Addresses and messages are cleared when they expire
No account is required. When an address expires or is replaced, the temporary inbox and its messages enter the deletion process.
Privacy Policy · Updated September 4, 2026
This policy explains what data TMPFox processes when you create a temporary inbox, sign in to your workspace, set up an alias, or view delivery records—and how you can control it.
No account is required. When an address expires or is replaced, the temporary inbox and its messages enter the deletion process.
Alias accounts need a receiving email for sign-in and forwarding. Message records are used only for troubleshooting, retries, and your review.
We don’t sell or rent personal information, build advertising profiles from message contents, or require you to set a password to sign in.
You can delete aliases and message records, or request access to or deletion of account information at support@tmpfox.com.
This policy applies to temporary email, email alias forwarding, verification-code sign-ins, 30-day delivery records, and support services on tmpfox.com. TMPFox is the data controller for these website features. When an email is sent by an external sender, that sender may also process the same message under its own policy.
This policy does not cover external links in messages, third-party websites where you use an alias to register, or third-party authenticator apps. Read their privacy notices separately before using those services.
Temporary email processes a random address, access token, expiration period, sender and recipient envelope information, subject, message body, attachments, and arrival time. Temporary mode does not require your name, password, or real receiving email, but anything sent to a public address may contain information voluntarily included by the sender.
The alias service processes your receiving email, verification-code sign-in status, alias address, enabled or paused status, quota, delivery status, and message records from the past 30 days. If you enable two-step verification, we store its enabled status and protected authenticator key material, but do not collect other content from your authenticator account.
We use this information to create and maintain inboxes, deliver alias messages to the specified destination, display message contents, detect spam, retry failed deliveries, and respond to support requests. Technical logs also help limit abuse, detect unusual access, diagnose delivery failures, and keep the service available.
We do not read message contents for behavioral advertising or create marketing profiles from shopping, identity, or interest information in messages. Statistics are used only in aggregate to understand service capacity and error rates; our hosting platform may automatically add necessary access metrics.
| Data category | Typical use | Maximum retention limit |
|---|---|---|
| Temporary addresses and messages | Receive, display, delete, and download attachments | Current active period; cleared after expiration or address replacement |
| Alias delivery records | Review, spam detection, and failed-delivery retries | 30 days |
| Account and alias settings | Verification-code sign-in, forwarding destination, status, and quota | While the account or alias remains active |
| Security and technical logs | Rate limiting, abuse prevention, and troubleshooting | Limited period needed for security purposes |
| Support correspondence | Respond to requests and document resolution | Until the request is resolved and for any necessary follow-up period |
Temporary inboxes operate for the active period shown on the page. When you replace an address, delete a message, or the active period ends, the relevant content is cleared from the online service. Brief queues or disaster-recovery copies in distributed systems may take a limited time to be overwritten.
Alias delivery records are kept for up to 30 days, and individual messages can be deleted sooner. Account settings are retained while you continue using the service. If a legitimate security investigation, dispute, or legal obligation requires longer retention, we keep only what is necessary.
The service reduces risk through short-lived verification codes, access tokens, optional authenticator codes, permission separation, rate limits, and encryption in transit. Administrator access and internal delivery interfaces also use network boundary controls; ordinary user interfaces receive only the permissions needed to complete an action.
Internet email is not stored with end-to-end encryption, and public temporary addresses may be guessed or forwarded. Do not use temporary email for bank, government, medical, or other highly sensitive accounts, and do not treat the email service as a permanent vault.
We use browser local storage to save temporary inbox tokens, sign-in tokens, and necessary interface state so you can continue your current task after refreshing the page. Deleting site data removes these local credentials and may prevent you from accessing a random inbox that has not yet expired.
Security logs may contain your IP address, browser type, request time, and error result. This information is used for abuse prevention and troubleshooting, not for cross-site advertising tracking.
Email senders, your receiving email provider, and our infrastructure may be located in different countries or regions, so delivery may involve international transfers. We protect these transfers using contracts, security controls, and data minimization as required by applicable law.
Data protection rules may differ between jurisdictions. If your region requires a specific transfer mechanism, contact support to learn about arrangements relevant to your request.
You can copy, pause, or delete aliases directly in the workspace, and delete individual delivery records. For account data associated with a receiving email, you may request access, correction, deletion, restriction of processing, or object to processing. We may first verify that you control the email address.
Some requests may be limited by law, security needs, or the rights of others. We will explain why we cannot fulfill a request and, where applicable, tell you how to complain to your local regulator.
The service is not intended for children who cannot legally consent to data processing independently, and we do not knowingly collect their account information. If a parent or guardian believes a child has submitted personal information to the service, contact us so we can investigate and take appropriate deletion measures.
The fact that a temporary address requires no registration does not mean it is suitable for children to use independently. Parents and guardians should assess external website content and email risks.
If features, retention practices, or legal requirements materially change, we will update the date on this page and provide notice where appropriate. Significant changes will not retroactively expand the purposes for which already-collected data is used unless we obtain valid authorization or the law permits it.
Review the latest text before continuing to use the service. Historical disputes are assessed under the policy and applicable law in effect when the relevant processing occurred.
Send privacy questions, data requests, or security reports to support@tmpfox.com. Say whether your request concerns a temporary inbox or an alias account, and avoid including unnecessary sensitive message content.
To prevent someone else from claiming or deleting your information, we may ask you to complete one verification from the associated receiving email. We will respond within the period required by applicable law and explain the status of complex requests.