Privacy Policy
Last updated: July 25, 2026 · Template pending legal review
This is a structured template. It must be reviewed by qualified counsel before public launch.
Who we are
InboxDome ("we") operates inboxdome.com, a temporary receive-only email service. Controller identity: [to be completed].
What we collect
- Temporary email content. Messages sent to your temporary address, processed and stored only to show them to you, and deleted when the inbox expires or you delete it.
- Technical metadata. Short-lived security logs (including IP addresses, kept at most 7 days) used for rate limiting and abuse prevention.
- Content-free usage counters. Aggregate event counts (e.g. "an inbox was created"). They never include addresses, subjects, senders, codes, or message content.
What we do NOT collect for the anonymous inbox
- No account, name, or personal email is required to use the temporary inbox on the homepage.
- No advertising trackers or third-party analytics scripts.
- No permanent behavioral profiles.
If you create an account
Accounts are optional and exist only for the developer API and billing. The anonymous inbox never needs one. When you do create one, we additionally process:
- Your email address and a password hash, held by Supabase, our authentication provider. We never see or store your password itself.
- The IP address you signed up from, kept for at most 7 days and then automatically deleted, and the country it resolved to, which is retained for fraud and abuse prevention.
- Consent timestamps and versions recording which Terms and Privacy Policy you accepted, kept as evidence for as long as the account exists.
- Account and API usage counters (inboxes created, requests made), which are content-free.
Verification, password-reset and security emails are sent through Resend and Amazon SES, which receive your email address in order to deliver them. You can delete your account at any time from the account page; deletion removes the profile record and its consent evidence.
Honest limits
- Emails are not end-to-end encrypted. Like almost all email services, we technically could access content and process it to provide the service.
- Anyone who has your private inbox link can read that inbox.
- Remote images in emails are blocked by default because they can reveal that you opened a message.
Retention
See the data retention summary. Consumer inboxes expire after 24 hours by default (extendable to at most 7 days) and are then permanently deleted. API inboxes follow the same default; how far you can extend them depends on the plan. Account records live until you delete the account, except the signup IP, which is deleted after 7 days.
Legal bases (EEA/UK users)
We process inbox content to perform the service you request, and security metadata under legitimate interest in protecting the service.
Subprocessors
Cloudflare, Inc. for hosting, storage and email routing infrastructure; Supabase, Inc. for account authentication; Resend and Amazon SES for outbound transactional email. Accounts are the only reason the last two are involved. The full list with purposes and locations is on thesubprocessors page.
Your rights
You can delete any message or the entire inbox at any time. Depending on where you live you may have additional rights (access, erasure, complaint to a supervisory authority). Contact us via the contact page.
Children
The service is not directed at children under 16.
Changes
We will update this page when our practices change.