When an inbox expires, its address and messages enter an automatic cleanup process.
Privacy Policy · Updated September 10, 2026
Data stays only long enough to deliver your mail,
not to turn short-term tasks into permanent records
This policy explains what data MsgTemp processes when providing temporary email, long-term forwarding, and support services, why we process it, how long we retain it, and what choices you have.
Logged-in users can review delivery status and email content for a limited period.
Email verification codes confirm control of the address, with an authenticator code available as an optional extra.
We do not build advertising profiles or sell email content or receiving addresses.
1. Scope and data controller
This policy applies to temporary inboxes, passwordless accounts, public forwarding addresses, delivery records, and support channels on msgtemp.com. If you visit a third-party website or follow an external link in an email, that third party’s own privacy rules apply independently.
MsgTemp is the data controller for this service. If you use the service on behalf of an organization, make sure you are authorized to submit receiving addresses and handle the related communications.
2. Temporary inbox data
When you create a temporary inbox, the system generates an address, access token, creation time, and expiration time. When email arrives, we process the sender, subject, body, attachment details, and receipt time so the message can be displayed in your current browser.
Temporary inboxes do not require your name, password, or account details. The access token is stored in your browser, and anyone who obtains it may be able to read the inbox during its validity period. Do not share the address management page.
3. Passwordless accounts and authenticators
When you use long-term forwarding, we process the receiving email address you provide, verification status, session issuance time, and alias quota. Verification codes confirm control of the email address and are not used for marketing subscriptions.
When you enable an authenticator, the system generates a setup key and verifies time-based codes. Store the key securely yourself; we will never ask you to send a code or complete key through support email.
4. Why we process this data
Our primary purposes are to create addresses, receive and display email, forward messages, carry out pausing or deletion requests, and maintain session security. We also use limited technical logs to investigate abuse, delivery failures, and service availability issues.
Unless required by law or initiated by you in a support request, we do not use email content for advertising, user profiling, or machine-learning training unrelated to receiving mail.
5. Technical logs and security signals
Servers may record request times, network addresses, browser type, API results, and error details. These logs help enforce rate limits, prevent automated abuse, troubleshoot errors, and protect service quality for other users.
Security logs are managed separately from email content, with access restricted on a need-to-know basis. We delete or de-identify logs when they are no longer needed for troubleshooting or our security responsibilities.
6. Retention periods at a glance
| Data category | Typical period | What happens afterward |
|---|---|---|
| Temporary addresses and email | 3 hours by default; may be extended manually | Deleted after expiration or when you change the address |
| Long-term forwarding delivery records | Past 30 days | Deleted on a rolling basis; not a permanent mailbox |
| Login sessions | Usually 7 days or until you log out | Token expires; can be cleared from the device immediately |
| Support correspondence | As long as needed to resolve the issue | Deleted when continued retention is no longer necessary |
Specific periods may be temporarily extended for security investigations, backup rotation, or legal obligations. Expired data in backups is not restored as an active inbox and is removed as backups cycle out.
7. Cookies and browser storage
The service uses local browser storage to save temporary inbox tokens, passwordless login sessions, and necessary interface state. This lets you continue your current task after refreshing the page and is not used for cross-site advertising tracking.
You can clear site data in your browser settings, but doing so will remove access to inboxes that have not yet expired and sign you out of the long-term forwarding dashboard.
8. Service providers and international processing
We may use hosting, database, email delivery, and security monitoring providers to operate the service, sharing only the data needed for the relevant task. Providers must apply confidentiality and security measures under contract and may not use the data for their own advertising.
Internet infrastructure may result in data being processed outside your region. We select safeguards based on applicable law and seek to minimize the amount of data transferred and the time it is retained.
9. Disclosures and legal requirements
We do not sell or rent personal data. We disclose limited information only to necessary recipients when providing the service, investigating clear abuse, protecting user safety, or responding to a valid legal request.
Where legally permitted, we assess the scope of requests and challenge those that are clearly overbroad. During an emergency security incident, we may impose temporary restrictions or preservation measures to prevent further harm.
10. Security measures and unavoidable risks
We use measures such as encryption in transit, access controls, short-lived tokens, rate limiting, and layered permissions to reduce risk. Long-term accounts can also enable an authenticator to add a second confirmation step to passwordless login.
No internet service can promise absolute security. A temporary email address is not an end-to-end encrypted vault; do not use it for highly sensitive information such as banking, government, medical, or account-recovery messages.
11. Your choices to access, delete, or object
You can stop using a temporary inbox immediately by destroying it or changing its address; individual messages can also be deleted from the reading view. Logged-in users can pause or delete public addresses, remove delivery records, and end the current session.
If you need to access, correct, or delete other information associated with a receiving address, contact support and complete any necessary identity verification. We will respond within a reasonable period as required by applicable law.
12. Children, changes, and effective date
This service is not intended for children below the local digital-services age of consent. If a parent or guardian believes a child has submitted personal information, contact us so we can help verify and delete it.
When this policy changes materially, we will update the date at the top of the page and, where appropriate, provide prominent notice. Continuing to use the service after changes means you have read the policy in effect at that time.
13. Contact us
For questions about privacy, retention periods, or your data choices, email support@msgtemp.com and describe the feature involved, the relevant time, and the receiving address that can be used for verification. Do not send verification codes, authenticator keys, or unnecessary email content in support messages.
For rules about service boundaries and prohibited conduct, please also read theTerms of Service.