Last updated: 26 August 2026
Temp Mail ("we", "us") provides free temporary email inboxes. This policy explains what data we process, why, and for how long. We wrote it to be read, not skimmed: it is short on purpose.
1. Data we do not collect
We do not ask for your name, your real email address, a phone number or payment details. There are no accounts. We do not sell data, and we do not share email content with anyone.
2. Data we store, and for how long
| Data | Purpose | Retention |
|---|---|---|
| Temporary email address and its mailbox settings | Delivering your mail | Until the mailbox expires (24 hours by default, 7 days with a password, extendable) or you delete it |
| Emails, attachments and the original message source | Showing and exporting your mail | Until the email retention period ends (shown under your address) or you delete it |
| A one-way hash of your IP address | Rate limiting and abuse prevention | Up to 30 days in ingest and rate-limit logs |
| A random device token stored in your browser | Reopening your mailboxes without an account | Until you clear your browser or remove the mailbox |
A locale cookie (NEXT_LOCALE) and your consent choice | Remembering your language and cookie preferences | 12 months |
| Contact form submissions | Answering your message | Up to 180 days |
Mail sent to an address that does not exist yet is held for a few minutes and then discarded.
3. Cookies and local storage
We use one functional cookie for your language and, if enabled, local storage for your mailbox list, preferences and consent choice. Advertising and analytics scripts are loaded only when enabled by us and, where the law requires it, only after you consent. See the cookie policy for details.
4. Advertising
The service is funded by advertisements served by Google AdSense. Where required (for example in the EEA, UK and Switzerland) you will be asked for consent before any advertising cookie is set, and you can reject it. Ads are always labelled.
5. Security
Emails are shown inside a sandboxed frame that cannot execute scripts, remote images are blocked until you load them, and passwords are stored as bcrypt hashes. Mailbox tokens are stored only as hashes on our servers. Access is encrypted in transit (HTTPS).
6. Who can read a mailbox
A mailbox without a password can be opened by anyone who knows its exact address. Choose a random address, or set a password, for anything sensitive.
7. Your rights
Because we hold no identity data, most requests are satisfied by deleting your mailbox yourself (mailbox menu → Delete). If you have a question or a request about data we hold, contact us through the contact page. Residents of the EEA and UK have the rights to access, rectify, erase and restrict processing of their personal data, and to complain to a supervisory authority.
8. Changes
We will update the date above when this policy changes. Significant changes will be announced on the site.