Privacy
Last updated 1 September 2026
inboxsink hands out disposable e-mail addresses. They receive mail and are then deleted. This page says exactly what is stored, for how long, and what never happens.
What we store
- Messages sent to a disposable address: sender, subject, body, headers and attachments, plus any verification code or confirmation link we extract from them.
- The address itself and its expiry time.
- Technical logs (IP address, timestamp, requested route) kept briefly to rate-limit abuse and keep the service standing.
- If you create an API account: your e-mail address, a password hash, and the hash of each API key. The key itself is shown once and never stored in clear.
How long
A free inbox and everything in it are deleted automatically when the inbox expires
— one hour after creation, unless you extend it. Deletion is a real DELETE, not a flag.
You can also delete an inbox yourself at any moment, from the website or the app.
Who can read a disposable inbox
An address generated for you is 12 random characters: guessing it is not realistically possible. But there is no password on a free inbox — anyone who knows the exact address can read what it receives. If you deliberately choose a short, guessable address, treat everything sent to it as public. Never use a disposable address for anything that matters: banking, health, identity, or an account you intend to keep.
What we never do
- We never sell, rent or share your messages with anyone.
- We never send mail from a disposable address — the pool domains are receive-only, with SPF
set to
-alland DMARC top=reject. There is no reply button because a reply would not arrive. - We never load remote images inside a message by default: an image is a read receipt for the sender.
- We do not profile you and we run no advertising network on your messages.
The mobile app
The iOS app collects nothing about you. Your address history, your theme and your language stay on your device and are never sent to us. The app talks to our API only to create an inbox, read it, extend it, delete it, or report an abusive message. It contains no analytics SDK, no advertising SDK and no account.
Reporting abuse
Any message can be reported from the app or the website. A report stores the message reference, the address it reached, the reason given and the time. We remove illegal content and disable pool domains that go bad. Write to abuse@inboxsink.com.
Your rights
Under the GDPR you may ask for access, correction or erasure of the data attached to an API account. Free inboxes carry no identity, so there is nothing to look up: they erase themselves on expiry. Contact contact@inboxsink.com.
Subprocessors
Hosting: Hostinger (Lithuania/France). Transactional e-mail (account mail only, never disposable mail): Mailjet, Sinch France. Payments, for paid API plans only: Stripe.
inboxsink — Terms · Home · contact@inboxsink.com