Privacy Policy
Service-specific policy · Last updated: August 2026
1. Scope
This Privacy Policy applies only to the Temp Mail Service at tempmail.zulfanoon.com. It supplements the general Zulfanoon Privacy Policy at zulfanoon.com/privacy, which covers all other Zulfanoon sites. In the event of a conflict between this policy and the general policy with respect to the Temp Mail Service, this policy controls.
2. What We Never Collect
The Temp Mail Service was designed to not require or collect:
- Names, usernames, or display names
- Real email addresses (you don't need to register)
- Passwords — there are no accounts
- Phone numbers, billing information, or payment details
- Government-issued IDs or age verification data
- Social media profiles or third-party authentication data
- Browsing history, device fingerprints, or cross-site tracking data
If you never provide this information, we cannot collect it.
3. What We Do Store (and For How Long)
| Data | Purpose | Retention |
|---|---|---|
tempmail_mb cookie |
Binds your browser to a random mailbox so you can access it | Until mailbox expires (24h) or you clear cookies |
| Random mailbox address | Enables email delivery to your inbox | Deleted with mailbox (≤24h) |
| Received messages | Delivered to your inbox so you can read them | Deleted with mailbox (≤24h) |
| Attachment metadata (name, size, type only) | Displayed in message list; attachments are not stored | Deleted with mailbox (≤24h) |
| Rate-limit counters (per IP, in Redis) | Prevents automated abuse and spam-bombing | 1 hour rolling window, then auto-deleted |
| Consented analytics (pageviews, clicks, sessions, device info, IP → country/city) | Usage analysis; collected only after cookie consent | 24 months, then auto-purged |
| Server logs (IP, user-agent, timestamp, request path) | Security, debugging, and abuse investigation | 30 days, then rotated |
There are no backups of mailbox data. When a mailbox expires and the purge job runs, the data is permanently gone. There is no export facility because there is nothing to export.
4. How We Use Information
- Provide the service: Route email, display your inbox, enforce expiry
- Prevent abuse: Rate limiting, address-creation caps, IP blocking, fraud investigation
- Security: Log analysis for intrusion detection, DDoS mitigation, vulnerability response
- Legal compliance: Respond to valid legal process (subpoenas, court orders); report suspected illegal activity to law enforcement
- Analytics (consented only): Aggregate usage patterns to improve the service
5. Legal Basis for Processing (GDPR)
- Legitimate Interest: Rate limiting and fraud prevention (we have a legitimate interest in preventing automated abuse)
- Legal Obligation: Responding to valid legal process and reporting suspected illegal activity
- Consent: Analytics collection (only after you accept cookies)
We do not process personal data for marketing, profiling, or advertising purposes in the Temp Mail Service.
6. Third-Party Services
- Cloudflare — CDN, DDoS protection, and email routing (processes inbound email headers; sees source IP and envelope data). Cloudflare Privacy Policy.
- ip-api.com — Resolves IP addresses to approximate country/city for analytics. No data beyond the IP is shared; queries are not stored by ip-api.com. ip-api.com Legal.
7. Cookies
| Cookie | Purpose | Duration |
|---|---|---|
tempmail_mb |
Binds your browser to a mailbox (functional; required for the service to work) | Until expiry or cleared |
zv_consent |
Stores your cookie consent choice | Until cleared |
zv_id (localStorage) |
Anonymous visitor ID for analytics | Until cleared |
zv_session (sessionStorage) |
Current browsing session identifier | Tab close |
Without tempmail_mb, the service cannot function — it's how we know which inbox to show you. It contains only a random 8-character code; it contains no personal data.
8. Data Security
- HTTPS encryption for all data in transit
- Server-side script sanitization and sandboxed rendering of message HTML
- Inbound email requires a valid ingest secret (HMAC-authenticated webhook)
- IP-based rate limiting with real-IP detection (Cloudflare-Connecting-IP, not X-Forwarded-For)
- Non-root Docker containers; PostgreSQL and Redis not exposed to the public internet
- No database backups of mailbox data — deletion is absolute
9. Your Rights
Under the GDPR and CCPA, you have rights over your personal data. However, the Temp Mail Service is designed so that almost no personal data exists to exercise rights over:
- Right of Access: Your data is your random mailbox address and its messages — you already see everything in the browser. There is nothing else to request.
- Right to Erasure: Your mailbox self-destructs within 24 hours. Generating a new address deletes the previous one instantly. Clearing your cookies severs the binding between your browser and the mailbox.
- Right to Data Portability: Since data is ephemeral and not associated with an account, there is no dataset to export.
- Right to Object / Restrict Processing: You can stop using the service at any time. Rate-limit data and server logs are retained regardless, but contain no personal identifiers beyond an IP address.
For GDPR/CCPA inquiries, email [email protected]. EU residents also have the right to lodge a complaint with their local data protection authority.
10. International Transfers
The Temp Mail Service is hosted on servers in the European Union (Contabo). Inbound email transits through Cloudflare's global network. No personal data is transferred outside the EU for storage. Where third-party services may process data outside the EU (e.g., Cloudflare edge nodes), Standard Contractual Clauses (SCCs) or equivalent safeguards are in place.
11. Children's Privacy
The Temp Mail Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has used the service, contact us at [email protected] and we will investigate.
12. Changes to This Policy
We may update this policy at any time. Material changes will be announced on the Temp Mail homepage. Your continued use after changes take effect constitutes acceptance. The "Last updated" date at the top reflects the most recent revision.
13. Contact
Privacy inquiries, GDPR/CCPA rights requests, or general questions: [email protected].