DATA LIFECYCLE / WHAT EXISTS WHEN

What happens to your data before an address disappears

“Temporary” isn’t an abstract promise. Here’s what temporary inboxes and forwarding aliases handle at each stage: creation, receipt, extension, and expiration.

Temporary credential: current browserTemporary window: 3–24 hoursForwarding archive: 30 days

Temporary inbox timeline

T+00 / Created

A random address and access credential are generated together

The address receives mail; the access credential proves that the current browser can read it. It isn’t an account password and won’t bring an expired address back. Don’t treat a browser session as cross-device sync.

T+01 / Received

Mail enters a limited lifecycle

The system processes the sender, subject, body, and delivery details so they can appear in your inbox. Temporary email is suitable for text verification codes and confirmation links—not as a file repository or channel for sensitive communication.

T+03H / Default expiration

Extend it when needed

Each extension adds 3 hours. It only moves the upcoming expiration time; it doesn’t turn the old address into a permanent one or guarantee that the sender will accept it.

T+24H / Absolute limit

Receiving stops and recovery isn’t available

Once 24 hours have passed since creation, you can’t extend the address further. There is no recovery path for the address, access, or mail, so complete verification or move your account email before then.

01 / FORWARDING PATH

A permanent alias preserves control—not a permanent archive

A forwarding alias can keep the entry point active long term, but mail in the dashboard still has a defined retention period.

01

Verify the receiving email

Enter a real receiving email address and sign in with the 6-digit verification code. This is the final delivery destination; the service you register with sees only the alias.

02

Route and filter

Incoming mail is forwarded according to the alias settings, with optional spam detection, allowlists, and blocklists. The system must briefly process message content to perform these actions.

03

Archive cleanup after 30 days

The dashboard archive is for short-term tracking and shouldn’t be relied on after 30 days. Save mail that you truly need long term in your receiving inbox.

02 / SIZE CHANGES THE PATH

The larger the attachment, the less we retain

≤ 50MB

Forwarded + archived for 30 days

The message is delivered normally to your receiving inbox, while a short-term copy remains in the dashboard to help troubleshoot delivery and spam classification.

50–100MB

Forwarded only—no archive

To limit storage pressure, large messages continue to your receiving inbox, but the dashboard keeps no searchable copy.

> 100MB

Rejected in full

Ask the sender to use a trusted file link, reduce the attachment size, or split the message into multiple sends. Email encoding may increase the final size.

TEMP

Temporary addresses aren’t file repositories

Temporary inboxes are designed for short-lived text communication. When you need attachment continuity, choose forwarding mode instead.

Practical ways to reduce exposure

  • Use a different forwarding alias for each site, so you can disable one precisely if it leaks.
  • Don’t include extra identifying information in the message body; separating addresses can’t hide the content itself.
  • On shared devices, sign out when you’re done so the local session credential isn’t left for the next user.
  • Don’t use a temporary email address for accounts you may need to recover later.
  • For suspicious emails, sign in manually through the official website instead of clicking urgent links.
03 / EXPOSURE INVENTORY

What we can see, and what we cannot

A privacy promise is only verifiable when it names specific data items — not a vague "we value your privacy".

Visible

Metadata required for routing

Recipient address, sender address, timestamps, delivery status. Without these we can't forward mail — or tell you where a message stalled when things break.

Automated

Content signals read by spam screening

The anti-spam engine scores content mechanically. No human reads it; the outcome surfaces only as one of three states — forwarded, blocked, or flagged.

Not visible

Your browsing identity

The disposable inbox requires no signup, and its access credential lives only in your browser session. We cannot map an inbox to a person.

Nonexistent

Any copy after expiry

When an inbox expires, an archive turns 30 days old, or an alias is deleted, the data is purged. There is no shadow backup — and no paid "recovery service".

04 / HONEST LIMITS

Three things we deliberately don't promise

Stating what we can't do protects you better than overclaiming.

No anonymity promise

Email isolation shrinks your address exposure; it is not legal anonymity. Your network environment, browser fingerprint, and the other site's logs are all outside our reach.

No block-evasion promise

Senders may reject temporary domains. We don't rotate domains to fight blocks — that's spam-tool behaviour, and it would poison deliverability for every legitimate user.

No permanent-storage promise

Every piece of data has an explicit expiry. Using TmpOne as a filing cabinet is misuse; forward anything important to a long-term mailbox you control.