Disposable inboxes require no name or account; forwarding only requires an email address for sign-in and delivery.
Privacy Policy / Effective August 20, 2026
Only the data needed to deliver and protect the service
This policy explains what information TMPPost processes when providing disposable email and permanent forwarding, why we process it, how long we keep it, and how you can request access or deletion. If different language versions differ in interpretation, the interpretation required by applicable law and most favorable to data subject rights will prevail.
At a glance
Four processing principles
Temporary content expires with its address; account settings and limited logs are retained for their purposes, not indefinitely.
You can destroy a disposable inbox, delete an alias, clear an archive, or request your account data.
Access tokens, authentication, rate limiting, and abuse detection help reduce unauthorized access and delivery risks.
Retention and limits
Data does not stay around just in case it might be useful
| Category | Purpose | Typical retention | Limit |
|---|---|---|---|
| Disposable addresses and messages | Create a web inbox and display incoming messages | 3 hours by default; up to 24 hours after extension | Cannot be recovered after expiration or manual deletion |
| Temporary access tokens | Link the current browser to the inbox | For the lifetime of the mailbox | Control cannot be verified if the token is lost |
| Account email and aliases | Code-based login, forwarding, and settings management | While the account remains active | A short-lived isolated backup may be kept to handle deletion requests and disputes |
| Forwarding archives and status | Display delivery results, retries, and spam flags | Usually no more than 30 days | Retention can end sooner when the user deletes the data |
| Security and access logs | Prevent abuse, troubleshoot issues, and protect systems | Usually no more than 90 days | Security incidents or legal obligations may require longer retention |
Full policy
1. Information we process
When you use a disposable inbox, we process the random address, access token, expiration time, and the message content and necessary transmission metadata delivered to that address. Creating a disposable inbox does not require a name, password, or long-term account.
When you use forwarding, we process your login email, verification results, aliases you create, active or inactive status, forwarding destinations, and delivery records. If you enable two-step verification, we process the key material and verification status needed to complete setup, but we do not request your device unlock information.
2. Purposes and legal bases
We create addresses, receive messages, forward incoming mail, and display the dashboard to fulfill your requests. To keep the service secure, we also detect unusual traffic, abusive deliveries, and violations of our terms, based on our legitimate interest in providing a secure and reliable service.
Where required by law, we rely on contract performance, legitimate interests, legal obligations, or your consent. We do not sell personal data or use disposable email content to build advertising profiles.
3. Message content and automated processing
The system must automatically process message bodies, subject lines, sender details, and attachment information to display and forward messages and perform spam classification and security scanning. Automated checks may block deliveries that are clearly malicious, oversized, or listed on blocklists.
Disposable inbox content is accessible only during its validity period and only to a session holding the corresponding token. Forwarding archives are available only to users authenticated through their account, and downloading attachments likewise requires valid authorization.
4. Sharing, processors, and international transfers
We disclose data to service providers only as necessary to operate hosting, network delivery, security monitoring, and customer support, and require them to process it on our instructions with appropriate safeguards. The sender of an incoming message and the provider of the final recipient’s mailbox may also process communications data independently.
Our infrastructure may be located outside your jurisdiction. Where an international transfer is required, we use applicable contractual safeguards, access controls, and data-minimization measures; we do not expand the purposes of data use because of a cross-border transfer.
5. Cookies and local storage
TMPPost uses browser local storage to save language preferences, disposable inbox sessions, login tokens, and sending-code cooldowns so requested features can work. These items are not cross-site advertising cookies.
Clearing site data can remove credentials stored on your device, but it does not automatically delete account settings on our servers. To delete account data, use the controls provided in the dashboard or contact support.
6. Security measures
We use measures including encryption in transit, access tokens, permission checks, rate limiting, least-privilege access, and log monitoring. No online service can guarantee absolute security, so you should also protect your device, login email, and two-step verification keys.
If you discover suspected unauthorized access, contact support promptly and suspend the affected aliases. We will assess the incident and meet notification and remediation obligations under applicable law.
7. Your rights
Under applicable law, you may request access to, correction, deletion, restriction, or export of personal data associated with your account, and you may object to processing based on legitimate interests. We may request reasonable identity verification to avoid disclosing data to an impersonator.
When some data cannot be deleted immediately because of a security investigation, dispute, or legal obligation, we will restrict its use and explain why. You may also lodge a complaint with the data protection authority where you live.
8. Children, changes, and contact
The service is not intended for children below the applicable age of digital consent in their region, and we do not knowingly collect children’s account information. If a guardian believes a child has provided personal data, they may contact us so we can investigate and delete it.
Material policy changes will update the effective date on this page and, where appropriate, be announced through an in-product notice. Send privacy questions and rights requests to support@tmppost.com.