TempFwd Privacy Notice
Effective 30 July 2026 · version 1.0
At a glance
1. What this notice covers
This notice explains what data TempFwd (tempfwd.com, "the site") collects when you use the disposable email and alias-forwarding services, how long it is kept, what it is used for, when it is deleted, and which rights you can exercise. By accessing or using the site you accept this notice; if you do not, please stop using it.
Mail you receive through the site is written and sent by third parties; its content and their sending practices are outside this notice, which governs only the site's own handling of data.
2. What we collect
2.1 When using a disposable inbox (no account)
- Inbox contents: the messages sent to your temporary address — sender, subject, body and time of arrival; attachments are not stored. This is the bare minimum needed to show you your mail.
- Access token: a random key the system issues for the inbox, stored in your browser's local storage and in the page URL, used to restore the same inbox after a reload or on another device. It contains no identity information.
2.2 When using alias forwarding (signed in)
- Sign-in email: your real address, needed to deliver verification codes and forwarded mail — the one piece the forwarding service cannot work without.
- Aliases and forwarding records: the alias addresses you create, per-alias forward/block counters, and the mail sent to aliases (archived 30 days) with each message's forwarding status.
- Security settings: if you enable two-factor authentication, we store the authenticator secret in encrypted form.
2.3 What we don't collect
No name, no phone number, no identity documents. No third-party analytics or advertising scripts run here, no cross-site tracking happens, and no user profiles are built. Routine server access logs (IP, time, request path) exist for security and troubleshooting, rotate away automatically after a short period, and are never used for marketing.
3. How long data is kept
Every period below is enforced automatically — deletion happens on schedule without you asking:
| Data type | Retention | At expiry |
|---|---|---|
| Temporary address and its mail | 3 hours by default, extendable, 24 hours max from creation | Address and mail destroyed together, unrecoverable |
| Messages in the forwarding archive | 30 days from receipt, per message | Deleted automatically; you can also delete singly or clear all |
| Sign-in codes | 10 minutes | Invalidated |
| Sign-in session (JWT) | 7 days | Lapses automatically; fresh sign-in required |
| Account data (sign-in email, aliases, 2FA settings) | Life of the account | Deleted when you request account closure by email |
| Server access logs | Short-term (security only) | Rotated and overwritten |
4. What the data is used for
- Delivering and displaying mail sent to your temporary address;
- Forwarding mail sent to your aliases into your sign-in inbox, and keeping the 30-day online archive;
- Sending sign-in codes and verifying two-factor codes;
- Scoring incoming mail for spam, blocking what fails, and honouring your "Not spam" appeals;
- Abuse throttling (such as code-request rate limits) and fault diagnosis.
Beyond these purposes we do not read, analyse or exploit the content of your mail.
5. What we commit never to do
- Never sell, rent or trade your data to anyone;
- Never target ads or recommendations based on mail content;
- Never embed third-party trackers, ad SDKs or social plugins — every static asset on this site is served from our own domain;
- Never read your message bodies proactively; human access happens only when you request support and explicitly authorise it.
6. Cookies and browser storage
The site sets no third-party cookies. Browser local storage holds exactly three things: your language preference, the temporary inbox access token, and the sign-in session token. All of them live on your own device and can be wiped anytime via your browser's "clear site data" — note that wiping the inbox token is irreversible, and an unexpired temporary inbox becomes unreachable without it.
7. Security
- HTTPS is enforced site-wide; mail travels encrypted between you and the server;
- Inbox tokens are high-entropy random values that cannot be guessed or enumerated;
- Accounts have no password, so there is no password to breach; two-factor secrets are stored encrypted;
- Message bodies render inside an isolated sandbox — scripts inside an email never execute on the site's pages.
No internet service can promise absolute security. Don't route mail that carries serious stakes (banking, government notices) through a temporary inbox — use your regular mailbox for those.
8. Sharing and disclosure
Your data leaves the site in exactly two situations. First, forwarding itself: mail addressed to your aliases is delivered to your sign-in inbox across the normal mail network, as configured by you. Second, legal compulsion: when courts or regulators demand data through valid legal process, we provide the minimum the law requires. No other sharing arrangements exist.
9. Your rights
- Access: everything in the temporary inbox and the forwarding archive is shown to you directly on the page — there is no hidden data;
- Deletion: delete single messages, clear the archive, remove aliases, or swap the temporary address (the old inbox is destroyed instantly) at any time;
- Closure: email support@tempfwd.com from your sign-in address to close your account — we delete your sign-in email, all aliases and the archive after verification;
- Withdrawal: stop using the site and no new data is created; existing data zeroes out on the schedules in section 3.
10. Children
The site serves a general audience and is not directed at children under 14 (or the equivalent age where you live), nor do we knowingly collect their personal information. If you believe a child has provided us data, write in and we will delete it promptly.
11. Changes to this notice
When the service changes, this notice is revised with it, and the effective date and version number at the top are updated. Material changes — to data uses or retention periods — are flagged prominently on the site. Continued use after a revision means you accept it.
12. Contact
Questions about this notice or your data go to support@tempfwd.com. For anything touching account data, write from your sign-in address so we can verify it's you.