Skip to the inbox

Privacy and data retention

Short version: no accounts, no cookies set by us, no tracking scripts of our own, and every message is deleted automatically within 60 minutes of arriving. Advertising is served by Google and described below.

What we store

For each generated address we store the address itself, the domain, a creation timestamp and a message count. For each received message we store the sender, subject, plain-text body, sanitized HTML body, extracted links, attachment metadata (filename, size and MIME type only) and two timestamps: when it arrived and when it must be deleted. Nothing is stored about the person reading the inbox.

What we do not store

No account records, because there are no accounts. No passwords. No email address of yours. We set no cookies of any kind, including analytics cookies, and no advertising identifiers of our own — the only cookies that can appear come from the advertising partner described under “Advertising” below. No browser fingerprint. Your generated address is kept in your own browser's sessionStorage, which is discarded by the browser when you close the tab, and it is never written to a cookie or synced anywhere.

Retention

Every message carries a deletion timestamp set 60 minutes after it arrives. Once that timestamp passes the message is no longer served or readable through any interface, and it is erased by an automatic time-to-live policy at the storage layer, in practice within 24 hours of expiry. Expiry applies whether or not the message was read. There is no archive, no interface through which an expired message can be retrieved, and no copy is kept once the deletion has run.

The ten-minute mode is a shorter clock on the address, not on the message: the address stops being offered to you after ten minutes, while any message it already received is deleted on the same 60-minute schedule as everything else.

Attachments

Attachment contents are not retained or served. Only the metadata listed above is kept, so the inbox can tell you a file was attached without ever handing you an executable.

Message safety

Incoming HTML is sanitized on our servers before it is stored: scripts, forms, iframes, event handlers, remote images and tracking pixels are removed at write time rather than at render time, so a tracking pixel never gets the chance to report that you opened the mail. The remaining HTML is displayed inside an iframe with an empty sandbox attribute and its own default-src 'none' content-security policy, which blocks every network request the message could attempt. Links are listed outside that frame so nothing is fetched unless you deliberately click it.

Inboxes are public to whoever knows the address

There is no authentication, so anybody who knows or guesses an address can read its inbox. The local part is ten random characters from a 32-symbol alphabet, which makes guessing impractical, but it is not a secret worth relying on. Never send anything sensitive to a temporary address.

Advertising

This site shows advertising served by Google AdSense. Google and its partners may use cookies or device identifiers to serve and measure ads; see how Google uses data from partner sites. In the EEA and the UK, ads are served non-personalised and a consent message is shown before any advertising cookie is set. We ourselves still set no cookies of any kind.

Third parties

Hosting and mail routing are provided by Cloudflare; message storage and the inbox API run on Google Cloud (region asia-south1, India). Advertising is provided by Google AdSense as described above. We retain no server access logs of inbox readers.

Who is responsible, and your rights

This service is operated as part of Webmail (WebMail Team, Bangalore / Pune, India) — full details on the legal notice. Sender data in received messages is processed on the basis of legitimate interest, for the sole purpose of showing the message to the address holder, and is deleted automatically as described above. You may request access to or erasure of data relating to you, or complain to your local data protection authority. Because messages self-delete within the hour, in most cases there is nothing left to access or erase by the time a request arrives.

Contact

Data questions and requests: info@sowebmail.com. Abuse reports: see the acceptable use page and the legal notice.