Privacy Policy · Updated August 27, 2026

What data we keep—and when it is deleted

This policy explains how TempLetter handles temporary inboxes, forwarding accounts, and access logs. We keep data lifetimes as short as possible, but a temporary address is not the same as complete anonymity.

Retention periods and processing limits

Different features serve different purposes, so not all data follows the same clock. The table below shows our usual limits; security investigations, legal requirements, or disaster recovery may require limited exceptions.

Data categoryPurposeTypical retentionAfter expiration
Temporary addresses and tokensCreate an inbox and verify access3 hours by default; users can extend itExpires and enters automatic cleanup
Temporary email content and attachmentsRead received email in the web inboxFor the life of the mailboxContent, attachments, and indexes are deleted
Forwarding aliases and account emailsLong-term forwarding and loginWhile the account or alias existsReceiving stops when the alias is deleted; account requests require separate verification
Forwarding email archiveReview delivery, failure, and spam statusUp to 30 daysRolling deletion
Security and access logsRate limiting, abuse prevention, and troubleshootingKept briefly as needed for securityAggregated, rotated, or deleted

1. Scope

This policy applies to the temporary email, web inbox, forwarding aliases, login console, and related support communications provided by templetter.com. Third-party sender websites, network operators, and external links you open have their own policies and are not governed by this policy.

When you submit an address to a third party, that party may still retain the address, device, payment, or account information. TempLetter can reduce direct exposure of your real email, but it cannot eliminate other ways third parties may identify you.

2. What we collect

Temporary features process generated addresses, access tokens, expiration times, received-email envelope information, message content, and attachments. Forwarding features also process your login email, created aliases, delivery status, sender information, and necessary account security status.

While the service is running, we may log request times, network addresses, browser types, API results, and anti-abuse signals. We do not require temporary inbox users to create a name profile, and we do not build advertising profiles by reading email content.

3. Processing purposes

We process data only to generate addresses, display messages, forward incoming mail, maintain archives, verify logins, enforce rate limits, and troubleshoot failures. Necessary security analysis helps prevent bulk abuse, malicious attachment distribution, and attacks on our infrastructure.

Our support team accesses necessary records only to resolve issues you raise, investigate security incidents, or comply with valid legal obligations. Access must be proportionate to the specific task and is restricted by internal permissions.

4. Temporary inboxes

Temporary inboxes use a random token held by your browser to control access. Anyone with the token may be able to view the inbox, so do not share the full link or browser storage. Addresses are valid for 3 hours by default; extending an address changes its expiration time.

Expiration means the address should no longer be treated as a recoverable identity. Cleanup is not guaranteed to occur at a particular millisecond, but the system removes available records according to their lifecycle. Do not rely on recovery after expiration.

5. Forwarding aliases and real email addresses

Your login email is both the address that receives verification codes and the forwarding destination. Senders typically see only the alias, but the mail delivery system must know the real destination to complete forwarding.

Pausing an alias stops future forwarding; deleting it ends that entry point. Deletion does not recall copies already delivered to your real inbox. Manage emails you have already received independently through your real email provider.

6. Email content and attachments

To display or forward messages, the system must briefly process their content, HTML, and attachments. Real HTML email is rendered in a restricted viewing frame, but attachments may contain risks; verify their source before downloading or opening them.

We do not promise that scanning will detect every malicious element, and email archives are not permanent backups. Save important files somewhere you control and can back up.

7. Cookies and browser storage

We may use localStorage or sessionStorage to store temporary email tokens, expiration times, forwarding login tokens, login emails, and verification-code cooldowns. This data helps restore sessions after a refresh and prevents repeated code requests within a short period.

You can clear local data through your browser settings, but doing so may immediately remove access to an unexpired temporary inbox or sign you out of the console. We do not use third-party advertising cookies to build cross-site tracking profiles.

8. Sharing and processors

Infrastructure providers may need to process limited data to support email receipt, storage, forwarding, hosting, and security protection. We require them to process data only for service purposes and to apply safeguards proportionate to the risks.

We do not sell temporary email content or account email addresses. If a corporate reorganization occurs, related data may be transferred only as needed to continue providing the service and comply with this policy and applicable law.

9. Legal requests

When we receive a valid legal request from an authority with jurisdiction, we may retain or disclose the specifically identified data. We review the scope of each request and, where legally permitted, seek to limit disclosure.

We may be unable to notify you in advance if the law prohibits notice or if notice would hinder an investigation. Data that does not exist cannot be provided, so short lifetimes remain our primary way to reduce exposure.

10. Security measures

We reduce the risk of unauthorized access through access tokens, verification codes, optional two-step verification, access controls, rate limiting, and protection in transit. No internet service can guarantee absolute security, especially for email content that can be forwarded or copied.

If you suspect a token has been exposed, create a new temporary address immediately. If your forwarding account behaves unexpectedly, sign out of other sessions, check your aliases, and enable two-step verification. Send security concerns to support@templetter.com.

11. Your rights and choices

From the console, you can copy, pause, resume, or delete aliases and let a temporary mailbox expire naturally. Where applicable law provides for it, you may also request access to, correction of, or deletion of account-related information.

To prevent account takeovers, we must verify that the requester controls the login email. Some minimal records may be retained temporarily for security, dispute resolution, or legal obligations.

12. Children, changes, and contact

This service is not designed for children below the applicable local age of digital consent, and we do not encourage using temporary email to bypass age restrictions. If a parent or guardian believes a child has submitted personal information, they can contact us for review.

When this policy changes materially, we will update the date on this page and provide additional notice where appropriate. For privacy questions, contact support@templetter.com; do not include sensitive identity documents or full email passwords in ordinary support messages.