creating a handful of accounts on the same website for personal use is more than fine.

The reason that this specific term above has been included in the ToC is because we have unfortunately also seen multiple cases of people creating a new account and then proceeding to creating hundreds of aliases within just a few hours, which does not resemble normal personal use but more likely indicates spam. So in order to protect the platform, there are automatic checks that run that can block users which indicate spam usage. Blocked users are then free to contact customer support to explain their high usage in case it was incorrectly flagged.

When premium features are added, certain restriction thesholds can be upped or lifted.

—

@TotemPoll thanks for your feedback and suggestions! Improvements to email are on the todo list and will be looked at including multi-select/bulk email management.

> [@TotemPoll](#):
>
> I can only view the first page of received emails. Pressing next just loads page for a bit and i am back on the first page. Doesn’t seem like something that should be happening at this point.

In the web app when pressing the “load more” button on the emails page, the emails should be appended to the list. So you should see the emails appear below the existing emails. I just tested this and it works fine for me, also have not heard any complaints about this before. Could you check again? And if still no more emails appear in the list after clicking the button, do you see any error message appear?

---

## Post 198 by @TotemPoll — 2026-04-02T11:47:37Z

@lanedirt Thanks for your reply. I am accessing the web app on Android.

Using Brave, both mobile and desktop views show a paginated email list. Pressing Next or a page number loads for a bit then remains on page 1 (issue i described earlier.)

Using Firefox, same issue on mobile view. However, firefox’s desktop view shows the actual proper desktop page and like you mentioned there’s a load more that works as intended.

I am using brave’s built-in adblocker and Ublock Origin on firefox. I don’t know if that could be responsible for this behavior on mobile view.

As for the discrepancy in desktop view, I looked it up and it appears firefox sends both a desktop user-agent and viewport width while chrome/brave only sends a desktop user-agent but a mobile viewport. Hence why brave’s desktop view is just a zoomed out mobile view. I am of the opinion that if i asked for a desktop view, i should be getting the real desktop view but to each their own.

Thanks.

---

## Post 199 by @user127 — 2026-04-09T13:15:30Z

In Brave 1.88.138, it wasn’t possible to use Touch ID on a Mac as the AliasVault popup covers the necessary window for that.

---

## Post 200 by @lanedirt — 2026-04-09T18:43:08Z

Hi @user127, thanks for reporting this issue.

Would it be possible for you to share a screenshot with how the Touch ID coverup looks like for you on your screen? That would help a lot with debugging and further investigation.

---

## Post 201 by @Grapeg — 2026-04-11T04:41:48Z

Interesting project with some neat ideas, like displaying the emails for an alias in the alias dashboard.

For me though making aliasing part of a password manager is an unnatural pairing dreamt up by the marketing dept at proton so you have to buy two modules to have full email (you might as well get unlimited, sir).

However if aliasvault develops to include a full email service it will definitely become something of interest to me.

---

## Post 202 by @8nanni — 2026-04-11T13:39:25Z

There is a problem with data synchronization; it should be fixed as soon as possible.

---

## Post 203 by @lanedirt — 2026-04-11T14:20:33Z

@Grapeg, Thanks, appreciate the feedback! The alias features are completely optional, so you can use AliasVault purely as a password manager if you prefer. That said, aliases are a core part of what AliasVault is designed to do, and we have a lot of improvements and expansions planned on the v1.0 roadmap, with more alias-related features longer term (like disposable phone numbers). Full email functionality is something we’re also exploring, but it’s a more complex step, especially for self-hosted setups.

—

> [@8nanni](#):
>
> There is a problem with data synchronization; it should be fixed as soon as possible.

@8nanni Thanks for bringing this to my attention. Could you share a bit more detail about the synchronization issue you’re seeing (what’s not updating and in which setup)? That would help us reproduce and fix it. I’m not currently aware of any particular sync issues, but it might have to do with your specific usecase so I’m happy to look into it with more detail.

---

## Post 204 by @Grapeg — 2026-04-12T01:02:08Z

Disposable phone numbers is also something I am very interested in. :slightly_smiling_face:

---

## Post 205 by @melliefollowing — 2026-04-12T12:36:59Z

Synchronization issues

After uploading or deleting attachments, my account experiences a permanent synchronization delay, lasting several hours or encountering various errors. However, when registering a new account, saving the password works correctly and syncs immediately. I’m unsure if uploading attachments is a feature disabled by the developer. But if attachment issues are triggered, the account is permanently compromised, and synchronization stops working correctly.

I’m in Malaysia. I hope the developers can add paid features as soon as possible. Compared to the Secria project,AliasVault has already met the requirements for paid full coverage.

---

## Post 206 by @lanedirt — 2026-04-13T12:18:37Z

Hi @melliefollowing, thanks for your message! Are you using the cloud-hosted environment or are you self-hosting? Synchronization times of the vault are dependent on your vault size and internet connection speed. Currently AliasVault stores all data in your vault as a single blob on the server, which means that if you are storing (lots of) large attachments, sync times can become quite slow.

Attachments in AliasVault are primarily designed for storing small files, like .txt files, (small) scans of passports and things like that. Even though AliasVault supports all kind of files, storing large files in your end-to-end encrypted vault has downsides.

If you’re using the cloud-hosted server, feel free to send your username in a DM so I can check the size of your vault to see if that’s the reason for the delays you’re experiencing.

We do have planned to update the vault storage model into multiple end-to-end encrypted “buckets”, which should speed up sync times so it e.g. doesn’t need to load all attachments when only changing a credential. This storage model update is already being worked on behind the scenes as part of the upcoming “vault sharing” feature, and will become available in the next 2-3 months.

---

## Post 207 by @lanedirt — 2026-04-14T17:01:48Z

Hi all,

Happy to share that the latest AliasVault 0.28.0 release is now available!

This release includes support for nested subfolders, full vault exports in new .avex / .avux formats from the web app (credentials, passkeys, attachments, favicons, and more), plus improved 2FA flow in the browser extension and various fixes and polish across the apps.

Website: [https://www.aliasvault.net/](https://www.aliasvault.net/)  
GitHub: [GitHub - aliasvault/aliasvault: Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable. · GitHub](https://github.com/aliasvault/aliasvault)

 ![0.28.0](https://forum-uploads.privacyguidesusercontent.com/original/3X/5/6/56900592ccd9eb363156ce6025de17036f474390.jpeg)

> - Nested subfolders now supported in all apps
> - Full vault export/import via `.avex` (AliasVault Encrypted eXport) and `.avux` (AliasVault Unencrypted eXport) for manual backups and moving data between servers (e.g. from cloud to self-hosted or vice versa)
> - Browser extension now supports copying the 2FA TOTP code to the clipboard after autofill so you can paste it into a confirmation field
> - Improved 2FA / TOTP field detection on more sites
> - New password strength indicators added to registration and password change pages (web app)
> - Load more for emails buttons added (browser extension & mobile)
> - Rate-limited local password unlock and other reported bug fixes

You can find the full changelog of this release here: [https://www.aliasvault.net/news/aliasvault-0.28.0-released](https://www.aliasvault.net/news/aliasvault-0.28.0-released)

–

@anon25722375, auto-lock timeout options have now been expanded in the apps with this release per your previous suggestion.

@parkerchandler1979, the reported issues with alias disabling and extension collapsing on PrivacyGuides website should now be fixed as part of this release.

@TotemPoll, Issues with email pagination in the web app using smaller screens (e.g. on mobile) are now fixed as well. Thanks again for the report!

---

## Post 208 by @lanedirt — 2026-05-17T14:14:04Z

Hi all,

Happy to share that the next update: AliasVault release 0.29.0, is now available!

This release makes it significantly easier to switch to AliasVault by introducing support for importing full vault archives (including attachments and custom fields) from other popular password managers. It also improves the autofill experience across mobile and browser.

In addition, this update brings more flexibility and control for self-hosted deployments that have been proposed by the community, alongside a range of other usability improvements and bug fixes across the apps.

Website: [https://www.aliasvault.net/](https://www.aliasvault.net/)  
GitHub: [GitHub - aliasvault/aliasvault: Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable. · GitHub](https://github.com/aliasvault/aliasvault)

 ![0.29.0](https://forum-uploads.privacyguidesusercontent.com/original/3X/f/0/f0411d8ea44b94ae75488c32c510226c509e5d84.jpeg)

> - Import full vault archives (including attachments and custom fields) from 1Password, Bitwarden and Proton Pass, making it much easier to migrate to AliasVault. Improved mobile autofill: when no match is found, you’re now prompted to link a URL/app to an existing credential.
> 
> - Improved browser extension autofill form field detection and 2FA autofill flow.
> 
> - Improved iOS clipboard: allow to choose between local clipboard and Universal Clipboard
> 
> - New self-hosting controls, including custom proxy headers support in the mobile apps, trusted proxies configuration, IP-based /admin access restrictions, account registration rate limiting and configurable upload size limits.
> 
> - Better overall UX with updates to item filtering, icons, credit card display, delete flows.
> 
> - Fixed multiple reported bugs

You can find the full changelog of this release here: [https://www.aliasvault.net/news/aliasvault-0.29.0-released](https://www.aliasvault.net/news/aliasvault-0.29.0-released)

---

## Post 209 by @anon7180143 — 2026-05-17T14:16:43Z

Where in the roadmap is better email management? Is that coming up or still ways to go?

---

## Post 210 by @lanedirt — 2026-05-17T15:00:07Z

Thanks for your comment! Yes better email management features such as bulk management, push notifications, replying and similar improvements are still planned.

Right now though, the main focus is still on the core vault features, with vault/password sharing being one of the biggest upcoming features with the most impact. But there are still many more planned features and improvements on the roadmap.

Which email management features are you most looking towards?

---

## Post 211 by @anon7180143 — 2026-05-17T15:49:28Z

> [@lanedirt](#):
>
> Which email management features are you most looking towards?

1. Better email view (of the content)
2. The standard options and things you can do with emails - reply, archive, ability to change name associated with each email when corresponding,
3. Other things people in this thread have already asked/shared

I’m sure you already have a list for this on your end so just those things for now.

---

## Post 212 by @unseen — 2026-06-12T19:11:10Z

I’ve been using it for almost a year and I love it!

Is there any way I can mass select login/alias to move them to a folder in bulk?

And I have a question regarding the email in AliasVault. I’m currently using the domain @aliasvault.net exclusively. Is it correct that if someone enter the same email address I’ve used, they will be able to access the mails? For example, if I created [unseen@aliasvault.net](mailto:unseen@aliasvault.net), can someone use the same email address unseen@aliasvault in their AliasVault account?

---

## Post 213 by @lanedirt — 2026-06-13T05:59:54Z

Hi, happy to hear you’ve been using AliasVault for such a long time already!

> Is there any way I can mass select login/alias to move them to a folder in bulk?

It’s not possible yet, but bulk operations on login and email items is a feature that’s being actively worked on and will be added in one of the next releases to all apps :slight_smile:. Likely within 2 weeks or so.

> Is it correct that if someone enter the same email address I’ve used, they will be able to access the mails? For example, if I created [unseen@aliasvault.net](mailto:unseen@aliasvault.net), can someone use the same email address unseen@aliasvault in their AliasVault account?

AliasVault’s private email addresses (`@aliasvault.net` for the cloud-hosted server) are cryptographically tied to the user that first claimed it. All email that is received for that alias is encrypted with the specific user’s encryption key, and so can only be read by that user. So in your example, if somebody else would try to re-claim an already used private email address, they will get to see an error that this email alias has already been claimed and cannot access it. Email claims are permanent, so even if you disable an alias (e.g. delete it), others still won’t be able to re-use it.

---

## Post 214 by @unseen — 2026-06-13T19:24:34Z

Thank you very much for your timely reply! That is reassuring. I think it would be great to add what you just explained to a small section (or a FAQ), somewhere users can easily see or find for those who wonder the same thing.

---

## Post 215 by @lanedirt — 2026-07-07T09:55:19Z

Hi everyone,

I’m back to share with you a new update: AliasVault release 0.30.0, is now available!

This release now adds support for **generating passphrases** (based on word dictionaries) in addition to random-character passwords in all AliasVault apps. This has been one of the most upvoted feature requests on GitHub.

We also updated a lot of things behind the scenes in the last couple of weeks: we revamped our [self-hosted docs website](https://docs.aliasvault.com/) to be more accessible and user friendly. We also moved our official website and communications to [aliasvault.com](https://www.aliasvault.com/), after recently acquiring this domain. User email aliases continue to use `@aliasvault.net`, creating a more clear distinction between official AliasVault team/support addresses (.com) and user-generated aliases (.net).

Finally, we’re also hard at work on making the sync mechanism and datamodel more efficient. The work on this is well underway and will significantly improve vault synchronization speed across all apps once ready. These upcoming improvements will enable us to introduce vault sharing as well. Stay tuned!

Website: [https://www.aliasvault.com/](https://www.aliasvault.com)  
GitHub: [https://github.com/aliasvault/aliasvault](https://github.com/aliasvault/aliasvault)

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/f/f/ff8ab4fd00e5ef2f6705c71d41d8bba7d6c3c876.jpeg)

> - Generate secure passphrases based on Diceware word lists (languages supported from this first release: English, Dutch, German, Italian, French, Spanish)
> 
> - Browser extension improvements: better highlighting of credentials matching the current website, streamlined autofill flow for creating new credentials and email aliases, better passkey compatibility across more websites, password generator settings are now configurable directly from the extension, bringing it in line with the web and mobile apps.
> 
> - Performance and reliability improvements
> 
> - Self-hosting improvements: fully revamped docs website ([docs.aliasvault.com](http://docs.aliasvault.com)) focusing on readability.

You can find the full changelog of this release here: [https://www.aliasvault.com/news/aliasvault-0.30.0-released](https://www.aliasvault.com/news/aliasvault-0.30.0-released)

---

## Post 216 by @autfernandez1987 — 2026-07-07T14:35:57Z

Still going strong, I see! :raising_hands:

I have one little nag: The default **Ctrl+Shift+L** keyboard shortcut by itself is great, but happens to be equal to the Bitwarden shortcut. So when using browser extensions for both, it doesn’t always lead to the desired behavior. I realize there is a straightforward way to fix this :wink:, but apart from fully migrating to AliasVault, it would be nice to be able to choose a different letter.

Cheers!

---

## Post 217 by @lanedirt — 2026-07-08T06:56:38Z

Thanks for your comment :slight_smile:

> I have one little nag: The default **Ctrl+Shift+L** keyboard shortcut by itself is great, but happens to be equal to the Bitwarden shortcut. So when using browser extensions for both, it doesn’t always lead to the desired behavior.

Yes the keyboard shortcut that AliasVault uses for triggering the autofill popup is indeed the same as Bitwarden’s, this was done by popular request for people who have fully switched and want to reuse the same muscle memory by default.

You can however override the keyboard shortcut via the settings in the browser extension. You can choose another shortcut or disable it entirely if you want. See screenshot below:

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/7/c/7c0c718f2b937588fe9b09d5111e4f9fc2521732.png)

---

## Post 218 by @autfernandez1987 — 2026-07-08T12:09:50Z

I was suprised I couldn’t find this option anywhere. Thanks for pointing it out, however… it seems to be hiding from me (this screenshot is from FireDragon running on Garuda linux Cosmic).

 ![Screenshot_2026-07-08_14-00-52](https://forum-uploads.privacyguidesusercontent.com/original/3X/1/a/1a05ef9af15d4eefadbdfeceb6cec97eca505da5.png)

---

## Post 219 by @lanedirt — 2026-07-09T06:40:35Z

Gotcha, this might be a specific browser support thing and an oversight. Firefox based browsers indeed work a bit different with customizing shortcuts. I’ll look into it, thanks for pointing it out!

---

## Post 220 by @overdrawn98901 — 2026-07-09T13:06:33Z

@lanedirt hi there! As someone who is pretty happy with Bitwarden, I was wondering what things AliasVault may offer that would he interesting to switch over. I’m curious, but migrating is non zero effort.

---

## Post 221 by @lanedirt — 2026-07-09T13:46:54Z

Hi! AliasVault can be an interesting alternative if you want passwords, email aliases, and identity generation in one privacy-focused, open-source, EU-based, and easily self-hostable app.

Migration always takes a bit of effort indeed, however we made the import process as simple as possible. You can export your Bitwarden vault to a .zip, then import that in AliasVault in just a few clicks. All items, custom fields, attachments etc. will be automatically imported. (The only thing that is not imported automatically as of yet are passkeys, reason for that is that passkeys are hard to migrate by-design, and currently requires implementation of a generic standard on both the export and import side. But we’re working on this as well!)

---

## Post 222 by @Niek-de-Wilde — 2026-07-09T14:07:25Z

Does aliasvault have any venture capital investments behind it @lanedirt ?

---

## Post 223 by @lanedirt — 2026-07-09T14:22:01Z

@Niek-de-Wilde No external investors, AliasVault is entirely self-funded and proudly independent. :slight_smile:

---

## Post 224 by @Niek-de-Wilde — 2026-07-09T20:49:20Z

Well in that case @overdrawn98901 can add that to the list of reasons to migrate :slight_smile: .

---

## Post 225 by @pine — 2026-07-09T21:03:26Z

Really love your mission and appreciate your ongoing updates in here. I’m sorry if this has already been mentioned and I’ve missed it, but could you speak to what the basis of your self-funding is and whether you consider it sustainable at length?

---

## Post 226 by @lanedirt — 2026-07-10T09:04:28Z

Hi @pine, thanks, appreciate the thoughtful question! Happy to share some additional context:

AliasVault is entirely self-funded by me and my partner, without external investors or venture capital. The funding comes from a combination of personal investment, some freelance work I still do alongside AliasVault, community donations, and keeping our costs low on purpose: small team, efficient infrastructure, and no unnecessary overhead.

On a personal level, I build AliasVault because I believe it can genuinely help people and be a net positive. To me that comes first; money comes second. The goal is not to chase growth at the expense of users. But really to build something useful for as many people as possible.

For context, I have also been running [SpamOK.com](http://SpamOK.com) as a free privacy-focused service for over 13 years since 2013. It has been running without as much as a single day of downtime, and I have kept that fully free simply because I’m proud of what it provides, and because I believe useful privacy tools should exist and remain accessible.

When AliasVault v1.0 launches (goal end of this year), the plan is to do introduce optional paid cloud features, such as Premium and Family plans, to help sustain the hosted service and ongoing development over time. AliasVault Cloud does require ongoing time and money to operate, especially as more users sign up. Other than hosting and redundant infrastructure, there is also a significant amount of work involved in security, maintenance, support, and continued development.

The aim is also to complete an external security audit by the end of this year, which is a considerable expense on it’s own, but has already been taken into account as well.

I’m also proud and grateful to all the people who have donated to the AliasVault project so far via buymeacoffee and opencollective, which really helps a lot too!

---

## Post 227 by @lanedirt — 2026-07-15T07:59:14Z

Hi @autfernandez1987, happy to share that with the latest 0.30.1 bugfix release (published yesterday), the keyboard shortcuts link should now also show up in both Firefox (and Safari). Thanks again for the report!

---

## Post 228 by @autfernandez1987 — 2026-07-15T08:17:11Z

I’m happy to hear it :slight_smile:. Thanks for fixing this so swiftly, I can confirm it works as expected now.

---

## Post 229 by @Alastal — 2026-07-17T16:41:32Z

I’ve been reading about this project for sometime and now its the time to test it after the new changes in Bitwarden  
The first thing I was searching for is changing login folder which took me sometime to figure out as it was so small :sweat_smile:

---

## Post 231 by @JollyPirate1 — 2026-07-21T21:56:00Z

are you using AI to build this app?

---

## Post 232 by @lanedirt — 2026-07-22T11:06:22Z

No, AliasVault is not an AI or LLM generated project. I’m the main developer, but the project also includes and accepts contributions from outside contributors.

As the core of AliasVault’s logic revolves heavily around encryption and other security-sensitive code, this requires thorough system knowledge. Contributors may use whatever development tools assist their work though (including AI assistants), but every contribution must be personally authored, reviewed, tested, and understood by the person submitting it. Contributions that do not meet this standard are rejected.

You can read the full project policy regarding this on GitHub [here](https://github.com/aliasvault/aliasvault/blob/9a043b4391ff341d7d019f64a4525883dd5b3be0/CONTRIBUTING.md#5-license-and-contributions).

---

## Post 233 by @JollyPirate1 — 2026-07-22T21:17:57Z

Asking cause it has an AI feel to it. May be just me then thanks for engaging
