Legal ยท Updated 31 August 2026
Privacy Notice
This notice explains how Inboxes.Run processes data when operating temporary inboxes, accounts, Plus, Developer access and Domain Network.
1. Data we process
- Mailbox data: generated address, mailbox state, incoming message headers and content, and technical delivery metadata.
- Account data: email address or Telegram account information used for sign-in, account state and linked inbox information.
- Developer and network data: API-key metadata, usage counters, network entitlement/capacity state and custom-access request details you submit.
- Payment data: order, provider reference, amount, status and entitlement information. Payment credentials are handled by the payment provider rather than stored as card or wallet secrets by Inboxes.Run.
- Technical data: IP address, timestamps, request paths, service/security events and other logs needed to operate and protect the service.
2. Why we process it
We process data to provide the service and requested features, authenticate accounts, deliver and display incoming mail, operate API/IMAP, manage paid entitlements and active domain capacity, respond to support/access requests, prevent abuse, secure infrastructure, diagnose failures, comply with legal obligations and resolve payment disputes.
3. Legal bases
Where GDPR applies, processing may rely on performance of a contract or steps requested before a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where we specifically ask for it, such as using contact details to reply to a custom Domain Network request. You can withdraw consent for consent-based processing without affecting earlier lawful processing.
4. Temporary mail and retention
Free and newly created Plus inboxes normally last 24 hours. Message content is tied to the temporary mailbox lifecycle and is not intended as permanent storage. Reclaim does not restore old messages, sessions or access secrets. Account, billing, security and operational records may be retained longer when reasonably necessary for account operation, fraud/security investigation, dispute handling, accounting or legal obligations. We aim to minimise logs and remove or de-identify data when it is no longer needed for those purposes.
5. Exact-recipient boundary and residual mail
Ordinary Inboxes.Run receive products are designed to accept messages only for active recipients. Unknown, expired and historical recipients are intended to be rejected before message content is accepted. We do not intentionally operate a former-user residual-mail or dead-domain catch-all feed, and we do not use such messages for account recovery, identity access or resale.
6. Browser storage
The web app may store language/theme preferences and temporary mailbox access information in your browser so you can reopen an active inbox. Clearing browser storage may remove that local access information. Treat devices and browser profiles that can access your mailbox as sensitive.
7. Service providers and transfers
We may use hosting, DNS/CDN, payment, authentication, monitoring and support providers to operate the service. They receive only the data reasonably needed for their function and are subject to applicable contractual and security controls. Data may be processed in more than one country; where required, we use appropriate transfer safeguards.
8. B2B roles
For ordinary consumer/account operation Inboxes.Run determines core service purposes and means. For some B2B Domain Network workflows where a customer determines how mailbox data is used, controller/processor roles depend on the actual arrangement and may require a separate data-processing agreement.
9. Your rights
Where applicable, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent and complain to a supervisory authority. Some requests may be limited by the temporary nature of the service, security needs or legal retention duties.
10. Security and contact
We use technical and organisational controls intended to limit access, protect service secrets and isolate receive workflows. No internet service can guarantee absolute security. For privacy requests, use the Support link on inboxes.run and state that your request concerns privacy.
We do not sell personal message content or use ordinary customer mailbox content for unrelated threat-intelligence, account access or identity exploitation.