Temporary addresses last 3 hours and can be extended up to 24 hours. View retention options

Updated: August 27, 2026

Privacy Policy: We retain only the data needed to deliver your email

This policy explains how OrbForward handles data generated by temporary email, anonymous forwarding, and dashboard sign-in. We design our services around shorter retention periods, fewer links to identity, and controls you can revoke.

Data processing at a glance

Each feature has its own retention purpose and period. Temporary mailboxes are not long-term cloud inboxes, and forwarding archives are not kept indefinitely.

Temporary email

Addresses are valid for 3 hours by default and can be extended to no more than 24 hours after creation. Messages enter the cleanup process when the mailbox expires, and attachments are not retained.

Anonymous forwarding

Your login email is used for delivery and account identification. Aliases can be paused or deleted at any time. Forwarding records are retained for up to 30 days.

Security logs

To prevent abuse, we process IP addresses, request times, error types, and essential device information. We do not use this data to build advertising profiles.

Your controls

You can replace a temporary address, pause or delete aliases in the dashboard, disable two-step verification, and contact us with data requests.

Retention periods and limits

The periods below are operational maximums, not a promise that every record remains until the final day. Security investigations, dispute handling, or legal obligations may require limited extensions.

What information we collect

When you use a temporary email address, we process the generated address, access token, expiration time, email headers, message body, and delivery time so we can display messages to the browser holding that token. The token is stored in your browser; clearing site data or changing devices may make your inbox unrecoverable.

When you use forwarding, we process your receiving address, the aliases you create, delivery status, and the message content necessary to provide the service. If you enable two-step verification, we store key material used to validate one-time codes, but we do not request or store your authenticator account password.

Purposes and legal bases

We generate addresses, receive mail, forward messages, and display archives to provide services you request. To protect our systems and users, we also apply rate limits, filter malicious content, diagnose failures, and conduct necessary security audits.

We do not serve personalized ads based on email content, and we do not sell login addresses, aliases, or message content. We disclose the minimum necessary data only to providers or authorities when required for infrastructure, email delivery, security protection, or legal compliance.

Email and attachment handling

Temporary mailboxes are for short-term receipt and do not retain attachments. Attachments up to 50 MB in forwarded messages may be retained briefly with the archive; attachments from 50–100 MB are forwarded on a best-effort basis without an on-site copy; messages over 100 MB are rejected.

HTML email is displayed in a restricted frame to reduce the risk of email scripts affecting the site. Automated filtering and sender reputation checks may be inaccurate. You can review status in the dashboard and retry or mark permitted messages as not spam.

Security and international processing

We protect data with access tokens, encryption in transit, permission isolation, request rate limiting, and two-step verification. No online system can promise absolute security, so important accounts should not depend on an unrecoverable temporary address.

Our infrastructure may process data outside your country or region. When cross-border processing occurs, we use contracts, access controls, and data minimization as required by applicable law, and restrict providers from using data for their own purposes.

Your rights and choices

You can stop using a temporary address, delete access credentials from your browser, or pause and delete aliases in the dashboard. For data linked to a login email, you can request access, correction, deletion, or restriction of processing, though we may need to verify control of the email address again.

Data required by law, security-incident investigations, or abuse-prevention measures may not be deleted immediately. We will explain why we cannot fulfill a request, the applicable basis, and the expected retention period.

Children, changes, and contact

This service is not intended for children below the age at which they can independently consent to data processing in their region. If a parent or guardian believes a minor has provided us with personal information, they can contact us; after reasonable verification, we will take appropriate action.

When we make material changes to this policy, we will update the date on this page and, where appropriate, explain them through an in-product notice. For privacy requests or security concerns, contact us at support@orbforward.com.

Choose how to receive mail based on the relationship

A temporary email is enough for a single verification code. For support, subscriptions, or replies, create a forwarding alias you can revoke independently.