Privacy Policy
Last updated: 12 August 2026
The short version. We collect as little as possible. Using the free temp-mail page requires no account and no personal details. Messages sent to a disposable address are deleted permanently when the inbox expires โ usually within ten minutes. We do not sell data, run advertising trackers, or use third-party analytics. But a disposable inbox is not private: anyone who knows the address can read it.
1. Who is responsible
Balkrishna Enterprise, Rajkot, Gujarat, India, is the data fiduciary / controller for personal data processed through emailcheck.in and the InboxWire API. Contact: privacy@emailcheck.in.
2. What we collect
| Category | What it is | When |
|---|---|---|
| Nothing identifying | The free temp-mail page needs no name, no signup, no email address of yours | Anonymous use |
| Account data | Email address, a bcrypt hash of your password (never the password), plan, signup timestamp | If you create an API account |
| API keys | A SHA-256 hash of each key plus a short non-secret prefix. We cannot recover a key after it is shown to you once | API accounts |
| Inbox metadata | Address, creation and expiry time, message count, owning account (null for anonymous inboxes) | Every inbox |
| Message content | Sender, subject, body text and sanitised HTML of mail delivered to your address โ see section 3 | Until expiry |
| Usage counters | Number of emails received per account per calendar month, for quota enforcement | API accounts |
| Technical logs | IP address, user agent, request path, status and timestamp, kept transiently by our host for security, abuse prevention and rate limiting | All requests |
| Billing data | Handled entirely by our payment processor. We receive a transaction reference and status โ never your card details | Paid plans |
We do not use Google Analytics or any third-party analytics or advertising SDK, we do not embed social widgets, and we do not run remarketing pixels.
3. Email content and why it is not private
Addresses on the public page have no password and no owner. Anyone who knows or correctly guesses an address can read the mail delivered to it. Addresses are twelve random characters, which makes guessing impractical โ but this is a convenience feature, not a security control.
Never send anything sensitive to an InboxWire address: no password resets for accounts you care about, no banking or payment data, no government identifiers, no medical or legal information, no private correspondence.
We process incoming mail automatically. Before storing HTML we sanitise it: all images are
stripped (which defeats tracking pixels), scripts and event handlers are removed, and links
are rewritten with rel="noopener noreferrer nofollow". We do not read your mail, and we
do not use message content to train machine-learning models, profile you, or sell to anyone.
Attachments are parsed for their metadata only and are not stored. Message content is stored unencrypted at rest in our database for its short lifetime.
If someone sends mail to your disposable address, that sender's personal data (their address, name and anything they wrote) passes through our systems. We process it only to display it to whoever holds the address, and we delete it on expiry.
4. Why we process it, and our legal basis
| Purpose | Basis (GDPR Art. 6 / DPDP Act) |
|---|---|
| Receiving, sanitising, storing and displaying your mail | Performance of a contract / provision of the requested service |
| Accounts, authentication, API keys | Performance of a contract |
| Quota counting and billing | Contract, and legal obligation for tax records |
| Rate limiting, abuse prevention, security logging | Legitimate interests โ keeping the Service available and lawful |
| Responding to abuse reports and lawful orders | Legal obligation and legitimate interests |
| Service and security emails to account holders | Contract |
We do not process any data for advertising, and we do not carry out automated decision-making that produces legal effects for you.
5. How long we keep things
| Data | Retention |
|---|---|
| Anonymous inbox and its messages | 10 minutes from creation, extendable in the browser; deleted permanently by a sweep that runs every 60 seconds |
| API inbox and its messages | The TTL you set โ 1 hour default, up to a maximum of 1 hour (Free), 1 day (Starter) or 7 days (Pro) |
| Messages beyond the per-inbox cap | Further incoming mail is rejected once an inbox holds 100 messages; nothing already stored is evicted |
| Account record and API key hashes | Until you delete the account, then removed within 30 days |
| Monthly usage counters | Retained as aggregate rows for billing history |
| Server access logs | Short-lived, per our host's retention (typically days, not months) |
| Invoices and tax records | As long as Indian tax law requires |
Deletion is irreversible. We keep no archive or backup of message content, so we cannot restore an expired inbox for you โ nor produce it for anyone else.
6. Cookies
We use no advertising or tracking cookies, and we have no cookie banner because we do not need consent for what we set:
- Session cookie โ set only when you sign in to the dashboard. It holds a signed
JWT, is
HttpOnlyandSameSite=Lax, is markedSecurein production, and lasts up to 30 days or until you log out. Strictly necessary. - Browser local storage โ the temp-mail page remembers your current inbox ID locally so a refresh does not lose it. This never leaves your device and you can clear it at any time.
7. Who else touches the data
We share personal data only with the processors needed to run the Service:
- Hosting and managed database โ runs the application and stores data.
- Inbound email routing โ accepts mail on our domains and forwards it to our ingest endpoint.
- Payment processor โ takes payments directly; card data never reaches us.
- Domain registrar and DNS provider.
Each acts on our instructions under a data-processing agreement. We do not sell, rent or trade personal data, and we do not share it for anyone else's marketing.
We may disclose data where legally compelled by a valid order from a court or authorised agency, or where necessary to investigate abuse, protect our rights, or protect someone's safety. Given our retention periods, there is usually very little to disclose.
If the business is sold or reorganised, data may transfer to the acquirer under the same commitments; we will announce this before it takes effect.
8. International transfers
We operate from India and our providers may process data in other countries, including the EEA and the United States. Where data leaves its origin jurisdiction, we rely on the provider's standard contractual clauses or equivalent safeguards. Given how briefly message content exists, exposure is inherently minimal.
9. Security
- HTTPS everywhere in production, with HSTS and a strict Content-Security-Policy.
- Passwords stored as bcrypt hashes; API keys stored as SHA-256 hashes and compared in constant time. Neither is ever recoverable in plaintext.
- All incoming HTML is sanitised; every image is stripped, defeating tracking pixels.
- Rendered messages are shown in a sandboxed iframe with scripts disabled.
- Rate limits on inbox creation, ingest, signup and authentication endpoints.
- Automatic expiry means the amount of data at risk at any moment is small by design.
No system is perfectly secure. Message content is not encrypted at rest, and disposable inboxes are readable by anyone with the address โ so please treat them as public. Report a vulnerability to abuse@emailcheck.in; we will not pursue good-faith researchers who avoid privacy violations and service disruption.
10. Your rights
Subject to applicable law โ including India's Digital Personal Data Protection Act, 2023, and the GDPR where it applies to you โ you may request:
- Access to the personal data we hold about you;
- Correction of inaccurate or incomplete data;
- Erasure of your account and its data;
- Portability of data you provided, in a machine-readable form;
- Restriction of, or objection to, processing based on legitimate interests;
- Withdrawal of consent, where processing relies on consent; and
- to complain to your supervisory authority โ in India, the Data Protection Board; in the EEA/UK, your national authority.
Write to privacy@emailcheck.in. We respond within 30 days and may ask you to verify control of the account email. Two practical notes: for anonymous inboxes we hold nothing that identifies you, so we cannot link a request to your data; and expired message content no longer exists, so it cannot be produced.
You can delete your own account at any time from the dashboard, and revoke any API key instantly.
11. Children
The Service is not directed at, and may not be used by, anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, write to privacy@emailcheck.in and we will delete it.
12. Changes
We will update this policy as the Service evolves. The "last updated" date changes with every revision, and material changes will be notified through the Service or by email to account holders before they take effect.
13. Contact and grievance officer
| Purpose | Address |
|---|---|
| Privacy, data rights, grievances (Grievance Officer) | privacy@emailcheck.in |
| Abuse, takedown, law enforcement, security reports | abuse@emailcheck.in |
| Billing and general support | support@emailcheck.in |
Balkrishna Enterprise, Rajkot, Gujarat, India. As required by Indian law, the Grievance Officer acknowledges complaints within 24 hours and resolves them within 15 days.
See also: Terms of Service ยท Acceptable Use Policy