Privacy Policy

TempMailGrab is built to collect as little as possible. This page explains exactly what we store, what we never do, and how temporary inboxes are deleted.

Summary

We do not run ads, we set no advertising or analytics tracking cookies, and we never sell your data. Disposable inboxes and the messages they receive are deleted automatically when the inbox expires.

What we store

  • Disposable inboxes & messages — the address you generate and any email it receives, kept only until the inbox's time-to-live (TTL) expires, then permanently purged.
  • A session cookie — an HMAC-signed, httpOnly cookie that privately ties inboxes to your browser so only you can read them. It holds no personal data.
  • Accounts (optional) — if you create an API account, we store your email address (or GitHub identifier) and a salted password hash. Nothing more.
  • Abuse-prevention metadata — transient request data used only to rate-limit and stop abuse, not to profile you.

What we never do

  • No advertising — no ad networks, no ad cookies, no ads.txt.
  • No third-party trackers, analytics fingerprinting, or cross-site profiling.
  • No selling, renting, or sharing of personal data.

Incoming email

Mail sent to a disposable address is received at the edge, parsed, and shown to you. HTML is sanitized before it is displayed, and one-time passcodes and verification links are extracted for convenience. Everything is deleted when the inbox expires.

Infrastructure

TempMailGrab runs on Cloudflare's edge network (Workers, D1, R2, Queues, and Email Routing). All traffic is encrypted in transit over TLS, and Cloudflare acts as our infrastructure processor.

Your choices

You can delete an inbox at any time from the homepage, or simply let it expire. Account holders can revoke API keys and remove webhooks from the dashboard at any time.

Contact

Questions about this policy? Email privacy@tempmailgrab.com.

Last updated: August 2026.