Temporary email
Addresses are valid for 3 hours by default and can be extended to no more than 24 hours after creation. Messages enter the cleanup process when the mailbox expires, and attachments are not retained.
Updated: August 27, 2026
This policy explains how OrbForward handles data generated by temporary email, anonymous forwarding, and dashboard sign-in. We design our services around shorter retention periods, fewer links to identity, and controls you can revoke.
Each feature has its own retention purpose and period. Temporary mailboxes are not long-term cloud inboxes, and forwarding archives are not kept indefinitely.
Addresses are valid for 3 hours by default and can be extended to no more than 24 hours after creation. Messages enter the cleanup process when the mailbox expires, and attachments are not retained.
Your login email is used for delivery and account identification. Aliases can be paused or deleted at any time. Forwarding records are retained for up to 30 days.
To prevent abuse, we process IP addresses, request times, error types, and essential device information. We do not use this data to build advertising profiles.
You can replace a temporary address, pause or delete aliases in the dashboard, disable two-step verification, and contact us with data requests.
The periods below are operational maximums, not a promise that every record remains until the final day. Security investigations, dispute handling, or legal obligations may require limited extensions.
| Data category | Purpose | Typical period | Limits |
|---|---|---|---|
| Temporary addresses and messages | Receive and display short-lived email | 3–24 hours | Attachments are not retained; messages over 100 MB are rejected |
| Login email and verification codes | Verify identity for the forwarding dashboard | Code: 10 minutes; account: until deleted | Verification codes cannot be used to read temporary mailboxes |
| Forwarded email archive | View status, retry delivery, and identify spam | Up to 30 days | Attachments of 50–100 MB are forwarded but not archived |
| Operational and security logs | Rate limiting, troubleshooting, and abuse prevention | Kept for the minimum period required for security | Not sold or used for cross-site advertising |
When you use a temporary email address, we process the generated address, access token, expiration time, email headers, message body, and delivery time so we can display messages to the browser holding that token. The token is stored in your browser; clearing site data or changing devices may make your inbox unrecoverable.
When you use forwarding, we process your receiving address, the aliases you create, delivery status, and the message content necessary to provide the service. If you enable two-step verification, we store key material used to validate one-time codes, but we do not request or store your authenticator account password.
We generate addresses, receive mail, forward messages, and display archives to provide services you request. To protect our systems and users, we also apply rate limits, filter malicious content, diagnose failures, and conduct necessary security audits.
We do not serve personalized ads based on email content, and we do not sell login addresses, aliases, or message content. We disclose the minimum necessary data only to providers or authorities when required for infrastructure, email delivery, security protection, or legal compliance.
Temporary mailboxes are for short-term receipt and do not retain attachments. Attachments up to 50 MB in forwarded messages may be retained briefly with the archive; attachments from 50–100 MB are forwarded on a best-effort basis without an on-site copy; messages over 100 MB are rejected.
HTML email is displayed in a restricted frame to reduce the risk of email scripts affecting the site. Automated filtering and sender reputation checks may be inaccurate. You can review status in the dashboard and retry or mark permitted messages as not spam.
We protect data with access tokens, encryption in transit, permission isolation, request rate limiting, and two-step verification. No online system can promise absolute security, so important accounts should not depend on an unrecoverable temporary address.
Our infrastructure may process data outside your country or region. When cross-border processing occurs, we use contracts, access controls, and data minimization as required by applicable law, and restrict providers from using data for their own purposes.
You can stop using a temporary address, delete access credentials from your browser, or pause and delete aliases in the dashboard. For data linked to a login email, you can request access, correction, deletion, or restriction of processing, though we may need to verify control of the email address again.
Data required by law, security-incident investigations, or abuse-prevention measures may not be deleted immediately. We will explain why we cannot fulfill a request, the applicable basis, and the expected retention period.
This service is not intended for children below the age at which they can independently consent to data processing in their region. If a parent or guardian believes a minor has provided us with personal information, they can contact us; after reasonable verification, we will take appropriate action.
When we make material changes to this policy, we will update the date on this page and, where appropriate, explain them through an in-product notice. For privacy requests or security concerns, contact us at support@orbforward.com.
A temporary email is enough for a single verification code. For support, subscriptions, or replies, create a forwarding alias you can revoke independently.