Privacy policy
Last updated 20 September 2026
Inboxspam exists so you don’t have to hand your real address to a site you don’t trust. A policy for a service like that ought to be short and specific, so this one is.
The short version
- No account, no password, no name. You never tell us who you are.
- A free inbox and every message in it is deleted an hour after it’s created. That’s the product, not a setting.
- No analytics, no advertising, no tracking. One cookie, doing one job.
- Your IP address is used as a counter to stop one person making thousands of inboxes, and for nothing else. It is never stored next to your inbox or your mail.
- We don’t sell data to anybody. There’s nothing here worth selling.
1. What this covers
This policy covers the website at inboxspam.com, the disposable addresses we hand out on inboxspam.net, inboxspam.org and junkmaildrop.org, and the mail sent to them.
Inboxspam is run by one person in the United States, not by a company. “We” throughout this policy means that person. The quickest way to get in touch is the contact form, which reaches them directly.
2. What we hold, and for how long
Everything the service stores is in this table. There is no other collection happening behind it.
| What | Why | How long |
|---|---|---|
| Your inbox address, and the times it was created and expires | To accept mail for you and show it to you | Deleted when the inbox expires — an hour after it’s created, on the free plan |
| A random token, kept in your browser as a cookie | So that your browser, and only your browser, can open the inbox it made | Until the inbox expires. We store only a SHA-256 hash of it, never the token itself |
| Mail sent to your address: sender, subject, headers, body and attachments | Because showing it to you is the service | Deleted with the inbox. A storage rule clears anything a failure leaves behind within 24 hours |
| The address on its own, held back after the inbox is gone | So that nobody who claims it later can receive the previous owner’s mail — a password reset arriving late, say | 30 days, as an address and nothing else. The messages were deleted at expiry |
| Your IP address, as part of a counter | To stop one person creating thousands of inboxes or flooding the contact form | An hour at most, and two minutes for name-availability checks. Removed automatically |
| Whatever you type into the contact form | To answer you | Kept in the mailbox we reply from, for as long as the conversation is live |
| Operational logs | To notice when something has broken | 3 days. They record internal inbox identifiers — never email addresses, message contents or IP addresses |
About that counter
It’s worth being exact, because it’s the only place your IP address goes. It is stored as a number against a key built from your address and the current hour, with nothing else alongside it. It isn’t written to a log, isn’t attached to your inbox, and doesn’t outlive the hour. It can’t be used to work out which inbox was yours or what arrived in it.
3. What we don’t do
- No analytics and no advertising. No measurement scripts, no fingerprinting, no tracking pixels, no third-party cookies.
- No mailing list. Giving us an address on the contact form subscribes you to nothing.
- No selling, renting or sharing of personal data, in any form, to anyone.
- Nobody reads your mail. It’s parsed automatically so it can be shown to you, and then deleted on schedule. The one exception is a message reported to us for abuse, which we may look at if it still exists.
- Nothing is ever sent from your address. Inboxspam only receives; there is no reply, forward or send, and no way to add one.
4. Cookies and browser storage
There is one cookie, named __Host-sid. It holds the random token that proves your browser is the one that made the inbox. It’s marked HttpOnly, so scripts on the page can’t read it, and Secure, so it only travels over HTTPS. It expires with the inbox. Without it you can’t open your inbox — and neither can anyone else.
Your browser also keeps a short note of which messages you’ve opened, so the “New” tags survive a reload. That note stays on your device; it is never sent to us and we can’t see it. Clearing site data removes it, along with the cookie and therefore the inbox.
There’s no cookie banner because there’s nothing to consent to: the only cookie we set is the one needed to give you the thing you asked for.
5. Who else is involved
- Amazon Web Services hosts the site, stores the mail and runs the code, in the US (Northern Virginia).
- Cloudflare provides our DNS and the mail routing that accepts a message before it reaches our storage. It also provides the anti-spam check on the contact form, which receives your IP address when you press Send on that form.
- A form-delivery service passes contact-form messages to the mailbox we reply from.
- Google Fonts. The site’s three typefaces load from fonts.googleapis.com and fonts.gstatic.com. Your browser fetches them directly, so Google sees your IP address and browser details. This one is different from the others — it’s a public asset service rather than a supplier we have an agreement with — which is why we intend to serve the fonts from our own domain instead.
Because the service runs in the United States, using it means data about you is transferred there. If you’re in the UK or the EEA, that transfer is part of providing the service you asked for.
6. What a disposable inbox can’t protect you from
The honest limits, in one place:
- An inbox is only as private as the browser that made it. Anyone who can use that browser profile can open it, because the cookie is the only credential there is.
- Clearing cookies loses the inbox, permanently and immediately. We can’t restore it: nothing connects you to it.
- Mail isn’t end-to-end encrypted. It’s encrypted in transit where the sending server supports that, and encrypted at rest in our storage, but treat anything arriving at a disposable address as readable.
- The sender always knows the address they sent to, and what they put in the message.
- Don’t use a disposable address for anything you’d mind losing or anything you’d mind a stranger reading. Not banking, not medical or legal mail, and not account recovery for anything you care about.
7. Your rights
If you’re in the UK, the EEA, or a US state with a privacy law, you have rights to access, correct, delete and object to the processing of your personal data.
Here is the awkward part, stated plainly: for an inbox, we usually can’t act on them, because we have no way to tell that a given inbox is yours. There’s no account to prove it with, and we’d rather that stayed true than invent an identity to check requests against. What exists instead is a Delete button that removes the inbox and every message in it straight away, and an expiry that does the same thing within the hour whether you ask or not.
Where we can act is the contact form. Write to us and we’ll delete your message, and our reply, on request.
Where UK and EU law applies, our lawful basis is legitimate interests: providing the service you asked for, and keeping it from being abused.
8. Children
Inboxspam isn’t for children. Don’t use it if you’re under 13, or under 16 in the UK and the EEA. We don’t knowingly collect anything from a child — and since we collect no names, ages or identities at all, we have no way to detect one, which is why this is a rule rather than a check.
9. Abuse reports and legal requests
Mail that claims to have been sent from one of our addresses is forged: Inboxspam cannot send. We’d still like to know, because it means our domains are being used as a return address. Report it through the abuse form, which is read.
We respond to valid legal requests with whatever exists at the time. Usually that is nothing. The inbox, its mail and the rate-limit counter are all gone within the hour, the logs hold no addresses, and we have no identity for anyone to hand over.
10. Changes
If this policy changes, the date at the top changes with it. If we ever start collecting something that isn’t in the table above, it’ll be listed here before we start.
11. Contact
Questions about this policy, or about anything we hold: use the contact form. It reaches a person.
See also the terms of use.