Temporary email
Addresses last 3 hours by default and up to 24 hours at most. Messages become inaccessible when the inbox expires or is destroyed.
This policy explains how Throwmx handles information when providing temporary inboxes and forwarding aliases. We process information only to provide the service, protect against abuse, and meet legal obligations. We do not sell personal information or use email content to build advertising profiles.
Addresses last 3 hours by default and up to 24 hours at most. Messages become inaccessible when the inbox expires or is destroyed.
Messages sent to aliases are forwarded to your login email and kept in an online archive for 30 days by design.
We do not sell personal information or use email bodies to build cross-site advertising profiles.
You can destroy a temporary inbox, pause or delete an alias, and contact us to make applicable rights requests.
This policy applies to temporary email, forwarding aliases, the login dashboard, and support communications on throwmx.com. When you visit third-party websites or click external links in emails, their privacy rules apply independently.
Throwmx is a receive-only email privacy tool and does not promise complete anonymity. Network operators, sending websites, and other services may still process your device and account information for their own lawful purposes.
When you create a temporary email address, we process the random address, access token, creation and expiration times, and the messages and attachments delivered to it. The access token restores access to the same inbox and should be protected like a short-lived password.
A temporary inbox does not require your real name or a registered account. After delivery, messages are processed only as needed for display, attachment downloads, abuse prevention, and basic operation—not to train advertising profiles.
When you use forwarding, we process your login email, verification status, created aliases, enabled or paused status, and quota. If you enable two-factor authentication, we also process the key status needed to complete TOTP setup.
Messages received by an alias are processed for spam detection, forwarding, status records, and a 30-day online archive. Your real email address is not shown to people who message the alias, but forwarding requires the system to know the destination address.
The system must process senders, recipients, subjects, message bodies, and attachments in transit to display or forward messages. Automated security checks may analyze technical characteristics and spam signals, but do not read content for advertising purposes.
Please do not use the service to receive highly sensitive information unnecessarily. If a sender accidentally sends sensitive content, you can delete the inbox or archived record and contact the sender to correct their process.
We process information to provide services you request, maintain security, diagnose faults, limit abuse, and comply with legal obligations. Necessary operational logs also help keep the service available and investigate unusual access.
Where the law requires consent as the legal basis, we will provide the appropriate choice. If data essential to core email functions is not provided, delivery or account verification may not be possible.
Servers may record request times, network addresses, browser information, response statuses, and security events for a reasonable period to operate the service and prevent abuse. We restrict log access and minimize links to email bodies where possible.
Browser local storage saves temporary email access credentials, interface preferences, and forwarding login tokens. Clearing browser data removes the local copy, but does not necessarily delete data still retained on our servers.
For hosting, network transmission, security, and email delivery, we may provide task-essential information to bound infrastructure providers. Providers may process data only under our instructions and contractual security requirements.
We do not sell personal information. If we receive a valid legal request, need to protect users and service security, or handle a corporate restructuring, we may disclose information as necessary and provide notice where required by law.
Different data has different lifespans, based on product purpose rather than indefinite retention. Backups, security logs, or legally required records may remain briefly after deletion from the primary system and are then cleared according to the rotation schedule.
| Data category | Typical retention | Deletion or limitation |
|---|---|---|
| Temporary inbox and email | 3 hours by default; up to 24 hours when extended | No longer accessible after expiration or destruction |
| Forwarded email archive | 30 days | Automatically cleared after expiration; can also be deleted early |
| Alias and account settings | While the account is in use | Deleted by the user or upon an applicable request |
| Security and operational logs | Limited period based on security needs | Cleared through rotation; may be extended when legally required |
Depending on the laws where you live, you may have rights to access, correct, delete, restrict, object to processing, or obtain a copy of your data. When making a request, specify whether it concerns a temporary inbox or forwarding account and what action you want us to take.
Temporary email does not require identity registration, so we may be unable to associate an expired, unverifiable address with the requester. To prevent data theft, we provide account information only when we can reasonably verify control.
This service does not knowingly collect information from children below the applicable local age of digital consent. A parent or guardian who discovers that a child has improperly provided data may contact us for review and deletion.
Internet infrastructure may process data in different jurisdictions. When data is transferred across borders, we use the contractual, technical, or organizational safeguards required by applicable law.
We use access controls, transmission protection, least privilege, rate limiting, and monitoring to reduce risk, but no internet service can guarantee absolute security. Users should also protect temporary tokens, login emails, and two-factor authentication keys.
If an incident may pose a significant risk to users, we will investigate, remediate, and notify affected users or regulators when required by law. Please send suspected vulnerabilities to the support email and do not publicly share anyone else’s messages.
When our product, legal requirements, or processing practices change, we will update the date on this page and provide appropriate notice for significant changes. Before continuing to use the service, you can review the new version and decide whether to proceed.
For privacy questions, complaints, or rights requests, contact support@throwmx.com. We will acknowledge your request within a reasonable period and explain the outcome or any legal limitations.