Privacy Policy
Draft policy. This page describes what the product currently does and stores. It has not yet been reviewed by a lawyer and should be before production use.
What we collect
Creating a temporary inbox does not require an account, name, or personal email. We store the inbox’s random address, its creation and expiry time, and a one-way hash (not the raw value) of the IP address that created it, used only for abuse and rate-limit enforcement.
What is stored temporarily
Messages sent to an active inbox — sender, subject, body, and attachments — are stored until the inbox expires or is deleted, whichever comes first.
How long messages remain
The default inbox lifetime is 30 minutes, extendable up to a configured maximum. When an inbox expires, it and every message in it are deleted by an automated cleanup job — not just hidden.
Security measures
Inbound HTML email is sanitized before storage and rendered inside a sandboxed frame that cannot run scripts or reach the rest of the site. Admin passwords are hashed, never stored in plain text. Traffic is rate-limited to reduce abuse.
Analytics
We track anonymous product events (e.g. an inbox was created, a message arrived) to understand usage. We do not send email content to any analytics provider. Page-view records are kept for 90 days and then automatically deleted. The “visitor” identifier used to count unique visitors is a hash that rotates daily and cannot be linked back to a specific IP address or person.
Where data is hosted
This service runs on third-party infrastructure rather than our own servers: Vercel (application hosting), Neon (database), a managed Redis provider (rate limiting and live-visitor tracking), and Cloudflare (DNS and inbound email routing). Each of these processes data on our behalf as part of running the service; none of them are given access to read your messages for their own purposes. Because these providers operate internationally, data may be processed outside the country you’re accessing this service from.
Cookies
The public product does not use tracking cookies. The admin panel uses a single session cookie required to stay signed in.
Third parties
No message content is shared with third parties.
Your rights
Because inboxes require no account, you can delete an inbox (and every message in it) at any time from the inbox page itself — no request needed.
Contact
Questions about this policy: privacy@tempmail.name.