No account is required. The address expires automatically and is not used as a long-term identity profile.
Legal and data boundaries
Privacy Policy
This policy explains what data PostTmp processes when providing temporary email and forwarding aliases, why we process it, how long we retain it, and how you can contact us. Effective date: August 25, 2026.
Sign-in is verified through your destination email and used only to provide aliases, forwarding, and security features.
Eligible forwarded messages are retained for up to 30 days, then deleted according to the system schedule.
You can pause or delete aliases, disable two-step verification, and submit data requests through our support email.
1. Scope
This policy applies to temporary email, forwarding aliases, message storage, and account security features on posttmp.com. Sender websites, your email provider, and third-party links accessed from messages have their own privacy rules and are not governed by this policy.
Using a temporary address does not make your online activity completely anonymous. Senders may still process device, account, or transaction information under their lawful authority, so you should review their policies too.
2. Data We Process
When you use temporary email, the system processes the random address, expiry time, envelope information needed for delivery, and message content. When you use forwarding, we also process your login email, alias prefix, forwarding status, quota, creation time, message status, and any two-step verification details you configure.
To maintain security and availability, we may record request times, coarse network information, browser type, error codes, and abuse-prevention events. We do not require you to create a name-based profile for a temporary inbox.
3. Purposes and Legal Bases
We process this data to create addresses, receive and display messages, perform forwarding, verify logins, troubleshoot delivery failures, and prevent automated abuse. For services you request, processing is necessary to provide the service; security logs support our legitimate interests in protecting users and the platform.
Where local law requires consent, we will obtain it before starting the relevant optional processing. Refusing non-essential processing will not prevent you from using core features that do not require it.
4. Temporary Email Lifecycle
New temporary addresses are valid for 3 hours by default and can be extended for up to 24 hours. After expiry, the address and inbox contents enter the cleanup process, so you should not use them for long-term account recovery, financial records, or information requiring permanent access.
The same browser may store local identifiers needed for recovery while an address is still valid. Recovery may no longer work after you clear site data, close a private browsing session, or let the address expire.
5. Forwarding Aliases and Message Storage
Forwarding accounts use your real email address to receive sign-in codes and destination messages. Each alias you create can be paused, resumed, or deleted. After deletion, new messages sent to that address can no longer be forwarded under its previous settings.
On-site storage is used to view status, retry failed deliveries, and handle false positives. Eligible content is stored for up to 30 days. Attachments of 50–100MB are sent with forwarded messages but are not stored again on the site.
6. Retention Periods at a Glance
Retention starts with the shortest period needed to fulfill a specific purpose and may be reasonably extended for security investigations, dispute handling, or legal obligations. The table below describes the main limits during normal operation.
| Data category | Typical period | Purpose and deletion boundary |
|---|---|---|
| Temporary address and messages | 3 hours by default, up to 24 hours | Enters automatic cleanup after expiry; recovery is not guaranteed |
| Forwarded message storage | Up to 30 days | Used to view, retry, and mark messages as not spam |
| Alias configuration | While the account is in use | Stops being used as an active configuration after the alias is deleted |
| Security and error logs | Usually no more than 90 days | Investigate abuse, failures, and unauthorized access |
| Support communications | As long as needed to resolve the request | Retained to follow up on requests and document the outcome |
7. Cookies and Local Storage
Core features use browser local storage to save unexpired temporary email status, forwarding login tokens, the login email, and verification-code cooldowns. These items maintain your session and prevent lost progress after a refresh; they are not used to build cross-site advertising profiles.
You can clear this data through your browser settings, but doing so may remove your current address or login state. The deployment environment may automatically add basic access analytics; we do not manually add third-party ad trackers to the page code.
8. Data Sharing and Processors
To provide email routing, hosting, and security protection, necessary data may be processed by restricted infrastructure providers. We do not sell your email address or rent message content to advertisers for profiling.
We may disclose information when legally required, to protect user safety, or to investigate clear abuse. Any disclosure follows a valid process and is limited as far as possible to the data needed for the stated purpose.
9. International Processing
Internet email may pass through senders, networks, and infrastructure in different regions, so data may be processed outside your location. We use contracts, security controls, or other available safeguards as required by applicable law.
International safeguards cannot change the fact that email itself is transmitted by multiple independent providers. Do not use temporary email for highly sensitive or region-restricted data.
10. Security Measures
We use access controls, session verification, transport protection, rate limits, and optional two-step verification to reduce the risk of unauthorized access and abuse. Email HTML is displayed in a restricted iframe to reduce the chance that message content can affect the site interface.
No internet service can guarantee absolute security. Protect your primary email account, verification codes, and authenticator keys, and promptly delete tokens or contact support if you suspect account access.
11. Your Rights
Depending on where you live, you may have the right to request access to, correction or deletion of, restriction of, or objection to certain processing of your personal data. You may also have the right to receive a portable copy or lodge a complaint with a regulator. We verify the requester’s identity to avoid giving data to someone without authorization.
Some requests can be completed directly in the dashboard, such as pausing or deleting an alias. For other requests, email support@posttmp.com with the email address used, request type, and necessary verification information.
12. Children, Updates, and Contact
PostTmp is not directed at children below the applicable local age of digital consent and does not knowingly collect identity profiles about them. If a parent or guardian believes a child has improperly submitted personal data, they can contact us so we can investigate and take appropriate action.
When we make significant changes, we will update the date on this page and provide a prominent notice when necessary. For privacy questions or rights requests, contact support@posttmp.com.