Privacy Policy
Last updated: 18 August 2026
This policy explains the information TempMails needs for guest inboxes and optional Google member features, together with the safeguards and limits that apply.
1. Guest and member access
A random 10-minute inbox does not require an account, name, permanent email address, phone number, or password. Google sign-in is optional and is required only for member features such as reserved custom addresses, longer timers, and inbox extension.
2. Google account information
When you choose Google sign-in, TempMails receives the stable Google account identifier, verified email address, and display name supplied through Google OpenID Connect. We use the stable account identifier—not the email address—as the account key. TempMails does not request Gmail messages, contacts, Google Drive files, or a Google password, and does not store Google access or refresh tokens.
3. Member ownership and activity records
To enforce custom-address ownership and investigate abuse or account disputes, TempMails links member-created mailboxes to the member record. It records sign-in, mailbox creation, extension, and deletion events. While a Google member is signed in, the browser sends periodic authenticated heartbeats while the site is visible so TempMails can maintain an approximate cumulative active-time total and last-seen timestamp. Hidden or long-idle gaps are not counted, and guests are not included in this member timer. Event records are scheduled for deletion after 90 days; cumulative active time and last seen remain with the member record until the account is deleted. A custom-address reservation remains linked to the member account while that account exists so another member cannot claim it.
4. Administrative access and records
Allowlisted administrators can view Google member email addresses, names, account status, mailbox counts, reservation counts, activity-event totals, approximate cumulative active time, and last-seen timestamps. Administrators can block member access or delete a member account. Administrative changes are recorded with the administrator email, action, target, and timestamp and are scheduled for deletion after 365 days.
5. Mailbox content and retention
To receive and display email, the service processes the temporary recipient address, sender details, subject, message content, headers, and permitted attachment data. The operator configures per-attachment and total-email size limits; an oversized attachment is not stored, while an oversized complete email can be rejected by the SMTP receiver. Messages remain available only while an eligible recipient mailbox is active and are then removed by scheduled cleanup, with a 24-hour failsafe maximum. Expired mailbox records are also removed automatically. Do not use the service for sensitive or irreplaceable information.
6. Mailbox access and browser storage
A random mailbox access token is generated when an inbox is created, while only its cryptographic hash is stored on the API server. The browser stores the temporary address, private mailbox token, selected tier, and expiration time so the inbox can survive a refresh. Google sign-in uses a protected session cookie. Deleting an inbox removes its local mailbox session and requests deletion of its messages.
7. Operational information
The service may process limited request information such as IP address, browser user agent, timestamps, rate-limit signals, and errors in rotating infrastructure logs for reliability, security, and abuse prevention. This information is not added to the member activity table by the application.
8. Visitor analytics
TempMails enables its first-party visitor counter and configured Google Tag Manager analytics by default unless the browser opts out in the controls below. The first-party counter gives the browser a random HttpOnly identifier and sends only a keyed hash of it to the TempMails analytics database; it does not add the raw identifier, IP address, browser user agent, email content, mailbox access token, or Google account identifier to the visitor tables. Google Tag Manager may load configured Google Analytics tags, which send website usage and device information to Google under Google's terms and privacy controls. A repeat visit is counted after at least 30 minutes without activity. Counts can be affected by cookie deletion, multiple devices, or blocked storage. Daily first-party visitor rows are scheduled for deletion after 90 days, and an inactive visitor profile after 400 days.
9. Received content and external links
Emails are supplied by third parties and may contain deceptive links or unsafe content. TempMails blocks remote images in its message preview to reduce tracking, but you remain responsible for links you choose to open.
10. Security and abuse prevention
Reasonable technical controls are used to protect mailbox sessions, authenticate member-only and administrator requests, and limit abuse, but no internet service can promise absolute security. Do not submit passwords, financial data, identity documents, medical data, private keys, or confidential business information.
11. International use
TempMails is accessible in multiple countries. Information may be processed where the service infrastructure and its providers operate, subject to applicable requirements.
12. Visitor analytics choices
Analytics are enabled by default for a new browser. You can disable them or enable them again at any time. Disabling prevents Google Tag Manager from loading on future page loads, deletes the first-party analytics cookie, and requests deletion of the corresponding hashed visitor profile and daily rows.
Current choice: loading preference
13. Access, deletion, contact, and changes
To ask about member data or request account deletion, email service@tempmails.co.in from the Google account email connected to the membership. Material policy changes will be published here with an updated date.
Review this policy against your actual hosting, analytics, logging, retention, and legal requirements before production deployment.