Privacy Policy
Last updated: July 24, 2026
Scope
This Privacy Policy explains how Temp Mail Lab ("Temp Mail Lab," "we," "us," or "our") collects, uses, stores, and discloses information as you use tempmaillab.com, generate a temporary inbox, browse our informational pages, or contact us.
Temp Mail Lab is designed to minimize persistent data collection, but the service necessarily processes inbox content, security data, and limited browser-side storage in order to create disposable email addresses, deliver messages, and prevent abuse.
Information We Process
Temp Mail Lab processes the following categories of information:
- Temporary inbox data: generated email address, server-side session token, session expiry, recovery key details only for workflows that offer recovery, and any custom local-part or domain selection you submit. The 10 Minute Mail page does not create a recovery key.
- Message data: sender address, subject line, message text, rendered HTML content, received timestamp, and deletion status for messages routed to your temporary inbox.
- Security and service integrity data: IP address or rate-limit keys derived from it, browser and request metadata, anti-bot verification results, and service interaction timing used to prevent abuse, fraud, and automated attacks.
- Browser storage data: theme preference and session-related values stored locally in your browser so the active inbox can persist across page loads.
- Communications: information you voluntarily send to us through support, privacy, or legal email contacts.
How We Use Information
We use the information above to:
- Create and maintain disposable inbox sessions.
- Receive, display, sanitize, and delete temporary email messages.
- Generate and honor recovery keys that restore inbox access.
- Enforce abuse controls, rate limits, bot checks, and security rules.
- Maintain site functionality, troubleshoot errors, and improve reliability.
- Respond to support, privacy, legal, and abuse inquiries.
- Comply with legal obligations and protect our rights, users, and infrastructure.
Legal Bases for Processing
For jurisdictions that require a legal basis for processing, Temp Mail Lab relies on one or more of the following:
- Performance of a service request for creating or restoring a temporary inbox.
- Legitimate interests in securing, operating, and improving the service and preventing abuse.
- Legal obligations for disclosure or retention required by applicable law.
- Consent for processing activities that require consent under applicable law.
Cookies, Local Storage, and Similar Technologies
Temp Mail Lab uses scoped, HttpOnly session cookies so the server can authorize inbox requests. The regular inbox and 10 Minute Mail use separate cookie names; the short-lived cookie is limited to its own API path. Browser local storage is used for non-secret interface state such as the regular inbox display metadata and theme preference. The 10 Minute Mail address, countdown, and message list are not persisted in localStorage or sessionStorage.
Clearing cookies, using private browsing modes, or switching devices can remove access to the current inbox. A Recovery Key can restore an eligible regular inbox, but 10 Minute Mail has no recovery mechanism. Third-party security or advertising technologies use their own cookies or similar identifiers under their respective policies.
Retention and Deletion
We keep different categories of data for different periods based on the technical needs of the service:
- Temporary addresses, session records, and recovery records: remain available for up to 30 days.
- 10 Minute Mail: starts with a 10-minute server session and has no recovery record. Before expiry, an active user can reset the remaining server window to 10 minutes; repeated resets do not accumulate. The address stops receiving when that session ends.
- Received messages: are intentionally short-lived and are normally deleted about 15 minutes after receipt. On an initial 10 Minute Mail session the limit is 10 minutes; after a timer reset it is capped at 15 minutes from receipt. Messages can disappear sooner after user deletion, inbox expiry, security review, or maintenance removal.
- Presence, rate-limit, and anti-abuse records: are kept only for the limited period needed to secure and operate the service.
- Browser-side storage: remains on your device until it is replaced, expires, or you clear it manually.
Temp Mail Lab is not a permanent email archive. Do not use the service for records you need to retain long term.
Sharing and Service Providers
We do not sell temporary inbox content. We share limited information with service providers and processors that help us operate the site, including:
- Cloudflare for hosting, edge delivery, worker APIs, email routing, and bot protection.
- Sanity for blog and content management pages.
- Advertising partners for production ad delivery, ad measurement, and ad-fraud prevention after user interaction.
- Payment and account providers for premium checkout, subscriptions, authentication, and account access.
- Professional advisers, law enforcement, regulators, or other parties for legally required disclosures or investigations of abuse, fraud, and security incidents.
Third-Party Service Providers and Privacy Links
Temp Mail Lab relies on third-party services to host, secure, publish, monetize, authenticate users, and process paid features. These providers process limited information under their own privacy policies.
- Cloudflare and Cloudflare Turnstile: hosting, edge delivery, email routing, security controls, rate limiting, and bot protection. See the Cloudflare Privacy Policy.
- Sanity: blog and content management. See the Sanity Privacy Policy.
- Supabase: premium account authentication and related account services. See the Supabase Privacy Policy.
- Paddle: card, PayPal, and subscription checkout processing. See the Paddle Privacy Policy.
- Whop: card, subscription, and checkout processing when Whop is offered as the payment provider. See the Whop Privacy Policy.
- NOWPayments: cryptocurrency checkout and donation processing. See the NOWPayments Privacy Policy.
- Monetag and advertising partners: production ad delivery, ad measurement, and fraud prevention after user interaction. See the Monetag Privacy Policy.
- Google AdSense: advertising delivery, measurement, and fraud prevention. Google and its advertising partners may use cookies, web beacons, IP addresses, or similar identifiers when ads are enabled. Learn how Google uses information from partner sites.
Advertising Choices and Consent
Third-party vendors, including Google, may use advertising cookies to show and measure ads based on visits to this and other websites. You can manage Google ad personalization through Google Ads Settings. Other advertising partners provide their own privacy and opt-out controls.
Where required, advertising cookies and personalized advertising must remain disabled until the visitor makes a consent choice. Google advertising will not be served to visitors in the EEA, the United Kingdom, or Switzerland until a Google-certified consent management platform is active.
Third-Party Links
Temp Mail Lab links to third-party websites, tools, payment pages, documentation, or service-provider pages. Those websites are governed by their own privacy policies and terms. We are not responsible for the content, security, or privacy practices of websites that we do not operate.
Online Privacy Policy Only
This Privacy Policy applies to information processed through Temp Mail Lab websites, tools, and online services. It does not apply to information collected offline or by third-party websites that are not operated by Temp Mail Lab.
International Processing
Our hosting and infrastructure providers process information in multiple countries. By using the service, you understand that data can be transferred to and processed outside your country of residence, subject to applicable law and provider safeguards.
Security
We use reasonable technical measures intended to protect the service, including HTTPS, security headers, rate limiting, bot protection, session-based authorization, and HTML sanitization for rendered email content. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Anyone who obtains your session token or recovery key can access the related inbox. Treat recovery keys as sensitive access credentials.
Your Choices and Privacy Rights
You can stop using the service at any time, delete messages from the interface, and clear your browser storage locally. If privacy law in your jurisdiction grants you rights such as access, deletion, or objection, you may contact us to submit a request.
Because Temp Mail Lab does not maintain a conventional user account, we cannot always identify a requester unless they can demonstrate control of the relevant session or recovery key.
Children's Privacy
Temp Mail Lab is not directed to children under 13, and we do not knowingly collect personal information from children in a manner that would require parental consent under applicable law. If you believe a child has provided us information inappropriately, contact us so we can review and address the issue.
Changes to This Policy
We update this Privacy Policy to reflect product changes, legal requirements, or operational updates. The version posted on this page is the version currently in effect, and the "Last updated" date above identifies the latest revision that became effective.
Contact Us
For privacy questions or requests, email privacy@tempmaillab.com. For general support, contact support@tempmaillab.com.