Privacy and data retention
Short version: no accounts, no cookies set by us, no tracking scripts of our own, and every message is deleted automatically within 60 minutes of arriving. Advertising is served by Google and described below.
What we store
For each generated address we store the address itself, the domain, a creation timestamp and a message count. For each received message we store the sender, subject, plain-text body, sanitized HTML body, extracted links, attachment metadata (filename, size and MIME type only) and two timestamps: when it arrived and when it must be deleted. Nothing is stored about the person reading the inbox.
What we do not store
No account records, because there are no accounts. No passwords. No email address of yours.
We set no cookies of any kind, including analytics cookies, and no advertising identifiers
of our own — the only cookies that can appear come from the advertising partner described
under “Advertising” below. No browser fingerprint. Your generated address is kept in your
own browser's sessionStorage, which is discarded by the browser when you close
the tab, and it is never written to a cookie or synced anywhere.
Retention
Every message carries a deletion timestamp set 60 minutes after it arrives. Once that timestamp passes the message is no longer served or readable through any interface, and it is erased by an automatic time-to-live policy at the storage layer, in practice within 24 hours of expiry. Expiry applies whether or not the message was read. There is no archive, no interface through which an expired message can be retrieved, and no copy is kept once the deletion has run.
The ten-minute mode is a shorter clock on the address, not on the message: the address stops being offered to you after ten minutes, while any message it already received is deleted on the same 60-minute schedule as everything else.
Attachments
Attachment contents are not retained or served. Only the metadata listed above is kept, so the inbox can tell you a file was attached without ever handing you an executable.
Message safety
Incoming HTML is sanitized on our servers before it is stored: scripts, forms, iframes, event
handlers, remote images and tracking pixels are removed at write time rather than at render
time, so a tracking pixel never gets the chance to report that you opened the mail. The
remaining HTML is displayed inside an iframe with an empty sandbox attribute and
its own default-src 'none' content-security policy, which blocks every network
request the message could attempt. Links are listed outside that frame so nothing is fetched
unless you deliberately click it.
Inboxes are public to whoever knows the address
There is no authentication, so anybody who knows or guesses an address can read its inbox. The local part is ten random characters from a 32-symbol alphabet, which makes guessing impractical, but it is not a secret worth relying on. Never send anything sensitive to a temporary address.
Advertising
This site shows advertising served by Google AdSense. Google and its partners may use cookies or device identifiers to serve and measure ads; see how Google uses data from partner sites. In the EEA and the UK, ads are served non-personalised and a consent message is shown before any advertising cookie is set. We ourselves still set no cookies of any kind.
Third parties
Hosting and mail routing are provided by Cloudflare; message storage and the inbox API run on Google Cloud (region asia-south1, India). Advertising is provided by Google AdSense as described above. We retain no server access logs of inbox readers.
Who is responsible, and your rights
This service is operated as part of Webmail (WebMail Team, Bangalore / Pune, India) — full details on the legal notice. Sender data in received messages is processed on the basis of legitimate interest, for the sole purpose of showing the message to the address holder, and is deleted automatically as described above. You may request access to or erasure of data relating to you, or complain to your local data protection authority. Because messages self-delete within the hour, in most cases there is nothing left to access or erase by the time a request arrives.
Contact
Data questions and requests: info@sowebmail.com. Abuse reports: see the acceptable use page and the legal notice.