Legal
Privacy policy
Poofy is a receive-only temporary email service. We collect as little as we can to run it, we never sell data, and we don't use advertising or analytics trackers.
Last updated
Who we are
Poofy ("Poofy", "we", "us") operates the website and temporary email service at poofy.email and the email domains it provides. For privacy questions, write to [email protected].
The short version
- You don't create an account and we don't ask for your name, phone number or personal email address.
- Mail sent to your Poofy address is stored so you can read it. Message bodies are encrypted at rest.
- We keep your IP address and browser type for a short time to stop abuse and enforce rate limits.
- We use only essential cookies. No advertising, no cross-site tracking, no analytics trackers.
- Anyone who has an inbox's password (or a share link to it) can read that inbox, so keep them private.
What we collect
Mail you receive. When someone sends email to a Poofy address, we store the sender, subject, a short preview, the message body and, where present, attachments. We automatically detect verification codes and sign-in links so we can show them to you. Message bodies and stored files are encrypted with AES-256 before they are written to disk.
Inbox credentials. Each inbox gets a random password. We store only a one-way hash of it (Argon2id), so we cannot see or recover your password.
Browser session. When you use Poofy we set a session cookie that remembers which inboxes this browser has opened. Alongside it we record the IP address, the browser's user-agent string, and when the session was created and last used.
Security and abuse data. We record security-relevant events (for example inbox creation, failed logins, share-link creation) with a timestamp and IP address. We keep short-lived counters per IP address to limit how fast inboxes can be created or logins attempted.
Things you choose to create. Labels, alert rules and read-only share links you set up are stored with your inbox or browser session.
What we don't collect. We don't ask for your name, phone number, payment details or any identity documents. We don't run advertising or analytics scripts, and we don't buy data about you.
How we use it
- To deliver mail to your inbox and show it to you, including codes, links and alerts you set up.
- To keep the service secure: rate limiting, blocking abuse, detecting attacks, and investigating reports.
- To comply with the law and respond to valid legal requests.
We do not sell, rent or share your data for advertising, and we do not read your mail except where needed to investigate a specific abuse report or a legal obligation, or to fix a technical problem you asked us to look at.
Legal bases (EEA and UK visitors)
We process data because it is necessary to provide the service you asked for (performance of a contract), for our legitimate interests in keeping the service secure and free from abuse, and where required, to meet legal obligations.
Cookies and local storage
We use only what the service needs to work:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| poofy_sid | Cookie (essential) | Remembers which inboxes this browser has opened | Up to 30 days, renewed on use |
| Inbox keyring | Browser local storage | Keeps your inbox addresses and passwords on your device so you can reopen them | Until you clear it or press "Forget this browser" |
| Theme | Browser local storage | Remembers light or dark mode | Until you clear it |
Because these are strictly necessary, we don't show a cookie banner. Remote images inside emails are blocked by default, so senders can't track when you open a message unless you choose "Load images".
How long we keep data
- Messages stay until you delete them, the inbox's retention period ends, or the inbox runs out of space (the oldest messages may then be removed automatically).
- Browser sessions expire after 30 days of inactivity and are deleted about a week later.
- Rate-limit counters are deleted within two days.
- Security logs are kept as long as needed to protect the service and investigate abuse.
- Encrypted backups are kept for up to 14 days, after which deleted data is gone from backups too.
Who else processes data
We use a small number of infrastructure providers, bound by their own data protection terms:
- Cloudflare — content delivery, DDoS protection, DNS, and forwarding of mail sent to our contact addresses.
- Hetzner — server hosting in the European Union.
We don't use any other third parties to process your data. Email you receive naturally involves the sender's own mail systems before it reaches us.
Sharing and disclosure
We share data only when:
- you create a read-only share link (anyone with the link can read that inbox until you revoke it);
- the law requires it, for example a valid court order, and then only what is required;
- it is necessary to prevent serious harm, fraud or abuse of the service.
Security
Mail is encrypted at rest, inboxes are isolated from each other at the database level, email HTML is sanitized and shown in a sandbox, attachments are scanned and risky files are blocked, and all traffic uses HTTPS. No system is perfectly secure, so please don't use a temporary inbox for accounts that hold money, health data or anything you can't afford to lose.
Your choices and rights
- Delete any message, remove an inbox from your browser, or press Forget this browser to end your session on our side.
- Access, correction or deletion requests: email [email protected] with the inbox address and, where possible, proof you control it (for example the inbox password or a message it received). Because there are no accounts, we can't verify requests any other way.
- Depending on where you live (for example under the GDPR or the California Consumer Privacy Act), you may have rights to access, delete, correct, restrict or object to processing, and to complain to your data protection authority. We don't sell or "share" personal information as defined by the CCPA.
Children
Poofy is not intended for children under 16, and we don't knowingly collect data from them.
International transfers
Our servers are in the European Union. Our infrastructure providers may process data in other countries under appropriate safeguards such as the EU Standard Contractual Clauses.
Changes
If we change this policy we'll update the date at the top of this page. Significant changes will be highlighted on the site.
Contact
Privacy questions: [email protected]. Abuse reports: [email protected].