What this site stores, and what it does not
What is stored when I use an address here?
The address itself, and the mail sent to it — sender, subject, body, attachments and the time it arrived. That is what makes an inbox you can reopen. There is no account, so there is no name, no password and no phone number to store, and you are never asked for any.
What is never collected
- No name, password or phone number — there is no sign-up.
- No payment details; nothing here is paid for.
- No mail you send, because you cannot send from these addresses.
- No selling of data, and no third-party advertising scripts on the pages.
What is kept about the visit itself
Ordinary web-server records, and a keyed fingerprint of the network address rather than the address itself, used to stop one machine flooding the service with thousands of new addresses. Analytics are aggregate — how many people visited a page and roughly where they came from — and never include an email address, a subject line or any message content.
Who can read the mail
Two answers, both honest:
- Anyone who has the address. That is the trade-off for a service with no password. Treat the address like a key.
- The people who run this site, when they have to. Support staff can open an inbox to help with a problem, and every one of those opens is logged with who did it and when. That log is reviewed; it is not decoration.
What that means for you
Use these addresses for sign-ups, codes, downloads and newsletters. Do not use them for banking, medical, legal or work mail. Not because we intend to read it — because an address anyone can open is the wrong container for anything you would mind another person seeing.
Keeping images from telling senders you read their mail
Remote images in a message are not loaded on the public site by default. That is deliberate: a single invisible image is how a sender learns the exact moment their mail was opened.
How long is it all kept?
Indefinitely. Addresses and messages are not deleted on a schedule — that permanence is the point of the site, and it is why the inbox still opens a year later. Nothing is removed except by an administrator acting deliberately, and even then it is archived rather than destroyed, so a mistake can be undone.
Backups
Mail is backed up, encrypted, to storage outside this server, and the restore is tested automatically every week. Backups exist so a disk failure cannot take your inbox with it. They are not a second copy that anyone browses.
What happens if someone asks for your mail
There is no account and no identity attached to an address, so there is nothing to hand over that identifies a person. What exists is the mail itself and the address it was sent to. A lawful, specific request about a named address could be answered; a fishing request for "everything" could not, because the data is not organised around people at all.
The full legal detail lives in the privacy policy. This page is the plain-language version, and where the two differ, the policy is the one that counts.