Temporary addresses
You can create one without an account. The address and token let you view the inbox during its active period.
Privacy Policy · Effective September 1, 2026
This policy explains how Forwardtmp handles information when you use temporary inboxes and long-term forwarding. We collect only what is needed to provide the service and never sell personal data.
You can create one without an account. The address and token let you view the inbox during its active period.
They are cleared when the mailbox expires, no later than 24 hours after creation.
After signing in, you can review delivery activity from the past 30 days; records are then deleted automatically.
You can change a temporary address, delete a forwarding identity, sign out of your session, or contact us.
This policy applies to the browser-based disposable email service, address-forwarding dashboard, and related support services provided at forwardtmp.com. It does not govern how third-party websites use a temporary address or alias you provide to them.
If you leave this site through a link, read the destination website’s own privacy notice. We do not describe the activities of external websites as Forwardtmp processing.
When you create a temporary mailbox, the system generates a random address, access token, and expiration time so your browser can retrieve new mail sent to that address. You do not need to provide your name, password, or real email address.
Messages may contain a sender, subject, plain-text or HTML content, and attachments. We process this information only to display and download it. Do not use a temporary mailbox for highly sensitive information or anything you must retain long term.
When you use the forwarding dashboard, you submit a real destination email address, and a one-time verification code confirms that you control it. We retain the destination, aliases you create, their active or paused status, creation time, and forwarding count to provide ongoing delivery.
If you enable authenticator protection, we store the encrypted configuration needed for verification—not other accounts in your authenticator app. Actions to recover or delete an alias are recorded in the necessary security logs.
Forwarded messages are processed to identify the sender, subject, body, attachments, and delivery status, then sent to your verified destination address. Failed or spam-classified messages retain their status so you can investigate and retry them in the dashboard.
We do not read message content to build advertising profiles. Automated security checks, format conversion, and abuse detection may analyze necessary technical characteristics.
To keep the service secure, we may record request times, truncated or hashed network identifiers, browser type, API results, and error details. Logs help us enforce rate limits, troubleshoot failures, prevent automated abuse, and investigate security incidents.
These records are not used for cross-site advertising tracking. Our deployment layer may aggregate non-identifying traffic statistics to understand capacity and page reliability.
Temporary email tokens, expiration times, and forwarding session tokens may be stored in your browser’s local storage so you can continue using the service after refreshing the page. Your login email and resend cooldown may be stored in session storage.
Clearing your browser’s site data removes these local states but does not prematurely delete valid records still within their server-side retention period. Advertising cookies are not required to use the core features of this site.
| Data category | Typical retention | Purpose and limits |
|---|---|---|
| Temporary addresses and emails | 3 hours by default, up to 24 hours | Provide short-term online mail receipt; deleted after expiration |
| Forwarding delivery records | Up to 30 days | Check status, view message content, and retry delivery |
| Aliases and destinations | While in use | Continue forwarding; forwarding stops when the identity is deleted |
| Security logs | Limited period required by risk level | Prevent abuse and investigate failures and security incidents |
| Support correspondence | As long as needed to resolve the request | Respond, document the matter, and avoid duplicate handling |
We process the data needed to provide mailbox and forwarding features at your request. We also process limited logs based on our legitimate interest in securing the service, preventing fraud, and improving reliability. We comply with legal obligations when required.
If processing requires your consent, we will give you a choice before collecting the data. Refusing non-essential processing will not prevent you from using core features that do not require it.
We may use infrastructure, email delivery, security, and error-monitoring providers. They may process only the data necessary for this site under contract. We do not sell or rent mailbox content or destination addresses to data brokers.
We may disclose information when required by a valid legal request, needed to protect users or service security, or as part of a business reorganization. We assess the scope of each request and limit disclosure as much as possible.
Network and email delivery may pass through infrastructure in different regions, so data may be processed outside your location. We require service providers to use appropriate contractual safeguards, security measures, and access restrictions.
Internet transmission can never be guaranteed completely secure, but we reduce risk through encryption in transit, access controls, and limited retention. You should also avoid sending irreplaceable secrets through a temporary mailbox.
You can change an address in the tool area or wait for a temporary mailbox to expire. In the dashboard, you can pause, resume, or delete each forwarding identity, and you can sign out of your current browser session. Because temporary mailboxes are not tied to an identity, we may be unable to determine who owned an expired address.
Where permitted by applicable law, you may request access to, correction or deletion of, restriction of, or objection to processing of data associated with an identifiable account. To avoid disclosing data to the wrong person, we will first verify the requester’s relationship to the destination email address.
This site is not designed for children below the applicable local age of digital consent, and we do not knowingly collect children’s account information. If we discover misuse, we will take steps to remove the data and restrict access.
We will update the date and provide notice in an appropriate location when this policy changes materially. For privacy requests, email support@forwardtmp.com. Please do not include verification codes, passwords, or unnecessary message content in your email.