Privacy Policy

Last updated: July 19, 2026

This policy explains how TmpKit, an independently operated temporary-email service, handles data when you use the website, inbox, tools, articles, or contact form. Questions and privacy requests can be sent to [email protected].

The short version

TmpKit does not require an account, name, or password to open a temporary inbox. That reduces the information we ask you to provide, but it does not make the service anonymous or confidential. TmpKit and the infrastructure providers needed to run it still process limited technical data, and anyone who knows or guesses a temporary address may be able to view messages sent to it. Never use TmpKit for sensitive, private, financial, medical, government, work, or account-recovery communications.

Data we process

Temporary inbox service

To receive and display mail, we process:

  • the generated or user-selected temporary email address;
  • message headers, sender and recipient addresses, subject, body, timestamps, and attachments;
  • a random session identifier stored in an essential cookie; and
  • expiry and anti-abuse state associated with that session.

Messages are available for the active retention period shown in the app. The period may be extended once where the interface offers that option. Inbox records then expire according to the service's short-retention configuration. The delete control can remove messages for the current address sooner. We do not promise that changing an address recalls copies already sent or stored by a sender, recipient, network provider, or legally required backup.

Temporary addresses are not password-protected mailboxes. A custom, reused, shared, leaked, or guessed address can be selected or viewed by someone else. Treat every message as non-confidential.

Website and security data

When a browser connects, our systems and infrastructure providers may process IP address, request URL, date and time, user agent, referrer, response status, rate-limit events, security signals, and diagnostic logs. This is necessary to deliver pages, terminate TLS, prevent abuse, troubleshoot failures, and protect the service. These records are retained only as long as reasonably needed for security, reliability, legal obligations, or resolving an incident; provider retention may differ from ours.

Contact data

The contact form collects the name, email address, and message you submit. The form sends that information through our email-delivery provider to the service inbox so we can reply, investigate bugs or abuse, and keep a necessary support record. We retain correspondence for as long as needed to handle the request, maintain security records, resolve disputes, or meet legal obligations. You can avoid the form and email support directly.

DNS and email-analysis tools

Tool inputs such as domains, selectors, DNS records, or pasted email headers are processed to return the requested result. Do not paste personal or secret information into the header analyzer. Tool pages do not contain AdSense ad units.

Cookies, local storage, analytics, and advertising

Essential storage

TmpKit uses strictly necessary storage for the temporary inbox session, security, language, theme, and saved privacy choice. Blocking this storage may prevent core features from working.

Optional analytics

Google Analytics is disabled until you choose Accept analytics in TmpKit's privacy choices. If you reject it, the Analytics tag is not loaded. You can change this choice through Cookie settings in the footer. When Google Analytics is enabled, Google may process device and browser information, IP-derived location, page and interaction data, cookies, or similar identifiers under its own terms. We use aggregated reports to understand which public pages work and where errors occur; we do not send temporary email addresses, message contents, or contact-form fields to Analytics.

Advertising and Google products

During the current AdSense application review, TmpKit uses only Google's account-verification meta tag and does not load the AdSense advertising script. If the site is approved and advertising is enabled later:

  • manual ads are limited to edited blog-article pages after the article body; the homepage inbox, email viewers, tools, research pages, the blog index, About, Contact, and legal pages are excluded;
  • Google and its partners may place or read cookies, use web beacons, collect IP addresses, and use other identifiers to serve, limit, personalize, and measure ads;
  • Google may use data from visits to this and other sites in accordance with How Google uses information from sites or apps that use its services; and
  • users in the EEA, UK, and Switzerland receive Google's certified consent platform before eligible personalized advertising. The platform provides consent, rejection, granular choices, and a Privacy and cookie settings revocation link on ad-bearing pages.

You can manage personalized advertising in Google's Ads Settings and review industry opt-outs at YourAdChoices. Rejecting personalized advertising does not necessarily remove all contextual or limited ads.

We do not sell personal data. We do not knowingly send Google personally identifiable information in ad requests, and public ad-bearing URLs do not contain inbox addresses or contact-form values.

Service providers and disclosures

We use providers only where needed to operate the service, including:

  • Cloudflare for DNS, content delivery, TLS, performance, and security;
  • hosting, compute, database, Redis, object-storage, monitoring, and network providers;
  • mail infrastructure for receiving temporary messages; and
  • an email-delivery provider for contact-form correspondence;
  • Google, only for optional Analytics and, after approval and configuration, manual advertising on eligible publisher-content pages and its certified consent platform.

Providers process data under their own terms and may operate in other countries. We may also disclose data when required by valid law, to investigate abuse or security incidents, or to protect users, TmpKit, and the public. We do not claim that every part of the service runs without third parties.

Legal bases and international transfers

Depending on your location, we rely on performance of the requested service, legitimate interests in security and reliability, consent for optional Analytics and eligible personalized advertising, and compliance with legal obligations. International providers may process data outside your country using the safeguards available to them and required by applicable law.

Your choices and rights

Depending on applicable law, you may ask to access, correct, delete, restrict, or obtain a copy of personal data we control, object to certain processing, or withdraw consent without affecting earlier lawful processing. Because inboxes are not accounts and expire quickly, we may be unable to identify or recover data after expiry. We may request enough information to verify and scope a request without exposing another person's inbox.

Use the footer's Cookie settings to accept, reject, or change optional Analytics before advertising is enabled. If Google's certified consent platform applies after advertising is enabled, use its Privacy and cookie settings link for advertising choices. You may also configure browser storage, Global Privacy Control where supported, and Google Ads Settings.

Send requests to [email protected]. You may also complain to the data-protection authority in your jurisdiction.

Security and limitations

We use HTTPS, access controls, short retention, HTML sanitization, attachment handling controls, and operational monitoring to reduce risk. No internet service is perfectly secure. Temporary mail is intentionally low-security and should never be treated as encrypted, private, permanent, or suitable for account recovery.

Children

TmpKit is a general-audience utility and is not directed to children under 13. We do not knowingly create advertising audiences from child-directed activity. If you believe a child submitted personal data through the contact form, contact us.

Changes

We may update this policy when the service, providers, or legal requirements change. The date above identifies the current version. Material changes will be reflected on this page before or when they take effect.

See also the Terms of Service.