Privacy Policy

Last updated: 16 August 2026.

This page describes what happens to data when you use Temp Mail Plus. It is written plainly because a policy nobody can read protects nobody.

The short version

We do not ask who you are. We do not have your name, your real email address or a password unless you choose to create an account. Mail sent to a temporary address is deleted automatically after a short period, and once deleted it is gone from our systems.

What we hold while you are using the service

The temporary address itself. Generated at random or chosen by you. It is linked to a random identifier stored in your browser so that the same address comes back when you reload the page. That identifier means nothing outside this site and is not shared with anyone.

Messages sent to that address. Sender, subject, body and any attachments, so that we can show them to you. We do not read them, scan them for advertising purposes or pass them to third parties.

Basic server logs. Standard web server records, including IP address and browser type, kept briefly to keep the service running and to deal with abuse.

What the database has no room for

The tables behind this service hold mailboxes, messages, attachments, accounts and sign in sessions. Not one of them has a field for a network address, a device fingerprint or a location, so no query exists that could tie an address you used on Tuesday to the one in front of you today. There is no visitor record, because there is no table it could live in.

The counters that stop a single visitor claiming hundreds of addresses in a minute are held in the memory of the running program and never reach the disk. A restart empties them. Nothing about your visit is assembled into a profile, because there is nowhere for a profile to accumulate.

The cookies we set ourselves

One for guest use. Thirty two random bytes stored under the name tm_guest, marked so that no script on the page can read it. It answers a single question, which is which mailbox belongs to this browser. It lasts thirty days, outliving the mailbox on purpose, so that coming back next week gives you a fresh address rather than an error.

One while you are signed in. A session token, of which the database keeps only a hash. A stolen copy of the database therefore hands nobody a working session.

Neither cookie carries anything about you, and neither is readable by any other website. Advertising and measurement cookies are a separate matter, set by Google, and covered further down.

How long

A guest mailbox and everything in it is deleted when you request a new address, and in any case after twenty four hours without use. If you create an account, your mailboxes are removed seven days after your last sign in, and no individual message is kept longer than thirty days.

A file arrives with a message and leaves with it, deleted from storage in the same pass. Cleanup runs on a short cycle around the clock, and it removes rows outright rather than marking them hidden, so a query for an expired address finds nothing rather than finding something withheld.

Deletion is automatic and runs continuously. There is no archive.

Accounts

If you create an account we store your email address and a hash of your password. We do not store the password itself. We use your address to let you sign in and to send password resets, nothing else. Individual mailboxes can be deleted from the account page whenever you like, and asking us to close the whole account removes the address, the password hash and everything filed under them in one operation.

Two short lived secrets travel to that address. The confirmation link issued at registration is good for twenty four hours, after which an unconfirmed registration is deleted rather than left lying about. The six digit code needed at each sign in is good for ten minutes and is destroyed after five wrong guesses. Both are kept as hashes, in the same way as the password and the session token, so a dump of the database is not a set of working keys.

What the analytics counts

Five events are recorded and this is the entire list: a mailbox was created, an address was copied, a message arrived, somebody registered, somebody signed in. Each is a count with no content attached to it.

Analytics never sees the address itself, and it never sees the contents either: sender, subject, body and file names all stay out of it. What the numbers show is how many people copied an address and how many sat waiting for mail that never came, which is how we find out that something is broken.

Who else is involved

Incoming mail is received through Cloudflare, which operates the mail servers that accept messages before they reach us. Attachments are stored with Cloudflare R2. Our servers are hosted with DigitalOcean.

Cloudflare Turnstile guards the registration, sign in and password reset forms, looking for the signatures a script leaves when it fills a form. It asks you to identify nothing and feeds nothing into an advertising profile. It is absent from the mailbox itself, where there should be no obstacle at all.

Confirmation links, sign in codes and password resets are delivered through Amazon SES and arrive from no-reply@tempmailplus.net. That address only sends, and mail written back to it goes nowhere.

We show advertising through Google AdSense. Google may use cookies to serve ads based on your prior visits to this and other websites. You can opt out of personalised advertising in Google Ads Settings.

We use Google Analytics to count visits and understand which pages are useful. It tells us how many people read a page, not who they are.

Anyone can open a guest mailbox

This is not a bug and it matters, so it belongs in the privacy policy rather than the small print. A guest address has no password. Anyone who knows or guesses the address can read what arrived at it. Do not use a temporary address for anything you would mind a stranger seeing, and do not use it for accounts you need to keep.

A mailbox created inside an account is closed to outsiders: signing in is the only way to see what is in it.

Your rights in the EEA and the UK

Data protection law there lets you see what is held about you, have it put right or wiped, object to a particular use of it, and take a complaint to your national regulator. Those rights apply here and are unusual mainly for how little they have to work on. A guest leaves behind an address, whatever mail reached it and a random token in a browser, and every part of that erases itself within a day of the last visit.

For an account there is more to erase and it is still a short list: the address you registered with, a password hash, your mailboxes and their messages. One request closes the account and takes all of it at once, and there is nothing left afterwards to send you a copy of.

Children

The service is not directed at children under 13, and we do not knowingly collect information from them. Tell us if a child has registered here and we will take the account down together with everything inside it.

Changes

Every revision of this policy moves the date printed above. Material changes will be noted on this page rather than applied quietly.

Contact

Questions about this policy: contact page.

Read next

All guides