Temporary inboxes do not require your name, phone number, or primary email address; the address and access token are used only for the current receiving session.
Last updated: September 4, 2026
Privacy is more than a promise—it means clear boundaries for every type of email data
This policy explains what ForwardSMTP collects, why it processes that data, how long it keeps it, and how you can access or delete it while using three-hour temporary inboxes and long-term forwarding addresses.
Temporary addresses are valid for three hours by default. Once they expire or you replace them, they can no longer be used as a recoverable identity.
Logged-in users can view delivery records from the past 30 days in the dashboard; they are then automatically deleted as scheduled.
We do not sell or rent personal data, build advertising profiles from email content, or add third-party analytics code directly to our pages.
1. Scope and roles
This policy applies to the temporary email, forwarding alias, email archive, and verification-code login features provided by forwardsmtp.com. It does not apply to third-party websites you access through email; those parties process submitted data under their own policies.
When you create a temporary inbox, we process the data needed to deliver messages as a service provider. When you use the forwarding dashboard, you choose which aliases to create and where to send messages, and we forward and archive them for a limited period at your direction.
2. What data we collect
Temporary inboxes process system-generated addresses, random access tokens, expiry times, sender and recipient details, subjects, message bodies, and attachments. To prevent abuse, the service may also record limited security logs such as request times, network addresses, browser types, and API errors.
The forwarding service processes your receiving email address, created aliases, alias status, delivery results, message bodies and attachments, and, optionally, whether an authenticator is enabled. Authenticator secrets are used to establish TOTP authentication and are not used to analyze your other accounts.
| Data category | Primary purpose | Typical retention |
|---|---|---|
| Temporary address and email | Receive, display, and delete messages from the current session | While the address is valid; 3 hours by default |
| Forwarding delivery records | Show successful, failed, or spam results and support retries | Up to 30 days |
| Login verification code | Confirm control of the receiving email address | Valid briefly; expires after verification |
| Security and rate-limit logs | Prevent bulk abuse and investigate failures | The shortest period needed for security purposes |
| Customer support communications | Respond to requests and record resolution outcomes | Until the issue is resolved and for any required compliance period |
3. Processing purposes and legal basis
We process email data to provide services you actively request: creating an inbox, displaying incoming messages, forwarding them to your chosen address, providing delivery tracking, and protecting the dashboard. Without this processing, core features cannot work.
Security logs help maintain service integrity, limit automated abuse, troubleshoot delivery failures, and enforce our terms of service. We do not read message bodies for ad targeting or repurpose email content to train public-facing generative AI models.
4. Expiration, deletion, and backups
Temporary inboxes expire according to the countdown shown on the page. Deleting a message or replacing an address ends the corresponding data’s availability early. Forwarding records remain in the dashboard for 30 days, and you can also delete individual records or an alias sooner.
After deletion from active systems, limited copies may remain briefly in disaster-recovery backups and will be overwritten during the backup rotation cycle. We will not restore an expired temporary address from backup for continued login access.
6. Security measures and practical limits
We use encryption in transit, short-lived tokens, permission isolation, API rate limiting, and optional authenticator codes to reduce risk. Email is transmitted across multiple systems, and we cannot fully control the actions of sending servers, network relays, or receiving services.
Temporary email should not be used for banking, healthcare, government identity, or critical accounts that cannot be recovered. Do not share your inbox token, and close the page or replace the address after using a shared device.
8. Access, correction, and deletion rights
Logged-in users can view aliases and records from the past 30 days in the dashboard, pause or delete aliases, and delete individual messages. Temporary users can delete messages or replace their inbox; because identity registration is not required, we generally cannot associate an expired anonymous token with its requester.
Under applicable law, you may also request access, correction, deletion, or restriction of processing, or object to specific processing. To avoid disclosing data to the wrong person, we may ask you to demonstrate control of the receiving email address or relevant token.
9. Children
This service is not directed at children below the local digital-consent age and does not knowingly collect children’s data. If a parent or guardian believes a minor submitted personal data to us, they can contact us with the relevant address and date range.
After confirmation, we will delete the data where it can be identified and the law permits. Anonymous temporary inboxes are designed to limit searches by name, so please provide enough—but not excessive—information to locate the data.
10. Policy updates
We may update this policy when features, legal requirements, or infrastructure change. We will highlight material changes on this page and update the last-updated date at the top.
Updates will not suddenly use already-collected data for an incompatible new purpose. If the law requires consent for a new purpose, we will offer a choice first rather than automatically expanding the scope of use.
11. Contact and complaints
Privacy questions, rights requests, or security reports can be sent to support@forwardsmtp.com. Please include the feature used, relevant dates, and the action you would like us to take, but do not attach unnecessary sensitive message content to an ordinary email.
We will confirm receipt and respond within the period required by applicable law. If you believe the outcome is inadequate, you may also complain to the data protection authority with jurisdiction in your area.
12. Language and interpretation
This policy is available in multiple languages for convenience, and each version expresses the same data-processing principles. If a translation is ambiguous, we will interpret it in light of the service’s actual data flows and the reasonable interpretation that better protects users.
This policy and the Terms of Service together form part of the rules governing use. If they conflict on personal-data processing, the specific explanations in this policy about data scope, purposes, and rights take precedence.