When someone sends mail to your generated address, the receiving infrastructure routes it to storage. The website uses your browser’s signed cookie to retrieve only the mailbox you can access. Your everyday address need not be shared with the sender, but the website and mail providers still process message and connection data. This is not end-to-end encrypted email or a guarantee of anonymity.
Keep the same browser and its cookies to use your inbox for 24 hours. Creating a new address or clearing cookies removes access to the previous inbox. Use a permanent email account for banking, important accounts, and password recovery. Access expiry does not mean all stored copies are immediately deleted.
Try it with a non-sensitive message
For example, receive a test notification you control, read it, then close the mailbox when the task is finished. Before closing it, keep any non-sensitive result you need. A closed mailbox cannot be recovered by typing its address. Switching the website language keeps the same browser session; moving to another device does not transfer access.
What remains after access expires
The 24-hour timer is an access limit, not a deletion certificate. HaruMail receives mail through Cloudflare and stores message records in Supabase. Automatic deletion of those records after 24 hours is not configured. The sender may also retain a copy. Read the retention policy before using the service; do not send identity documents, payment details or private correspondence to this mailbox.
How this guide is maintained
HaruMail publishes these guides based on the service’s implemented behavior and the references below. Examples use fictional data. If a step or explanation is incorrect, send a correction through the contact page without including private email content.