Last updated: 29 September 2026
This policy explains what TempsMail does with information about you. It describes the service as it actually works today. Where we say we keep something for a set number of days, that number is the one configured on our servers, not an estimate.
TempsMail.org is operated by XCORP, business registration number 0315842874.
Write to that address for anything in this policy, including requests to delete data. It reaches a person, not a ticket queue.
This is the single most important thing on this page, so it comes first rather than buried in a clause.
A temporary address has no password. Anyone who types the same address into TempsMail sees the same messages. That is how the service works and it is not a flaw we intend to fix — the whole point is that you can open an inbox without proving who you are. The practical consequence: do not have anything sent to a temporary inbox that you would mind a stranger reading. No bank statements, no identity documents, no password resets for accounts that matter, no private correspondence.
When you open an inbox we record the address, the domain it uses, the IP address the request came from, and a short technical fingerprint of the browser. The IP and fingerprint exist for one reason: people abuse free mail services to send spam, register fake accounts in bulk and probe other sites, and without them we cannot tell one abusive script from thousands of ordinary visitors.
Deleted means deleted. We do not keep a second copy of expired mail, we do not read the messages, and we do not use their contents to select advertising.
An account is optional; the service works without one. If you make one, we store your first and last name, email address, country, an avatar if you upload one, and a password stored as a cryptographic hash rather than as text. You can sign in with Google or Facebook instead, in which case we receive the basic profile details those services hand over — we never see your password for them.
Accounts that use the API also have an API key, which identifies your requests.
Ask us by email and we will delete your account and everything attached to it.
Our web servers keep standard access logs — IP address, time, page requested, browser string. They are used to investigate faults and abuse and are rotated on a short cycle.
We use a small number of outside services. Each one receives your IP address because that is unavoidable when your browser fetches something from them, and most set their own cookies. Here is the complete list, with what each is for.
| Service | What it does here | Cookies it sets |
|---|---|---|
| Google Analytics 4 | Counts visits and shows which pages get used | _ga, _ga_QQWYJGBK20 |
| Google AdSense | Selects and displays the advertising on this site | _gcl_au, and cookies on doubleclick.net |
| Google Funding Choices | Shows the consent notice and records your choice | FCCDCF, FCNEC |
| Hotjar | Records how pages are used — scrolling, clicks, where people get stuck | _hjSessionUser_…, _hjSession_… |
| Google reCAPTCHA | Separates people from automated scripts | _GRECAPTCHA |
| Cloudflare | Serves the site worldwide and absorbs attacks | cf_clearance |
| Google Fonts, jsDelivr | Deliver typefaces and code libraries | none |
Our own cookies are few: locale remembers which language you chose,
XSRF-TOKEN and tempsmail_session keep your session working and
protect forms from being submitted by other sites on your behalf.
This site carries advertising, and that is what pays for it. Google and its partners use cookies to choose which advertisements you see, which may be based on your earlier visits to this and other websites. You can turn personalised advertising off at Google Ads Settings, or opt out of third-party vendors at aboutads.info. The advertisements will keep appearing; they simply stop being tailored.
Hotjar records how pages are used so we can find broken layouts and confusing steps. It captures movement, clicks and scrolling. It does not capture the contents of your temporary inbox. You can opt out permanently at Hotjar's do-not-track page.
Depending on where you live you may have the right to ask what we hold about you, to have it corrected or erased, to object to how we use it, and to receive a copy. Email [email protected] and we will deal with it within 30 days.
Two honest caveats. First, most of what this service holds disappears on its own within days, so by the time a request arrives there is often nothing left to delete. Second, because temporary inboxes are anonymous by design, we frequently cannot tell whether a particular inbox was yours — we will not hand over its contents to someone who merely claims it.
If you are unhappy with how we handled a request, you can complain to your national data protection authority.
Our servers are in Vietnam and the service is delivered through Cloudflare's global network. The outside services listed above process data in their own locations, including the United States, under their own agreements.
This service is not intended for children under 16 and we do not knowingly collect their information. If you believe a child has sent us personal data, email us and we will remove it.
When this policy changes we update the date at the top. The previous version was replaced in full on 29 September 2026 because it had been inherited from a different company's template and described a product this site is not.