Legal

Privacy Policy

Last updated: 2026-08-05 · Applies to all language versions of foxtemp.com

Key point 1 The temp inbox lives for at most 24 hours; address and mail self-destruct on expiry, and attachments are never stored.
Key point 2 The forwarding archive keeps mail for 30 days; your real email is only used as a forwarding destination and sign-in credential.
Key point 3 We never sell data, load third-party ad or tracking scripts, or build cross-site profiles.
Key point 4 You can delete mail or aliases anytime, or request account closure to erase everything with it.

1. Who we are and the scope of this policy

Foxtemp (foxtemp.com, "we," "us," "the site") provides two free services: a no-sign-up temporary email inbox, and email forwarding aliases available after signing in. Both are receive-only channels that never send mail. This policy explains what data we collect when you use those services or browse our pages, how we use it, how long we keep it, and the control you have over it. It applies to all five language versions of this site.

2. Data we collect

We follow a data-minimization principle, broken down by scenario:

  • Using the temp inbox (no sign-up required): the system-generated temporary address, a random access token, and the sender, subject, and body of mail sent to that address. Attachment content is never stored; a whole message over 100MB is rejected server-side. We don't require or collect any identity information from you.
  • Using forwarding aliases (sign-in required): your real email address (sign-in credential and forwarding destination), the alias list you create and its forward counts, mail sent to an alias (including status: forwarded/blocked/failed/pending) plus attachments for messages up to 50MB total, and your two-factor-authentication status and secret (if enabled).
  • Server logs: to keep the service available and investigate abuse, our servers briefly record access IP, timestamp, and request path in a rolling log that isn't cross-referenced against message content.
  • What we never collect: name, phone number, ID documents, payment information (there are no paid features on this site), or passwords (sign-in uses a one-time code, so no password ever exists).

3. How we use data

The data above is used only for the following purposes, and nothing else:

  • Display and delivery: showing temp-inbox mail to whoever holds the access token; forwarding alias mail to your real inbox.
  • Spam filtering: screening mail sent to aliases, with the block result and reason fully visible to you and correctable with one click.
  • Sign-in and security: sending sign-in codes, verifying two-factor codes, and maintaining sessions for up to 7 days.
  • Abuse prevention: rate-limiting high-frequency or malicious traffic based on technical logs.

We do not read your mail for advertising purposes, do not sell or rent any data, and do not use your data to train any model.

4. Retention and automatic deletion

All content data carries a fixed deletion point enforced automatically server-side:

  • Temp inbox and its mail: valid for 3 hours by default and refillable, capped at a 24-hour total lifetime from creation; destroyed automatically on expiry (or when you switch to a new address), and cannot be recovered.
  • Temp inbox attachments: zero retention — discarded on arrival, never written to storage.
  • Forwarded-mail archive: kept 30 days, deleted automatically on expiry; you can manually delete a single message or clear everything, and manual deletion takes effect immediately.
  • Archived attachments (total ≤50MB): kept and deleted together with their message; messages of 50–100MB are forwarded only, with no attachment kept in the archive.
  • Account data (real email, aliases, 2FA settings): retained for the life of the account and deleted together once you request closure.

5. Cookies and local storage

This site does not use third-party cookies. We store a small amount of functional data in your browser's local storage: the temp inbox's access token (so a refresh can restore the inbox), a sign-in session token (valid 7 days), and your language preference. This data lives in your own browser, and clearing browser data removes it; once cleared, a temp-inbox credential without a saved link cannot be recovered.

6. Analytics

To understand traffic and feature usage, this site uses self-hosted analytics stored on our own servers, never shared with any third party and never used for cross-site tracking or advertising. Analytics is limited to page views and anonymized action events, and never includes message content.

7. Data sharing and disclosure

We never sell, rent, or trade any of your data. Disclosure only happens in these limited situations:

  • To carry out the forwarding feature itself — delivering mail sent to an alias to the real inbox you designated (this is your direct instruction when you use the feature);
  • In response to a lawful, legally binding request from a competent authority; at that point we can only provide data that is still within its retention window and hasn't already been auto-deleted;
  • To infrastructure hosting providers necessary to run the service (they provide only storage and networking, with no access to business data).

8. Security measures

  • HTTPS enforced site-wide for encrypted transport;
  • Temp inboxes are isolated by a random access token — no token, no access to the inbox;
  • Sign-in uses one-time codes (60-second resend cooldown, rate-limited), so there's no password to be breached; TOTP two-factor authentication is supported;
  • Message bodies render in an isolated sandbox, so embedded scripts never execute on our pages;
  • No third-party script loads on any page, removing supply-chain script risk at the source.

No internet service can promise absolute security. We recommend not using a disposable inbox for banking, payment, or other sensitive mail, and enabling two-factor authentication on your real email.

9. Your rights and controls

  • Deletion: delete temp-inbox mail anytime (switching addresses destroys the whole inbox), archived mail (individually or all at once), or any alias;
  • Account closure: email support@foxtemp.com to request account closure, and we'll delete your real email, all aliases, and any remaining archive;
  • Inquiry: you can ask us what data we currently hold on you — given the short retention windows, the answer is usually simple;
  • Correction: a message wrongly flagged as spam can be reinstated with one click on its detail view, with no need to contact us.

10. Minors

This service is aimed at general internet users and is not directed at children under 14; we do not knowingly collect personal information from them. If you are a guardian and believe a child has provided us personal information, please contact us so we can delete it.

11. Changes to this policy

We update this policy as features change and revise the "last updated" date at the top of the page; material changes to data use or retention periods will be prominently flagged on the site. Continuing to use this site after an update means you accept the revised policy.

12. Contact us

For any question about this policy or your data, email support@foxtemp.com — we typically reply within one business day.

Prefer the engineer's-eye version? Privacy by Design lays this same policy out as a visual timeline.