Privacy Policy

Last updated: 6 August 2026.

This page follows the data, not the promises. It walks an address from the click that generates it to the moment it stops existing, and says at each step what is written down, where, and who else can see it.

The moment you generate an address

Before the click, nothing about you exists here. After it, exactly two records do.

The first is the mailbox itself: an address, the domain it was issued on, and the timestamp at which it dies. The second is a random string placed in your browser so this page can show you the same mailbox when you come back. That string is generated here, is not derived from anything about you, and is meaningless to every other website in the world.

What is absent deserves more attention than what is present. Your network address is recorded nowhere, and the reason is structural rather than a matter of policy: the database has no column capable of holding one. Look through the tables for mailboxes, for messages, for accounts, for sessions, and there is simply no place to put it. It sits in memory while one request is being answered and disappears the moment the answer goes out.

Nor is there an access log. The proxy standing in front of the application runs with logging switched off, so no file on disk records which page was fetched from where at which second. Retaining those files for months is what most sites do without ever deciding to; here they were never written in the first place.

Even the rate limiter forgets. The counter that stops one visitor spawning addresses by the thousand is a table in the memory of the running process, sweeps its own expired entries once an hour, and is wiped completely whenever the process restarts. Nothing about it survives to disk.

The seconds after, when the counter is told

Generating an address sends one event to Google Analytics. It says that a mailbox was created, whether a name was typed in by hand, and whether the domain was changed from the default. Three facts, no identifiers.

Across the life of the address four more events may reach the counter: a copy to the clipboard, an arrival of mail, a registration, a sign-in. Each of them is a tally mark and nothing else.

The address string never travels with them. Neither does any fragment of any message: the sender line stays here, so does the subject, so does every line of the body, so does the filename of anything attached. A mail service that handed those to an advertising platform would be surrendering the one thing it exists to protect, which is why the boundary sits in the code rather than in a promise on this page.

While the address receives mail

A message that arrives is written down because otherwise there would be nothing to display: sender, subject, body and any files that came with it. That material is never scanned to choose an advertisement, never sold and never handed on. The HTML is cleaned once on arrival, and that pass removes scripts, stylesheets, frames and inline styles along with everything inside them.

Images are left alone, and that has a consequence you should know about. A tracking pixel is an image one dot across, fetched from the sender's server when the message is displayed, so opening mail here tells the sender that the address is live and roughly when it was read. Removing images would end that and would also break how most ordinary mail looks, which is why the trade is made this way rather than the other. Nothing about that fetch passes through us: the sender learns what any mail client would tell them, and we learn nothing extra.

Registering adds two fields and no more: the address you sign up with, and a password put through argon2id. The password itself is written down nowhere and cannot be worked backwards out of the hash. The address you register with signs you in and receives a reset link; it has no other use here.

A guest address protects nothing by itself. No password exists on a guest mailbox, and none could exist without converting it into an account, since a password is a check against an identity and a guest has none. In practice the generated names are hard to reach by guessing, but the rule to work by is simpler than the arithmetic: whoever learns the string reads the mail. If a stranger reading it would bother you, put it behind an account instead.

Meanwhile, in other companies' systems

Cloudflare accepts every connection before it reaches this server, filters attacks and serves cached files, so it sees the address of every visitor and keeps aggregate traffic figures. That happens under Cloudflare's privacy terms rather than ours.

Cloudflare Turnstile watches the registration and password forms for signs of automation. No puzzles, and the verdict never joins an advertising profile.

Amazon SES carries password reset mail, and only that, from a separate sending domain.

Google runs the advertising and the visitor counter, and sets cookies for both. Those cookies may be used by Google and its partners to select ads from where you have been before. Personalised advertising can be switched off at Google Ads Settings or blocked in your browser; the generator works the same either way, and no page here waits for your consent before it will show you anything.

The moment the address ends

For a generated address with no account behind it, the ending comes twenty four hours after you last opened it. Pressing generate again brings that ending forward to the same second, taking the mail with it.

Registering moves the numbers rather than the principle. The mailbox then counts a week from your last sign in, any individual message inside it gets a month at the outside, and a file attached to a message shares the message's ending exactly.

Deleting here means the row leaves the table, not that a flag is set on it. The sweep runs every ten minutes, removes what has expired, and clears the attached files out of object storage in the same pass. Nothing is archived, no backup holds a second copy, and no extract is retained for analysis. Once that pass has gone by, the message is beyond producing: not for you, not for an advertiser, not for anyone arriving with a demand, because no copy remains anywhere to read it from.

After that, if you want it gone sooner

Delete the account in your settings and everything hanging off it goes in a single operation: the registered address, the password hash, every mailbox, every message, every file. A guest has nothing to delete, because pressing generate destroys the previous mailbox on the spot and doing nothing at all destroys it inside a day.

Visitors in the EU and the UK have four rights under the GDPR: to see what is held, to correct it, to erase it and to complain to a supervisory authority. They apply here, and the first one is unusually easy to answer, because the walkthrough above is the complete inventory. The third is faster still: pressing generate erases the previous mailbox before any request could be written.

Children

This is not a service for children, it is not advertised to them, and no information about anybody under 13 is held knowingly. Tell us that an account belongs to a child and it is deleted, without documents or an argument.

Revisions to this page

Any edit moves the date printed at the top. If what gets collected ever changes, the change will be explained here in plain sentences rather than tucked into a bullet somewhere.

Questions: hello@tempmailgenerator.net or the contact page.

Read next

All guides