TMPPost

Privacy Policy / Effective August 20, 2026

Only the data needed to deliver and protect the service

This policy explains what information TMPPost processes when providing disposable email and permanent forwarding, why we process it, how long we keep it, and how you can request access or deletion. If different language versions differ in interpretation, the interpretation required by applicable law and most favorable to data subject rights will prevail.

At a glance

Four processing principles

Retention and limits

Data does not stay around just in case it might be useful

CategoryPurposeTypical retentionLimit
Disposable addresses and messagesCreate a web inbox and display incoming messages3 hours by default; up to 24 hours after extensionCannot be recovered after expiration or manual deletion
Temporary access tokensLink the current browser to the inboxFor the lifetime of the mailboxControl cannot be verified if the token is lost
Account email and aliasesCode-based login, forwarding, and settings managementWhile the account remains activeA short-lived isolated backup may be kept to handle deletion requests and disputes
Forwarding archives and statusDisplay delivery results, retries, and spam flagsUsually no more than 30 daysRetention can end sooner when the user deletes the data
Security and access logsPrevent abuse, troubleshoot issues, and protect systemsUsually no more than 90 daysSecurity incidents or legal obligations may require longer retention

Full policy

1. Information we process

When you use a disposable inbox, we process the random address, access token, expiration time, and the message content and necessary transmission metadata delivered to that address. Creating a disposable inbox does not require a name, password, or long-term account.

When you use forwarding, we process your login email, verification results, aliases you create, active or inactive status, forwarding destinations, and delivery records. If you enable two-step verification, we process the key material and verification status needed to complete setup, but we do not request your device unlock information.

2. Purposes and legal bases

We create addresses, receive messages, forward incoming mail, and display the dashboard to fulfill your requests. To keep the service secure, we also detect unusual traffic, abusive deliveries, and violations of our terms, based on our legitimate interest in providing a secure and reliable service.

Where required by law, we rely on contract performance, legitimate interests, legal obligations, or your consent. We do not sell personal data or use disposable email content to build advertising profiles.

3. Message content and automated processing

The system must automatically process message bodies, subject lines, sender details, and attachment information to display and forward messages and perform spam classification and security scanning. Automated checks may block deliveries that are clearly malicious, oversized, or listed on blocklists.

Disposable inbox content is accessible only during its validity period and only to a session holding the corresponding token. Forwarding archives are available only to users authenticated through their account, and downloading attachments likewise requires valid authorization.

4. Sharing, processors, and international transfers

We disclose data to service providers only as necessary to operate hosting, network delivery, security monitoring, and customer support, and require them to process it on our instructions with appropriate safeguards. The sender of an incoming message and the provider of the final recipient’s mailbox may also process communications data independently.

Our infrastructure may be located outside your jurisdiction. Where an international transfer is required, we use applicable contractual safeguards, access controls, and data-minimization measures; we do not expand the purposes of data use because of a cross-border transfer.

5. Cookies and local storage

TMPPost uses browser local storage to save language preferences, disposable inbox sessions, login tokens, and sending-code cooldowns so requested features can work. These items are not cross-site advertising cookies.

Clearing site data can remove credentials stored on your device, but it does not automatically delete account settings on our servers. To delete account data, use the controls provided in the dashboard or contact support.

6. Security measures

We use measures including encryption in transit, access tokens, permission checks, rate limiting, least-privilege access, and log monitoring. No online service can guarantee absolute security, so you should also protect your device, login email, and two-step verification keys.

If you discover suspected unauthorized access, contact support promptly and suspend the affected aliases. We will assess the incident and meet notification and remediation obligations under applicable law.

7. Your rights

Under applicable law, you may request access to, correction, deletion, restriction, or export of personal data associated with your account, and you may object to processing based on legitimate interests. We may request reasonable identity verification to avoid disclosing data to an impersonator.

When some data cannot be deleted immediately because of a security investigation, dispute, or legal obligation, we will restrict its use and explain why. You may also lodge a complaint with the data protection authority where you live.

8. Children, changes, and contact

The service is not intended for children below the applicable age of digital consent in their region, and we do not knowingly collect children’s account information. If a guardian believes a child has provided personal data, they may contact us so we can investigate and delete it.

Material policy changes will update the effective date on this page and, where appropriate, be announced through an in-product notice. Send privacy questions and rights requests to support@tmppost.com.