Temporary inboxes are short-lived
Addresses, tokens, and messages enter the deletion process when their validity ends; they are not permanent cloud storage.
Privacy notice · Updated September 15, 2026
This notice explains what data TempVeil processes in temporary inboxes and logged-in forwarding workspaces, why we process it, how long we keep it, and how you can delete or control it. We do not sell personal data or use message content for advertising profiles.
Addresses, tokens, and messages enter the deletion process when their validity ends; they are not permanent cloud storage.
Delivery records in logged-in workspaces are retained for up to 30 days by default to help troubleshoot delivery status.
Your receiving email is used for verification codes and alias forwarding, and is not shown to people who email the alias.
You can rotate your inbox, delete messages or aliases, end your session, or contact support to request data actions.
This notice applies to the temporary email, message reading, verification-code login, public alias forwarding, delivery records, and two-step verification features provided by tempveil.com. It does not apply to third-party websites in messages, senders’ data practices, or external services you access from message content.
Temporary inboxes can be used without an account; forwarding workspaces require verification-code login with a receiving email address. The data boundaries and retention periods differ between these modes, as explained below.
Temporary email features process system-generated addresses, access tokens, expiration times, sender addresses, subjects, timestamps, HTML or plain-text content, and necessary attachment information. Forwarding features also process login emails, alias prefixes, delivery status, and security settings.
To operate the service, we record limited network and technical logs, such as request times, IP addresses, browser information, API results, and summaries of errors. Logs are used for rate limiting, security investigations, and troubleshooting—not to build cross-site advertising profiles.
Some data is provided directly by you, such as your login email, alias prefix, and authenticator code. Other data comes from sending systems that deliver messages to temporary addresses or forwarding aliases, including message headers, content, and delivery times.
The system also automatically generates email addresses, access tokens, session tokens, and security event records. Please do not send other people’s sensitive information to public or short-lived addresses.
We process message data to receive, display, forward, and troubleshoot email. We process login emails to send verification codes, identify forwarding destinations, and maintain account sessions. Security logs help prevent abuse, protect infrastructure, and identify unusual requests.
Without this data, the relevant features cannot operate. For example, after a temporary inbox token is deleted, your browser can no longer read that inbox; after an alias is deleted, new messages sent to it are no longer forwarded.
Temporary inboxes are accessible during their validity period, then enter the cleanup process when they expire or you rotate them. Forwarded-message records are retained for up to 30 days by default; account identity data and active aliases are kept while you continue using the features.
Security logs are generally retained for a limited period needed to prevent abuse and investigate failures. Deletion from backups may take a reasonable amount of time, but backups do not make the data available online again.
| Data category | Primary purpose | Typical boundary |
|---|---|---|
| Temporary email and messages | Immediate receipt and reading | Cleaned up after expiration or inbox rotation |
| Forwarding delivery records | Status checks and troubleshooting | Up to 30 days |
| Login email and aliases | Identity, destination, and access management | While the account is in use or until manually deleted |
| Security and access logs | Rate limiting, auditing, and abuse prevention | A limited period as necessary |
We use access tokens, permission checks, request rate limiting, and input sanitization to reduce the risk of unauthorized access. HTML email is rendered in a restricted reading environment, and dynamic scripts and dangerous link protocols are limited.
No internet service can guarantee absolute security. Do not use temporary addresses to receive financial keys, medical records, long-term account recovery credentials, or other irreplaceable information.
Our service infrastructure and technical providers may be located outside your region, so data may be processed across borders. We use contracts, access controls, and data minimization as required by applicable law to protect this processing.
Rights and regulatory requirements vary by region. When contacting support, you may state your location so we can handle your request under the applicable requirements.
TempVeil is intended for users who understand the risks of development testing and email forwarding; it is not specifically directed at children. We do not knowingly collect data from children below the legally defined age to build profiles.
If a parent or guardian believes a child submitted personal data to the service, please contact us with enough non-sensitive information to locate the data. After verification, we will take appropriate steps to delete it.
You can delete individual temporary messages, rotate your address, delete or pause aliases, and clear local login information by signing out. Depending on your region’s laws, you may also have the right to request access, correction, deletion, restriction, or objection to certain processing.
To prevent data from being given to the wrong person, we may need to reasonably verify your identity. Making a request does not affect your right to complain to your local regulator.
We may update this notice when service features, legal requirements, or infrastructure change. We will highlight material changes on this page and update the date at the top.
The revised notice applies to processing activities carried out after it takes effect. We recommend checking this page periodically when using ongoing features such as long-term forwarding.
Send privacy, deletion, or data-processing questions to support@tempveil.com. Please include the relevant feature, address, and approximate time, but do not attach verification codes, tokens, or complete sensitive message content.
We will acknowledge requests within a reasonable period and handle them based on applicable law and technical feasibility. To protect others’ privacy, we may refuse requests that cannot be verified or are clearly abusive.