← Back to Dev-Mail

Privacy Policy

Effective date: 4 December 2025

Dev-Mail (“we”, “us”, “dev-mail”) provides temporary, anonymous mailboxes for developers and teams. This policy explains how we process data when you use our website, APIs, and Telegram bot.

1. Information We Process

Dev-Mail is designed to minimize personal data. We only process:

  • IP address and browser User-Agent. Stored when you first open the site, and used to derive the session token below and to enforce rate limits. The same browser on the same network therefore returns to the same inbox instead of being handed a new one.
  • Session identifiers. A token that keeps a temporary inbox attached to you. It is a hash of your IP address and User-Agent, so it is stable rather than random, and it is not anonymous with respect to those two values.
  • Message content. Emails you instruct us to receive, stored as delivered. Disks are encrypted at rest by the hosting provider. Attachments are not stored.
  • Operational metadata. Timestamp, mailbox host, and delivery status, kept to troubleshoot abuse, rate limits, and deliverability.
  • Telegram handle. Only when you bind our bot. We store the chat ID required to push notifications and nothing else.

2. How We Use Data

  • Deliver transient email to the sandbox inbox you created.
  • Enforce abuse-prevention rules, including rate limits and filtering malicious payloads.
  • Provide voluntary notifications (e.g., Telegram pushes) that you explicitly enable.

We never sell, rent, or feed your traffic into advertising or analytics marketplaces.

3. Retention & Deletion

  • Addresses. An address is released after six hours without activity and can then be handed to someone else. Once it is released you lose access to it, and rotating your address has the same effect immediately.
  • Mailbox contents. We do not currently run an automatic hard-delete job, so a message row can outlive the address that received it even though nobody can reach it any more. Treat this service as transient plumbing, not as storage, and never route anything you would mind us still holding.
  • Tokens. The session token is derived from your IP address and User-Agent, so it does not rotate on its own. It changes when either of those changes.

You may request deletion of data still tied to your token via [email protected]. We respond within five business days.

4. Security Controls

  • Script and iframe tags are removed before a message is displayed, and attachments are never stored. Remote images are not blocked, so opening a message can still tell the sender you opened it.
  • The database is not reachable from the public internet; the application reaches it over a private network address.
  • Traffic to the site is served over HTTPS, terminated at our CDN.

5. Your Choices

  • Use Dev-Mail without revealing a personal identity.
  • Rotate or delete inboxes at any time via the “New Email” control.
  • Unbind Telegram instantly by sending /unbind to the bot.
  • Contact us to access, export, or erase any remaining metadata tied to your token.

6. International Data Transfers

Application and database servers currently run in Hong Kong, and requests reach them through Cloudflare’s global network, so traffic may be routed via a data centre in your own region first. Wherever we add capacity, the same safeguards apply: encryption in transit, access control, and retention minimization.

7. Updates

We may revise this policy if we add new features or regulatory requirements. Material changes will appear here with a new effective date. Continued use of Dev-Mail after an update constitutes acceptance.

8. Contact

Email [email protected] for any privacy request. We answer verified requests within five business days.

© 2026 Dev-Mail. All rights reserved.