Last updated: August 7, 2026.
This policy explains how Temp Mail 24 processes information when you visit temp-mail24.com, use a temporary inbox, play an optional browser game, or contact us. Temp Mail 24 is the controller of the site-level processing described here. Contact the operator through the contact page.
Important privacy limits
No account, name, permanent email address, or password is required to open an inbox. This reduces the information we ask you to provide, but it does not make the Service anonymous, confidential, or suitable for sensitive communications. A person who obtains a working address or browser token may be able to access messages. Do not use Temp Mail 24 for banking, healthcare, identity documents, private keys, account recovery, or information you cannot safely lose or disclose.
Information we process
- Temporary inbox data: the generated address, encrypted browser token, and incoming message headers, sender and recipient information, subject, body, attachments, timestamps, and delivery metadata supplied by senders and mail systems.
- Technical and security data: IP address, request time, requested URL, referrer, browser/device information, response status, errors, rate-limit data, and ordinary web, mail, firewall, and hosting logs.
- Reader contribution and membership data: If Temp Mail 24 makes a contribution feature available through Google Reader Revenue Manager, Google may provide us with the member identity or email address you choose to share, the selected plan and recurrence, amount and currency, membership or contribution status, timestamps, and transaction, cancellation, or refund identifiers. Google processes payment credentials; Temp Mail 24 does not receive your full payment-card number.
- Contact data: the name, reply address, category, message, and other information you voluntarily submit through the contact form.
- Usage and advertising data: page views, allowlisted product events, approximate location, device/browser information, consent signals, advertising interactions, and identifiers processed by Google Analytics, Google AdSense, Google Privacy & Messaging, or their partners when permitted.
- Session replay and interaction diagnostics: Microsoft Clarity processes page interactions, navigation, device/browser data, approximate location, performance signals, and JavaScript errors to help us understand and improve the site. Private inbox roots are masked in the page markup and Clarity is configured for strict text masking. Clarity may operate without cookies according to consent and project settings.
- Cookie-free traffic statistics: Ahrefs Web Analytics receives page URL, referrer, user agent, language, approximate city/country derived from IP, and interaction events. Ahrefs states that raw IP addresses are discarded and a daily salted hash is used for daily visitor counts.
- Optional game data: scores, counters, a random pseudonymous player ID, and leaderboard results. Game values may remain in local storage; the server leaderboard stores up to 100 pseudonymous results and does not intentionally store an email address with a score.
Incoming messages are provided by third-party senders, not necessarily by the person viewing the inbox. Do not send personal information about another person to a temporary address unless authorized.
Purposes and legal bases
- Provide the requested Service: assign an address, retrieve and display messages, reset the inbox, operate requested game features, and answer support requests. Where applicable, this is necessary to perform our agreement with you or take steps at your request.
- Operate and protect the Service: diagnose failures, prevent fraud, spam, malware, automated abuse, and attacks, enforce the Terms, and maintain availability. We rely on legitimate interests in operating and securing a limited receive-only service, balanced against user rights.
- Process voluntary contributions: If you choose to contribute, we process the limited membership and transaction records made available to us to complete the requested arrangement, administer recurring contributions, cancellations and refunds, prevent fraud, provide support, and meet accounting, tax, and legal duties. Depending on the activity, the legal basis is taking steps at your request or performing the contribution arrangement, our legitimate interests in operating and protecting the Service, or compliance with law.
- Comply with law: retain or disclose limited information when necessary to meet a binding legal obligation or valid legal process.
- Analytics and advertising: where consent is required, optional storage and processing are based on consent. You may refuse or withdraw consent without losing the essential inbox. Where consent is not required, limited analytics may operate based on our legitimate interest in understanding and improving the site, subject to available opt-outs.
Inbox token, security, and retention
The essential
tmtoken
cookie contains an encrypted representation of the assigned address. It is HttpOnly, SameSite=Lax, limited to the site path, and Secure on HTTPS. Its configured lifetime is up to 30 days from issue unless replaced, reset, deleted, or the configuration changes. It is not an account, password, or guarantee of exclusive access.
Messages are held by connected mail infrastructure only for operational periods determined by mailbox capacity, provider configuration, cleanup, security, and legal requirements. We do not promise a fixed message-retention period or recovery. Resetting an address or clearing browser data can end practical access even if a copy remains briefly in a mail system or backup.
Security and web logs are retained only as long as reasonably needed for operations, abuse prevention, incident investigation, or legal claims. Contact records remain while a request is handled and for a reasonable follow-up or legal period. Provider records follow the relevant provider’s settings. Local game data remains until site storage is cleared.
If you contribute, we retain available membership and transaction records while needed to administer the contribution, handle cancellations, refunds, disputes, fraud, and support, and for the accounting, tax, limitation, and legal periods that apply. We then delete or anonymize them where reasonably possible. Google’s retention of payment and account data is governed by its own notices.
Providers, disclosures, and international transfers
Information may be processed by hosting, content-delivery, mail, security, WordPress/contact-form, analytics, advertising, and consent-management providers as needed for their functions. Current integrations include Microsoft Clarity, Google Site Kit/Google Analytics, Google AdSense and Privacy & Messaging, and Ahrefs Web Analytics. Their own policies govern processing they perform as independent controllers.
Third-party vendors, including Google, may use cookies or similar technologies to serve and measure ads using information from a visitor’s prior visits to this website or other websites. Google’s advertising cookies allow Google and its partners to select ads using visits to Temp Mail 24 and/or other sites on the Internet. Where required, advertising storage, personalized advertising, and related personal-data processing follow the choices recorded through our consent controls. Learn how Google uses information from sites and apps that use its services, review Google Business Data Responsibility, or manage personalized advertising in Google Ads Settings.
If the contribution feature is made available, Google Reader Revenue Manager, Google Payments, and Google Publisher Center may process payment, membership, cancellation, refund, fraud-prevention, support, and compliance data under the Google terms and notices presented at checkout and the Google Privacy Policy. Google determines its role for the processing it performs. We receive only the member and transaction information Google makes available to publishers and disclose it to service providers, professional advisers, authorities, or counterparties only when needed for these purposes or required by law.
Providers may process information outside your country. Where required, transfers should rely on an adequacy decision, contractual safeguards, or another lawful mechanism. We may disclose information when required by valid law, to protect rights and infrastructure, or in a genuine reorganization subject to safeguards. We do not knowingly sell lists of temporary addresses or message contents.
Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of personal data; object to processing based on legitimate interests; withdraw consent; and complain to a data-protection authority. These rights are not absolute. Because no account is required, we may be unable to identify records as yours without the browser token or adequate evidence, and we will not retain extra data merely to identify requesters.
You can reset the address, clear
tmtoken
and local storage, use browser controls, or reopen Privacy and cookie settings. Residents of applicable US states can use Do Not Sell or Share My Personal Information. We respect applicable browser opt-out signals, including Global Privacy Control, where legally required. Google choices are also available through Google Ads Settings.
If you make a recurring contribution, use the cancellation controls provided by Google. You may use the contact page if you need help locating those controls or want to exercise a privacy right concerning contribution records held by Temp Mail 24.
Submit a rights request through the contact page with only the minimum information needed to understand and verify it.
Children
The Service is not directed to children who cannot lawfully consent to online services in their jurisdiction. A parent or guardian who believes a child submitted personal information should contact us.
Changes and contact
We may update this policy when the Service, providers, or legal requirements change. The date above identifies the latest material revision. Privacy, security, legal, and abuse requests can be submitted through the contact page. Never include passwords, verification codes, or unnecessary private messages.