Legal

Privacy Policy

EmailFW is built around privacy. This policy explains—in plain language—what we collect, why, how long we keep it, and how you stay in control.

Last updated: August 3, 2026 Applies to all pages and features on emailfw.com
  • Gone when expiredTemp mail addresses and their messages are destroyed together—no copies kept
  • 30 days maxForwarding archive for alias mail is kept up to 30 days, then purged automatically
  • Never soldWe do not sell or rent user data; no ad or analytics trackers on site pages

1. Scope

This policy covers everything you use on emailfw.com: the no-signup temp mail inbox and the permanent forwarding service (alias management, mail archive, two-factor authentication). By using the service you acknowledge this policy.

2. Data we collect

We follow data minimization—only what is required to run the feature you are using:

  • Temp mail:A disposable address generated for you, mail sent to it (sender, subject, body), and an access token so you can reopen the same inbox. No personal profile is required.
  • Permanent forwarding:Your real email used to sign in, the aliases you create, mail received on those aliases, and forwarding status. Your real address is used only for login codes and delivering forwarded mail.
  • Security settings:If you enable two-factor authentication, we store the secret used to verify TOTP codes; it is removed when you turn 2FA off.
  • Basic operational logs:Minimal access records (such as request time and rate) to prevent abuse and support troubleshooting—for example, login code rate limits.

3. Data we do not collect

  • We do not ask for your name, phone number, postal address, or government ID;
  • We do not load third-party ads, analytics, or behavioral tracking; all page assets are self-hosted;
  • There is no paid tier, so we never collect payment information;
  • We do not read or profile your mail content for recommendations or advertising.

4. Retention periods

Every data type has a fixed lifetime and is removed automatically—no manual cleanup needed on your side:

Data typeRetentionNotes
Temp mail & its messages3 hours defaultExtendable; max 24 hours total per address, then fully destroyed
Temp mail attachmentsNot storedAttachment bytes are discarded on delivery; list may show an attachment flag only
Forwarding archive30 daysIncludes blocked spam; attachments kept when entire message ≤50MB
Login verification codesMinutesInvalid after successful login or timeout
Login session (JWT)7 daysExpires automatically; you can sign out anytime
Account & alias settingsUntil deletedRemoved when you delete aliases or request account deletion

5. Cookies & local storage

We do not use third-party cookies. A small amount of functional data is stored in your browser’s localStorage:

  • Language preference (so the next visit opens the right locale);
  • Temp mail access token (to restore your inbox after refresh);
  • Login token (to keep the forwarding console signed in for up to 7 days).

Clearing browser data removes these entries. Server-side data still expires on the schedule in section 4.

6. How we use data

We process data solely to provide the feature you requested: receive and display mail, forward alias mail to your real inbox, filter spam, and deliver login codes. We do not use it for ads, profiling, or sale to third parties.

7. Sharing & disclosure

We do not share your data with third parties except where required by applicable law or a valid legal order—in which case we disclose only what the law compels and only to the extent permitted.

8. Security measures

  • HTTPS enforced across the site;
  • Passwordless login via one-time email codes—nothing to brute-force in a password database;
  • Optional TOTP two-factor authentication for forwarding accounts;
  • Rate limits on verification code requests to block abuse.

9. Your rights & controls

Most controls are available directly in the UI:

  • Temp mail: delete individual messages or click “New address” to discard the current inbox instantly;
  • Forwarding archive: delete one message or clear all records from the last 30 days;
  • Aliases: pause, resume, or delete any alias at any time;
  • Account: to delete your entire account and associated data, email support@emailfw.com from your login address and we will verify and process the request.

10. Minors

The service is intended for users who can enter a binding agreement under their local law. Where minors are restricted from online services, use only with guardian consent where required.

11. Policy updates

We may update this policy when features or regulations change. The “Last updated” date at the top will change; material updates will be highlighted on the site. Continued use after an update means you accept the revised policy.

12. Contact us

Questions about this policy or your data? Email support@emailfw.com and we will respond as soon as we can.