What this policy covers
It covers the MailOnce website and temporary-email product, including browser sessions, temporary addresses, inbound messages, OTP extraction, device linking and the limited browser preferences needed to keep the interface usable. Separate third-party sites reached through links have their own privacy practices.
Data the service processes
Browser session
A public session identifier, a hashed ownership verifier, status and lifecycle timestamps. The raw server-side verifier is not stored as the database proof.
Temporary address
The generated address, its domain, status, creation/expiry information, extension state and the session that owns it.
Inbound message
Sender information, subject, bounded text, sanitized HTML when available, message size, read state, timestamps and a detected top verification code when one is found.
Attachments
Attachment metadata such as a safe display name, media type, size, checksum or scan state may be processed when an incoming message contains attachments.
Device linking
Pairing state, hashed pairing/continuation proofs, linked-device credential state and the target inbox needed to authorize the linked read session.
What stays in your browser
The active MailOnce browser session is stored in sessionStorage under the current web implementation. It contains the browser-session credentials, inbox credentials, temporary address and expiry information needed to reconnect the interface during that browser-tab session. Expired or invalid stored state is removed when read.
MailOnce also uses a first-party language preference cookie named mailonce.locale. It stores only the selected supported locale, uses SameSite=Lax, is marked Secure on normal HTTPS deployments, and has a one-year maximum age.
Expiry and deletion are not the same event
MailOnce deliberately treats product availability and backend cleanup as separate stages so the policy does not promise instant deletion when the inbox timer reaches zero.
1. Active
The address can receive mail while its lifecycle and product limits permit it. Messages carry their own expiry timestamps.
2. Expired or closed
The inbox is no longer treated as an active address. In the current Free cleanup policy, a closed inbox becomes purge-eligible after a 24-hour retention interval.
3. Cleanup
General message and session cleanup uses configured retention and grace periods plus bounded cleanup jobs. Deployment safety checks can block destructive cleanup until mail-system retry assumptions are verified.
Network and abuse-prevention data
A client IP address can be normalized and processed as a source key for rate limiting and abuse controls. MailOnce uses this operational signal to protect shared capacity; it is not presented as a public profile or inbox identity.
Third parties and message senders
MailOnce receives email content from external senders and may direct users to external websites through links contained in messages. Those senders and websites are independent of MailOnce. Infrastructure providers used to host or deliver the service may process the minimum data required to operate that infrastructure; the production provider list must stay aligned with the deployed system.
Analytics, advertising and future integrations
This policy does not silently grant permission for future tracking. If MailOnce introduces advertising, non-essential analytics or another third-party integration that changes data collection, the relevant disclosure and consent behavior will be updated before that processing is enabled where required.
Your choices and privacy rights
Privacy rights depend on where you live and the legal basis that applies to the processing. Privacy questions and requests about access, deletion, correction, restriction or other applicable rights can be sent through the official MailOnce Support channel at support@mailonce.org. Some temporary data may already be expired or deleted before a request can be matched to it.
Privacy contact
The official MailOnce Support mailbox at support@mailonce.org is the current contact for privacy questions and requests. Do not send passwords, session tokens, inbox tokens or unnecessary private message content.
Changes to this policy
The policy will be revised when the product’s data flows, providers, retention rules, analytics/advertising integrations or legal requirements materially change. The published version should describe the deployed service, not an older architecture plan.
Understand the lifecycle behind the policy
The Privacy & Data Lifecycle knowledge page explains the product behavior around inbox privacy, expiry and cleanup in a more practical, non-legal format.
Read Privacy & Data Lifecycle