Updated September 7, 2026
Operator: lee davin
Data processed
We process the generated recipient address, sender, subject, readable body, and received time to display incoming messages. A signed access cookie contains the mailbox address and its creation and expiry times. Hosting and security systems may process IP addresses, request times, browser information, and error logs. No name, phone number, or payment details are required to create an inbox, but information included by a sender is still processed.
The functional xtmail_session cookie maintains mailbox access for up to 24 hours. It uses Secure, HttpOnly and SameSite=Strict. Tabs in the same browser share it. Clearing site cookies removes access; knowing the email address alone does not restore it. Essential session storage is separate from future advertising consent.
Access period and storage
Browser access expires 24 hours after creation. Closing the inbox or creating another address clears this browser’s previous access information; copies of a valid access token may remain usable until their expiry. This does not delete stored messages or sender copies immediately. In the current deployment, received-message records are stored in Supabase. No automatic 24-hour deletion job is configured for those records, so storage can outlast browser access. Provider logs and backups follow their actual settings and policies.
Providers and browser cookies
The current website uses Vercel for hosting, Cloudflare Email Routing and a Worker for incoming mail, and Supabase for message storage. Data may be processed outside your country. The essential xtmail_session cookie uses Secure, HttpOnly, and SameSite=Strict over HTTPS. Tabs and language pages in the same browser share it; other devices do not. Removing it loses inbox access. The service is not end-to-end encrypted.
Advertising and requests
Advertising scripts are currently disabled. Inbox contents and verification codes are not sent to Google for advertising. If advertising is introduced, this notice and applicable consent controls must be updated first. For access or deletion requests, use the private support channel listed on the contact page. Do not post sensitive information publicly. An email address alone does not prove past ownership or allow mailbox recovery.
Cloudflare · Supabase · Vercel