Can websites see your real email address when you sign up? Yes. And it is only the first stop. A hospital pixel story made me map my own signups, and the map is what I built AliasFleet around: an email-alias service that gives each site its own address, so the worst one leak can do is burn one relationship. The moment you hit submit, your address starts travelling: to their analytics tools, their ad platforms, data brokers, and eventually to someone's breach database.
You are not giving it to the website
Think about what actually receives your address. A signup form is a hopper. Your email drops in, and then the site's machinery carries it to several places at once: the user database, the analytics scripts, the email marketing platform, the ad accounts, the fraud-check vendors. Each of those is another database, another company, another set of engineers with access. Your address is not in one place. It is in a dozen, before breakfast.
That is the mental model that matters. You did not hand one thing to one company. You forked your identity into every system that company plugs together. And none of those forks expire when you delete the account.
Their trackers watch the form itself
Before the address even reaches the company's servers, it often passes through trackers on the page. The clearest documented case is the hospital one. In 2022, The Markup tested the websites of Newsweek's top 100 hospitals in America and found the Meta Pixel on 33 of them, MacObserver reported. The pixel did not just watch page visits. When testers clicked "Finish Booking" on a Scripps Memorial Hospital doctor's page, the pixel sent Facebook the doctor's name and field of medicine, plus the first name, last name, email address, phone number, zip code and city entered into the booking form. The details were hashed before sending, and Meta could still link them to Facebook profiles.
These were hospitals, and people rightly called that a HIPAA problem. Novant Health ended up notifying 1,362,296 patients after its own Meta Pixel transmitted data that potentially included email addresses, phone numbers, IP addresses, appointment types and dates, physicians selected, and free-text content, to Meta. The code had been on the site since May 2020. The pixel was there for advertising measurement, the same reason any retailer installs one.
Hospitals got the scrutiny because the data was medical. The mechanism is the ordinary one: a tracking pixel logs what happens on the page, including what gets typed into forms. I cannot tell you whether the pixel is on the specific site you are signing up for today. That is the point. The signup page is a collection surface, and you get no readout of who is watching it.
Do trackers really read what I type into forms?
The documented cases involve form submissions and button clicks: the hospital pixel investigation captured details entered into booking forms, and the Novant disclosure covered content typed into free-text boxes on the site. Keystroke-level capture exists in some analytics tools, but I have not verified how widespread it is on ordinary signup pages.
Then your address joins the ad platforms
The deliberate version of the same journey happens inside the company's own marketing stack. This one is a documented feature.
In August 2019, GoodRx compiled lists of users who had purchased particular medications, including drugs for heart disease and blood pressure, and uploaded their email addresses, phone numbers, and mobile advertising IDs to Facebook so it could identify their profiles. GoodRx then used that to target those users with health-related advertisements. The FTC announced the case in February 2023, fined the company $1.5 million, and barred it from sharing health data for advertising. It was the agency's first enforcement action under the Health Breach Notification Rule.
Google's version of the pipeline is public documentation, not an enforcement case. Enhanced conversions in Google Ads ingests first-party customer data "such as email addresses", hashes it with hex SHA256, and sends it to Google, where it is matched to signed-in Google accounts that engaged with the advertiser's ads. The leads variant takes user-provided data from website lead forms and matches it against offline conversions. The feature exists because advertisers asked for it, and the email is the most reliable field.
"Hashed for privacy" is how the industry phrases it. The FTC's 2024 position is the counter: hashing does not anonymise identifiers. The same input always produces the same hash, so the hash works as a stable identifier for that address across every company that uploads it.
The FTC said it plainly in July 2024: hashed identifiers "aren't 'anonymous' and can still be used to identify users, and their misuse can lead to harm." All user identifiers, the agency wrote, "have the powerful capability to identify and track people over time, therefore the opacity of an identifier cannot be an excuse for improper use or disclosure."
So the email you typed into one signup form can end up, hashed, in an ad platform's identity graph, matched to the accounts you hold elsewhere. The mechanism is not a leak. It is the product working as designed.
The brokers, and then the breach
From there the address enters the trade. The FTC's 2014 study of nine data brokers found an industry that buys, combines, and resells consumer data built around personal identifiers like email, and the ACLU's summary is worth reading for the bluntness: Acxiom held "3000 data segments for nearly every U.S. consumer", and brokers tie an email address to race, religion, political affiliation, income, and more. Consumers, the FTC found, mostly had no idea the market existed.
The last stop is the one everyone knows about, and it keeps confirming the pattern. 23andMe lost 6.9 million customers' data after attackers used credentials stolen from other sites to walk in through its front door, and agreed an $18 million settlement with 43 attorneys general in July 2026. Ticketmaster's parent confirmed a breach of its third-party cloud database in an SEC filing; the attacker claimed 560 million records including names, addresses, emails and phone numbers were for sale. Have I Been Pwned now counts 1,042 breached sites and 17.8 billion exposed addresses. Your address does not need to be special. It just needs to be somewhere.
The one part you control
The database, the pixel, the upload, and the broker are all out of your hands. That is the honest shape of the problem, and any honest writing about it ends there instead of pretending otherwise. The part you control is the handover: what the form receives.
Give each site an address that exists only for that site. An email alias is a forwarding address with no inbox of its own: mail to it forwards to your real inbox, and the site never learns the address underneath. When the hospital, the retailer, or the coupon app feeds that alias to its trackers and ad platforms, every one of those systems gets an identifier that points to exactly one relationship. A hashed copy of it in an ad graph reveals nothing about your real address. A breach dump containing it names the site that leaked it, which is the mechanism the leak-tracing guide walks through. A "you" that appears in a broker's file under that alias loses the email as the string that ties your accounts together. Your name, phone number, and street address can still be joined on, so this is not a clean-room promise. But the one identifier you reuse everywhere is no longer in the set.
That is the containment the one-address-per-site habit buys. It does not make the website behave. It makes the website's misbehaviour irrelevant to everything else in your life. And it is a habit, not a purchase: setting it up takes a couple of minutes, the free tier covers ten aliases, and the breach-response guide is the checklist for whatever the old address has already been through.
Does one address per site stop all of this?
No, and I would rather say that than oversell it. It does not fix the address you have handed out for a decade: that one is already in the dumps, and no new habit retracts it. It does not erase the identity profile already built from your real address. It does not help while you are logged in, and it does not stop fingerprinting. What it gives you is containment from here on. Every new signup goes to its own alias instead of the same address that is already everywhere, so each future form stops adding to the trail the past decade built. That is the only part of the route you get to choose, so it is the part worth choosing.
The databases will run their course without you, and the brokers will trade whatever they hold. What you decide is what goes into their hands at the start: an address you can pause or kill in one click, and then the furthest your signup can travel is still one relationship.
Top comments (0)