Temporary email
We create random addresses and session identifiers for receiving mail, with a maximum service period of 24 hours.
This policy explains what data BoxTmp processes when providing temporary inboxes and permanent forwarding, why we process it, how long we keep it, and how you can contact us.
We create random addresses and session identifiers for receiving mail, with a maximum service period of 24 hours.
Sign in with an email verification code; aliases remain active until paused or deleted, while archives are kept for up to 30 days.
We record limited request, timing, and technical information to prevent abuse and troubleshoot problems.
You can change a temporary address, delete an alias, disable 2FA, or contact support to make a request.
| Data category | Purpose | Typical retention limit |
|---|---|---|
| Temporary address, emails, and session identifiers | Create an inbox, display messages, and extend a session | Address: up to 24 hours; not retained as a long-term mailbox record |
| Login email, aliases, and security settings | Authentication, forwarding, alias management, and 2FA | For the life of the account relationship or as long as necessary after deletion |
| Forwarded email archives and small attachments | View status, retry delivery, and troubleshoot problems | Up to 30 days |
| Request logs and security events | Rate limiting, abuse prevention, reliability, and compliance | Retained for a limited period as needed for security |
This policy applies to the temporary email, forwarding alias, dashboard, and support channels provided by boxtmp.com. How a third-party website handles information you submit there is governed by its own policy.
We process data only as needed to provide the service and take on the applicable role of data controller or service provider depending on the circumstances. This policy does not promise that a temporary email will hide your device, network, or identity information that you voluntarily submit to third parties.
A temporary email normally requires no registration, but the sender will send sender details, the subject, message body, and any attachments to the generated address. When using permanent forwarding, you provide a destination email, alias prefix, verification code, and optional two-step verification code.
When contacting support, you may provide a description of the issue, when it occurred, and necessary screenshots. Do not send passwords, full verification codes, identity documents, or sensitive message content unrelated to troubleshooting through support channels.
To maintain sessions, check expiration times, and protect our interfaces, we process session identifiers, request times, response statuses, IP addresses, and limited browser or device information. Your browser stores the current temporary email session and forwarding login token locally so your state can be restored after a refresh.
This information is used to operate the service, enforce security controls, and diagnose faults—not to build cross-site advertising profiles. You can clear browser storage, but doing so may erase your current session or login state.
Our core purposes include creating mailboxes, receiving and displaying messages, forwarding mail to a specified address, showing delivery status, and verifying identity. Processing also supports rate limits, malicious automation detection, and protection for users and infrastructure.
Where required by applicable law, we may also retain necessary records to handle complaints, meet legal obligations, or protect legitimate rights. We do not use message content for targeted advertising.
Temporary addresses are active for 3 hours by default and may be extended, but never beyond 24 hours from creation. After a session ends, you should not rely on the address for recovery messages or treat it as long-term email storage.
The system must temporarily process message content and attachments to deliver mail. Dangerous content, oversized messages, or traffic that violates our service rules may be rejected, quarantined, or deleted.
Forwarding aliases deliver incoming mail to your real destination inbox without revealing the real address to ordinary senders. The dashboard may provide email archives for up to 30 days so you can check status, mark messages as not spam, or retry failed deliveries.
Large attachments between 50–100MB may be forwarded with the original message but are not stored again in the dashboard. Deleting an alias does not automatically delete copies already received in your real mailbox.
Different data is retained according to its functional limits; see the table on this page for details. We delete or anonymize data when the retention period ends, the purpose is fulfilled, or a valid deletion request is confirmed, although secure backups may remain during a limited rotation period.
Legal obligations, dispute resolution, fraud investigations, or system integrity may require limited retention for longer. These exceptions cover only what is necessary, with access restricted.
We use access controls, encryption in transit, rate limiting, log reviews, and optional two-step verification to reduce risk. No online system can guarantee absolute security, so important accounts should not rely on a temporary address.
If you suspect that your forwarding dashboard has been accessed, sign out immediately, review the security of your destination mailbox, and enable two-step verification. Report vulnerabilities responsibly through the support email, and do not access anyone else’s mail.
Our infrastructure or service providers may be located outside your region, so data may be processed across borders. We use applicable contractual, technical, and organizational measures to protect such transfers.
This service is not intended for children who cannot legally consent to data processing. If a parent or guardian believes that a minor has improperly provided personal data, they can contact us so we can investigate and take action.
Depending on where you live, you may have rights to access, correct, delete, restrict processing, object, or obtain a portable copy of your data. Because temporary email is registration-free and short-lived, we may be unable to reliably link an anonymous session to an individual without collecting more information.
When making a request, describe the feature involved, the relevant time period, and verifiable information showing your control. We will verify the requester’s identity and respond within the applicable period, or explain why we cannot comply.
We may update this policy when there are significant changes to features, laws, or service providers. The new version will show its effective date on this page, and we will provide reasonable notice of material changes.
Continuing to use the service after an update means you have seen the new policy, but it does not reduce any mandatory rights granted to you by law. We recommend checking this page periodically if you use forwarding over the long term.
Send privacy questions, data requests, or security reports to support@boxtmp.com. Provide enough context to help us locate the issue, while avoiding unnecessary sensitive content.
We will confirm receipt and handle the request within a reasonable period based on its complexity and applicable law. If the issue involves a third-party email service, you may also need to contact that service directly.