Legal

TempFwd Privacy Notice

Effective 30 July 2026 · version 1.0

At a glance

Minimum collection: only what's needed to get mail to you — no profiling, no ads, no selling data.
Temporary inboxes burn after reading: at expiry (24 hours max) every message is destroyed for good; attachments are never stored in the first place.
Forwarding archives cap at 30 days: each message counts down on its own, then deletes itself — or clear everything manually anytime.
Passwordless by design: accounts have no password to leak — one-time codes sign you in, optional two-factor hardens it.

1. What this notice covers

This notice explains what data TempFwd (tempfwd.com, "the site") collects when you use the disposable email and alias-forwarding services, how long it is kept, what it is used for, when it is deleted, and which rights you can exercise. By accessing or using the site you accept this notice; if you do not, please stop using it.

Mail you receive through the site is written and sent by third parties; its content and their sending practices are outside this notice, which governs only the site's own handling of data.

2. What we collect

2.1 When using a disposable inbox (no account)

  • Inbox contents: the messages sent to your temporary address — sender, subject, body and time of arrival; attachments are not stored. This is the bare minimum needed to show you your mail.
  • Access token: a random key the system issues for the inbox, stored in your browser's local storage and in the page URL, used to restore the same inbox after a reload or on another device. It contains no identity information.

2.2 When using alias forwarding (signed in)

  • Sign-in email: your real address, needed to deliver verification codes and forwarded mail — the one piece the forwarding service cannot work without.
  • Aliases and forwarding records: the alias addresses you create, per-alias forward/block counters, and the mail sent to aliases (archived 30 days) with each message's forwarding status.
  • Security settings: if you enable two-factor authentication, we store the authenticator secret in encrypted form.

2.3 What we don't collect

No name, no phone number, no identity documents. No third-party analytics or advertising scripts run here, no cross-site tracking happens, and no user profiles are built. Routine server access logs (IP, time, request path) exist for security and troubleshooting, rotate away automatically after a short period, and are never used for marketing.

3. How long data is kept

Every period below is enforced automatically — deletion happens on schedule without you asking:

Data typeRetentionAt expiry
Temporary address and its mail3 hours by default, extendable, 24 hours max from creationAddress and mail destroyed together, unrecoverable
Messages in the forwarding archive30 days from receipt, per messageDeleted automatically; you can also delete singly or clear all
Sign-in codes10 minutesInvalidated
Sign-in session (JWT)7 daysLapses automatically; fresh sign-in required
Account data (sign-in email, aliases, 2FA settings)Life of the accountDeleted when you request account closure by email
Server access logsShort-term (security only)Rotated and overwritten

4. What the data is used for

  • Delivering and displaying mail sent to your temporary address;
  • Forwarding mail sent to your aliases into your sign-in inbox, and keeping the 30-day online archive;
  • Sending sign-in codes and verifying two-factor codes;
  • Scoring incoming mail for spam, blocking what fails, and honouring your "Not spam" appeals;
  • Abuse throttling (such as code-request rate limits) and fault diagnosis.

Beyond these purposes we do not read, analyse or exploit the content of your mail.

5. What we commit never to do

  • Never sell, rent or trade your data to anyone;
  • Never target ads or recommendations based on mail content;
  • Never embed third-party trackers, ad SDKs or social plugins — every static asset on this site is served from our own domain;
  • Never read your message bodies proactively; human access happens only when you request support and explicitly authorise it.

6. Cookies and browser storage

The site sets no third-party cookies. Browser local storage holds exactly three things: your language preference, the temporary inbox access token, and the sign-in session token. All of them live on your own device and can be wiped anytime via your browser's "clear site data" — note that wiping the inbox token is irreversible, and an unexpired temporary inbox becomes unreachable without it.

7. Security

  • HTTPS is enforced site-wide; mail travels encrypted between you and the server;
  • Inbox tokens are high-entropy random values that cannot be guessed or enumerated;
  • Accounts have no password, so there is no password to breach; two-factor secrets are stored encrypted;
  • Message bodies render inside an isolated sandbox — scripts inside an email never execute on the site's pages.

No internet service can promise absolute security. Don't route mail that carries serious stakes (banking, government notices) through a temporary inbox — use your regular mailbox for those.

8. Sharing and disclosure

Your data leaves the site in exactly two situations. First, forwarding itself: mail addressed to your aliases is delivered to your sign-in inbox across the normal mail network, as configured by you. Second, legal compulsion: when courts or regulators demand data through valid legal process, we provide the minimum the law requires. No other sharing arrangements exist.

9. Your rights

  • Access: everything in the temporary inbox and the forwarding archive is shown to you directly on the page — there is no hidden data;
  • Deletion: delete single messages, clear the archive, remove aliases, or swap the temporary address (the old inbox is destroyed instantly) at any time;
  • Closure: email support@tempfwd.com from your sign-in address to close your account — we delete your sign-in email, all aliases and the archive after verification;
  • Withdrawal: stop using the site and no new data is created; existing data zeroes out on the schedules in section 3.

10. Children

The site serves a general audience and is not directed at children under 14 (or the equivalent age where you live), nor do we knowingly collect their personal information. If you believe a child has provided us data, write in and we will delete it promptly.

11. Changes to this notice

When the service changes, this notice is revised with it, and the effective date and version number at the top are updated. Material changes — to data uses or retention periods — are flagged prominently on the site. Continued use after a revision means you accept it.

12. Contact

Questions about this notice or your data go to support@tempfwd.com. For anything touching account data, write from your sign-in address so we can verify it's you.