About this policy
This policy explains how the TempMail application handles information when you create a temporary inbox, receive messages, and browse this website. It describes the features currently implemented in this application.
Temporary email separates short-term messages from your regular email address. It does not guarantee anonymity or provide a password-protected mailbox.
Information the service handles
- Inbox information: your generated email address, inbox identifier, creation time, and expiry time.
- Incoming email: sender and recipient addresses, subject, message text or HTML, message identifiers, and delivery timestamps.
- Delivery details: depending on the incoming message and provider, email headers, attachment information, raw email, and the provider's delivery payload may also be stored. These can contain personal information supplied by senders.
- Operational information: the application logs errors. When webhook debugging is enabled, logs can include email-related information. Hosting and email providers may also process connection information, such as IP addresses and request details, according to their own settings.
This application does not require an account registration form to create an inbox.
How information is used
Inbox and message information is used to create temporary addresses, receive and display email, restore your current inbox in the same browser, process message delivery, troubleshoot errors, and retain expired inboxes for administrator review.
Visiting the FAQ or this policy page does not create a new inbox.
Browser storage and cookies
The inbox page stores the current email address in your browser's local storage under temp-mail-address. It reads that value when you return so it can try to restore the same inbox.
You can remove this value by clearing this site's browser data. Clearing browser storage does not delete server-side messages; use Delete on the inbox page for that.
The public inbox does not use application cookies. Signing in to the admin dashboard sets an HttpOnly session cookie that expires after eight hours; signing out clears it. Admin sessions and temporary failed-login counters are stored in server memory, with failed attempts grouped by client IP address. The current application does not implement advertising trackers or analytics scripts. Hosting infrastructure and future integrations may have separate behavior.
Service providers and external content
Inbox records and messages are stored in Supabase. Incoming messages are delivered through the email provider configured by the site operator; the application supports Resend and a configured incoming-email webhook. These providers process the information needed to operate their services.
HTML email is displayed in a sandboxed preview that blocks scripts. Remote images and other resources in an email may still contact external servers when displayed, which can disclose connection information to those servers.
The current application has no feature that sells email data or shares it with advertising services. Provider retention, processing locations, and infrastructure access depend on the operator's deployment and provider agreements.
Retention and deletion
Your address displays a configured expiry time. After expiry, the inbox and its messages are no longer available through the public inbox. They remain stored for administrator review until manually deleted. Expiration does not automatically delete records.
Delete removes the current inbox from the active database and creates a new address. With the supplied database schema, messages associated with a deleted inbox are also removed. Change creates a new address without deleting the previous inbox immediately.
The application does not offer recovery of deleted messages. Deleting an inbox does not necessarily remove copies held in provider backups, delivery systems, or operational logs; their retention depends on the operator's and providers' settings.
Access and privacy limits
Inboxes do not have a password or user login. The application retrieves messages using an address or message identifier. Anyone who knows those details may be able to access the corresponding messages. Keep your temporary address and message identifiers private.
Do not use this service for banking, sensitive personal records, confidential communications, or accounts requiring long-term recovery. Use a permanent, secure email account for those purposes.
Your choices
- Use Delete to remove the current inbox and its associated messages from the active database.
- Clear site data in your browser to remove the locally saved address.
- Avoid sending sensitive information to a temporary address.
- Stop using the service when you no longer need it.
For information held in provider logs or backups, or other privacy questions, the site operator must handle the request through their published contact channel. A dedicated privacy contact has not yet been provided for this deployment.
Changes to this policy
This page may be updated when the application's data handling changes. The date above identifies the latest revision. Review this policy before using new features or integrations.