Privacy Policy
Last updated: 12 August 2026. This policy is published in English only; the English text is the authoritative version.
The short version
- No account, no name, no password, no payment details. We never ask for them.
- We store every message sent to your temporary address, including its full raw source and any attachments, until that data is purged.
- We log the IP address and country of each address creation so we can rate limit abuse.
- Your inbox is protected only by the secret link. Anyone who has that link can read it. Treat it as public.
- Google Analytics runs on every page of this site.
1. Who we are
TempMailer.net ("we", "us") operates a free disposable email service at tempmailer.net. We are the controller of the personal data described below. For any privacy question or request, write to privacy@tempmailer.net.
2. What the service does
When you open the site we generate a random email address for you and give you a private link to its inbox. Mail sent to that address is received by our own mail servers, stored, and shown to you in the browser. A standard address is valid for 24 hours from the moment it is created. An address created on the 10 Minute Mail page is valid for 10 minutes. Extending an address resets its lifetime from the moment you press the button; it does not add time on top of the remaining time.
3. What we store
We store the following, and nothing beyond it:
Messages sent to your address
- The sender's address and display name, the subject line, the plain-text body and the HTML body.
- The complete raw source of the message and its parsed header set. Headers routinely contain the sending server's details and, for mail sent by a person rather than a service, can contain the sender's own IP address. We do not strip them.
- The time the message was received.
- Attachments, written to disk on our server, along with the file name, declared MIME type and size. Attachments above the configured size limit (10 MB by default) are discarded on arrival and are never stored.
The mailbox itself
- The generated address, the domain it belongs to, its expiry time, and the 64-character random token that forms your inbox link.
A creation log
- Your IP address. It is read from the
CF-Connecting-IPheader set by Cloudflare, or fromX-Forwarded-For, or from the connecting socket. - A two-letter country code, taken from Cloudflare's
CF-IPCountryheader. We do not run our own geolocation database and we do not store a city, region or coordinates. - Whether a referral code was active and, if so, which one.
- Basic acquisition detail: the interface language you were using, the path on our site you were on when the address was created, the host name (not the full URL) of the page that linked you to us, and any
utm_source,utm_mediumorutm_campaignvalues present in the address bar. - The time the address was created.
An abuse list
- We maintain a manually curated list of IP addresses that are allowed to bypass rate limits or are blocked outright, with a free-text note explaining why. An IP address only appears on this list if an administrator puts it there.
We do not ask for or store your name, a password, a phone number, a payment method or any other identifier. There are no user accounts on the public site.
4. Why we store it
- Message data is stored because delivering it to you is the entire point of the service you asked for. Where the GDPR applies, the legal basis is performance of a contract with you (Article 6(1)(b)).
- The creation log (IP address, country code, referral code and acquisition detail) is stored to enforce rate limits, to detect and stop abuse of a free service, and to produce aggregate statistics about traffic and where it comes from. Where the GDPR applies, the legal basis is our legitimate interest in keeping the service available and not being used as an abuse platform (Article 6(1)(f)).
5. Your inbox is not private
This is the most important thing on this page. Your inbox is protected by nothing except the secrecy of its link. There is no password and no login. Anyone who obtains the link — from your browser history, a shared screen, a copied URL, a synced device — can read every message in that inbox, download its attachments, and keep watching it as new mail arrives. New mail is also pushed over a real-time channel named after the same token, which is not individually authenticated.
Do not use a TempMailer address for anything you would mind a stranger reading. That includes password resets for accounts you care about, banking or payment confirmations, medical correspondence, identity documents, or anything covered by a confidentiality obligation.
6. How long we keep it
We would rather be accurate than flattering here.
- Every mailbox has an expiry time (24 hours, or 10 minutes for 10 Minute Mail). Once it passes, the address stops working: mail addressed to an expired mailbox is rejected by our servers and is never stored.
- Expiry on its own does not erase what has already been received. Until the data is purged, the messages, attachments and mailbox record still exist, and the inbox link still opens.
- An automated purge of expired mailboxes — the mailbox record, its messages, its attachment records and the attachment files on disk — is being rolled out and is intended to run on a short, repeating schedule. Until it is fully in place we are not publishing a guaranteed deletion interval and you should not rely on one. If you need something gone, ask us (see section 10) rather than waiting.
- Creation-log entries (IP address, country code, referral code, acquisition detail, timestamp) are kept separately from mailbox records for abuse prevention and statistics, and are not removed when the mailbox they relate to is deleted.
- Deleting a mailbox record deletes its messages and, by database constraint, the attachment records attached to them.
7. Cookies and browser storage
- A session cookie is strictly necessary for the site to work. It is what remembers which mailbox is yours: it holds the token of your current address (and a separate one for a 10 Minute Mail address), plus any referral code you arrived with.
- A cookie and a matching entry in your browser's local storage remember your light/dark theme choice.
- Google Analytics sets its own cookies (see the next section). We do not set advertising cookies of our own and we do not run an ad network.
8. Third parties
- Google Analytics. Every page loads Google's gtag.js and reports to a Google Analytics 4 property. Google receives your IP address, the page you are on, the referring page, and general device and browser information, and processes it under its own terms. If you do not want this, block it with a content blocker or your browser's tracking protection; the site works fine without it.
- Cloudflare. The site is served through Cloudflare, which terminates your connection and supplies the IP address and country code we log.
- Bunny Fonts. Web fonts are requested from
fonts.bunny.net, which therefore sees your IP address and user agent. - Whoever emails you. The service that you hand a TempMailer address to keeps its own records of that address under its own privacy policy. Nothing here binds them.
We do not sell personal data, and we do not share message content with anyone except where we are legally required to.
9. Security
Traffic between your browser and the site is encrypted in transit. Inbox tokens are 64 random characters, which makes them impractical to guess. Administrative access to stored mail is restricted to authenticated staff accounts. You should also know the limits: mail arrives over SMTP and whether that hop was encrypted is decided by the sender, and stored messages and attachments are not encrypted at rest. A free, anonymous, link-only inbox is not a secure channel and is not offered as one.
10. Your rights and how to delete data
If you are in the EEA or the UK you have the right to ask for access to your personal data, correction, erasure, restriction of processing, portability, and to object to processing based on legitimate interests. You may also complain to your national data protection authority. Similar rights exist under several other privacy laws, and we apply this section to everyone regardless of where you are.
To have an inbox and its messages deleted, email privacy@tempmailer.net with the full inbox link or the exact email address. Because we hold no identity information, that link or address is the only way we can locate your data — we cannot verify a claim of ownership any other way, and we will not act on a request that would expose someone else's inbox. Requests are handled manually; we aim to respond within the statutory one-month period where it applies.
11. Children
The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has used the service and you want the associated data removed, contact us and we will remove it.
12. Changes to this policy
If we change what we collect or how long we keep it, we will update this page and move the "last updated" date above. Continuing to use the service after a change means you accept the updated policy.