Privacy policy

Data moves only to provide and manage your email

This policy explains what we collect, why we process it, how long we keep it, and how you can delete or correct it. Last updated: September 4, 2026.

Retention limits

Different data, different lifetimes

Retention periods are based on functional needs. Security logs may be kept separately for a limited time to prevent abuse and investigate incidents.

Data category Purpose Typical retention Your control
Temporary addresses and emails Receive and display messages for the current session Initially 3 hours; extendable within product limits Destroy the inbox or delete individual messages at any time
Aliases and receiving addresses Deliver incoming messages to the specified destination While the alias exists Pause or delete permanently
Alias delivery records Verify delivery, assess spam, and retry delivery 30 days Delete individual messages or clear all records
Authentication and security logs Login, rate limiting, abuse prevention, and incident investigation A reasonable short-term security window Submit an access or deletion request
Support communications Respond to questions and retain the support context As long as needed to resolve the request Contact support to close the ticket

1. Scope and operator

This policy applies to the temporary inboxes, email aliases, delivery records, and related support services on inboxtmp.com. Inboxtmp determines how data needed for these features is processed. If a third-party website sends mail to your address, that third party remains responsible for its own collection and sending practices.

For questions about this policy, personal data, or security incidents, email support@inboxtmp.com. To protect accounts, we may first ask you to verify your identity through a receiving email address you control.

2. Data we process

Temporary inboxes process random addresses, access credentials, expiry times, senders, subjects, message content, and attachments. Long-term aliases additionally process your receiving address, alias status, delivery results, spam assessments, and the status of any one-time codes you enable.

When you access the service, the server also records your IP address, timestamp, request path, browser type, and error details for a short period. This technical data supports rate limiting, diagnostics, availability, and bulk-abuse prevention—not advertising profiles.

3. Purposes and legal bases

We create addresses, display emails, forward incoming messages, and provide management features to fulfill your requests. To protect the service and other users, we may also apply rate limits, spam detection, fraud prevention, and incident audits where reasonably necessary for security.

Optional notifications or product updates are sent only after you actively submit your email, and you can opt out at any time. We do not repurpose data required for core email reception for unrelated marketing.

4. Temporary inboxes

Temporary inboxes require no account and are accessed with a high-entropy token. Anyone who has the token may be able to read the inbox, so do not expose the full address or access details on shared devices, public chats, or screenshots.

When an inbox expires, it stops accepting new messages and enters the deletion process. Expiry does not tell third parties to retract messages they have already sent, nor does it delete data you submitted to other websites.

5. Email aliases and forwarding

Long-term aliases require a passcode login using your receiving address, after which messages are delivered to that destination. Pausing an alias discards subsequent messages; deleting an alias cannot be undone, and we cannot guarantee that the same prefix will be available again.

During delivery, messages undergo necessary content parsing, spam assessment, and queuing. We retain limited-time records to verify delivery results, but do not promise permanent storage of original messages.

6. Cookies and local storage

The site uses browser local or session storage to save temporary inbox credentials, countdowns, login tokens, and interface state. This keeps your experience continuous after refreshes; it is not third-party ad tracking.

Clearing browser data removes the related access credentials from your device and may prevent you from reopening an unexpired temporary inbox. Login tokens expire, and signing out removes them from the current device.

7. Service providers and disclosures

We may use hosting, network, caching, email delivery, and security providers to process data required to provide the service. Providers may process data only under contract and our instructions, and must apply appropriate confidentiality and security measures.

We may disclose the minimum necessary information to authorized authorities when legally required, to protect user safety, or to investigate attacks on the service. Where permitted by law, we review requests and challenge excessive demands.

8. International processing

Network traffic and email delivery may cross the country or region where you live, and infrastructure may be operated by providers in different regions. We choose providers that offer reasonable protection commitments and limit their access.

Protection standards may differ across jurisdictions. To learn about arrangements relevant to your location, contact us through the support address.

9. Security measures

We use encryption in transit, access controls, short-lived credentials, rate limiting, and log monitoring to protect our systems. Long-term account management supports email passcodes and optional TOTP codes; partial credentials cannot call protected interfaces.

No system can guarantee absolute security. Do not use a temporary address for medical, financial, identity-document, important account-recovery, or other information whose exposure or loss you cannot accept.

10. Your rights and choices

Depending on applicable law, you may have the right to access, correct, delete, restrict, or object to processing, and to obtain a portable copy. After verifying your identity, we respond within a reasonable period and explain the legal basis when we cannot fulfill a request.

You can delete emails, destroy temporary inboxes, or pause and delete aliases directly in the product. For requests that cannot be completed in the interface, email support@inboxtmp.com with the relevant address and request type, but do not send sensitive information from the email body.

11. Children and misuse

The service is not intended for children who cannot legally consent to data processing independently. If a guardian believes a child has provided personal data to us, they can contact support to request review and deletion.

Do not use the service to harass others, bypass registration limits, commit fraud, or receive unlawful content. Where necessary, we may restrict access and retain the minimum evidence needed to handle a security incident.

12. Changes and contact

When features, laws, or provider arrangements change materially, we will update the date on this page and, where reasonable, provide prominent notice. Updates will not retroactively grant us permission to process data for purposes unrelated to the original ones.

For privacy requests, complaints, or security disclosures, contact support@inboxtmp.com. If you are dissatisfied with our response, you may also complain to the authorized data protection authority in your area.