Updated September 7, 2026

Operator: lee davin

contact@haruemail.com

Data processed

We process the generated recipient address, sender, subject, readable body, and received time to display incoming messages. A signed access cookie contains the mailbox address and its creation and expiry times. Hosting and security systems may process IP addresses, request times, browser information, and error logs. No name, phone number, or payment details are required to create an inbox, but information included by a sender is still processed.

The functional xtmail_session cookie maintains mailbox access for up to 24 hours. It uses Secure, HttpOnly and SameSite=Strict. Tabs in the same browser share it. Clearing site cookies removes access; knowing the email address alone does not restore it. Essential session storage is separate from future advertising consent.

Access period and storage

Browser access expires 24 hours after creation. Closing the inbox or creating another address clears this browser’s previous access information; copies of a valid access token may remain usable until their expiry. This does not delete stored messages or sender copies immediately. In the current deployment, received-message records are stored in Supabase. No automatic 24-hour deletion job is configured for those records, so storage can outlast browser access. Provider logs and backups follow their actual settings and policies.

Providers and browser cookies

The current website uses Vercel for hosting, Cloudflare Email Routing and a Worker for incoming mail, and Supabase for message storage. Data may be processed outside your country. The essential xtmail_session cookie uses Secure, HttpOnly, and SameSite=Strict over HTTPS. Tabs and language pages in the same browser share it; other devices do not. Removing it loses inbox access. The service is not end-to-end encrypted.

Advertising and requests

Advertising scripts are currently disabled. Inbox contents and verification codes are not sent to Google for advertising. If advertising is introduced, this notice and applicable consent controls must be updated first. For access or deletion requests, use the private support channel listed on the contact page. Do not post sensitive information publicly. An email address alone does not prove past ownership or allow mailbox recovery.

Cloudflare · Supabase · Vercel

Privacy · Contact