Your data is yours alone
We built MinuteMail so that privacy is the default — not a setting you have to find and turn on.
Last updated: January 2025
Our Promise
MinuteMail was built with privacy as its foundation — not as an afterthought. We believe your personal data belongs to you, and temporary email should leave zero trace. This policy explains exactly what we collect (almost nothing), what we do with it (nothing), and how your data is handled.
What We Collect
TL;DR — Effectively nothing.
We do not collect personal data, create user profiles, set tracking cookies, or use analytics services.
MinuteMail does not collect:
- Names, email addresses, or phone numbers
- Account credentials (no accounts exist)
- Browser fingerprints or device identifiers
- Tracking cookies or advertising pixels
- Browsing history or referral data
- IP addresses in permanent storage
How Email Data Works
When a mailbox is created:
- 1A random address is generated — not linked to your identity
- 2Incoming emails are stored in Redis (volatile in-memory storage)
- 3Emails are delivered to your browser via WebSocket in real-time
- 4When the timer expires, all data is irrecoverably deleted
At no point is email content written to disk, backed up, or transmitted to third parties. Our SMTP server processes messages only to identify the destination mailbox and parse content for display.
Cookies & Storage
MinuteMail uses no tracking cookies. We may use browser localStorage to persist UI preferences (such as preferred session duration) — this data never leaves your device and is not transmitted to our servers.
Third-Party Services
We do not integrate analytics platforms (Google Analytics, Mixpanel, etc.), advertising networks, social media trackers, or any service that would expose your activity to third parties. Our infrastructure runs on standard hosting providers. While these providers may log network-level data for security purposes, MinuteMail's application layer does not access or retain this information.
Data Retention
Active session
Email data exists in Redis only while the timer is running
After expiry
All data (mailbox metadata, emails, attachments) is deleted from Redis with TTL-based expiration
No backups
We do not backup email data. Deleted means permanently gone
Security
- HTTPS/TLS encryption for all web traffic
- WebSocket connections secured with WSS
- Rate limiting to prevent abuse
- Input sanitization to prevent XSS and injection attacks
- No server-side logs of email content
Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect information from children. Since we don't collect personal data from anyone, this concern is inherently mitigated.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top. Your continued use after changes constitutes acceptance of the revised policy.
Privacy concerns? Reach us via our Contact page.