Extension Privacy Policy

    What the TempMailer browser extension collects, why, and how to delete it.

    What this policy covers

    This policy applies to the TempMailer browser extension, including the popup, background service worker, and any future content scripts we ship. It is a companion to our main website privacy policy, which covers the tempmailer.io service.

    What we collect

    The extension stores and processes the minimum necessary to run:

    • Locally on your browser (via chrome.storage.local): the randomly generated username for your temp inbox and the domain you selected (e.g. ghostinbox.store). These stay on your device.
    • On our servers: an anonymous user identifier, the username/domain pair you own, and any email messages delivered to your temp address (sender, subject, body, timestamp).
    • Only if you choose to sign in (optional - the free inbox works without an account): your account email address and password. The password is used to authenticate you and is stored only as a salted hash; we never keep it in plain text. After login we store short-lived session tokens in chrome.storage.local so you stay signed in.

    What we do NOT collect

    • No account is required to use the free inbox - signing in is entirely optional
    • No name, phone number, or payment details in the extension
    • No plain-text passwords - credentials are only ever hashed
    • No location, IP-based geolocation, or device fingerprinting
    • No browsing history, no tabs, no data from websites you visit
    • No analytics cookies, no tracking pixels, no third-party SDKs

    How we use your data

    • The anonymous user ID and the username/domain pair let us route incoming emails to your inbox and no one else's.
    • Email messages are shown to you in the extension popup. We don't read them, analyze them, or do anything else with them.
    • If you sign in, your email and password are used solely to authenticate you and load the reserved inboxes on your account - nothing more.

    We do not sell, rent, or share any of this data with third parties for advertising or any other purpose.

    Who has access

    Our servers and database are hosted by our infrastructure providers (including Render), which process the data on our behalf under their data processing agreements. Access controls ensure that only your anonymous user ID - or, if you sign in, your account - can read or modify your inbox and messages. TempMailer staff do not routinely access user inboxes.

    Retention and deletion

    • Your inbox persists as long as you keep it. Click "New address" in the extension to abandon the current inbox and mint a new one.
    • Uninstalling the extension removes the local reference to your inbox. The inbox record remains on our servers until deleted (see next item).
    • To fully delete an inbox and all its messages, email us at support@tempmailer.io with the inbox address (e.g. abc123@ghostinbox.store). We purge inbox + messages within 7 days of receiving the request.
    • Inactive inboxes (no new messages in 90 days) may be auto-deleted to manage storage.

    Security

    All traffic between the extension and our servers uses TLS (HTTPS and WSS). Data is encrypted at rest on our managed hosting infrastructure. Account passwords are never stored in plain text - only as a salted hash - and session tokens are short-lived and rotated.

    Permissions we request (and why)

    • storage - remembers your inbox address between browser sessions (and, if you sign in, keeps your session token) so you don't have to regenerate or re-authenticate every time.
    • clipboardWrite - powers the "Copy" button so you can paste your temp address into signup forms.
    • host access to tempmailer-backend.onrender.com - connects to the TempMailer backend to create inboxes, fetch your messages, and (optionally) sign you in. This is the only domain the extension contacts.

    Children

    TempMailer is not directed to children under 13. If you believe a child has used the extension and you'd like their data removed, email us and we'll purge it promptly.

    Changes to this policy

    If this policy changes materially, we'll update the "Last updated" date below and - for significant changes - surface a notice in the extension itself. Continued use after an update means you accept the revised policy.

    Contact

    Questions, deletion requests, or privacy concerns: support@tempmailer.io.

    Last updated: April 23, 2026