Privacy Policy
This policy explains what we process, why, and your choices. We do not sell personal information.
What we process
- Account & billing: your email, subscription status, and a payment-provider customer id.
- API keys: stored only as a one-way hash.
- Addresses: the disposable addresses you create.
- Inbound email: sender, recipient, subject, body, and headers of mail sent to your addresses, including the raw original message as received.
- Transactional email we send you: account emails such as email verification, password resets, and account notices, sent to the address on your account.
- Operational logs: IP address, timestamps, and request metadata for security and reliability.
Retention
Inbound email is automatically deleted on a short schedule (currently about one hour after receipt). Account, address, and billing records persist while your account is active and for a reasonable period afterward as required for legal, tax, and security purposes. Logs are kept for a limited period.
Payments & subprocessors
Payments are handled by Lemon Squeezy (merchant of record); we do not store full card details. We also rely on Cloudflare for hosting, inbound email routing, and database; Brevo to send our transactional account emails (verification, password resets, and notices); and GitHub where sponsorships are used. These providers process data under their own terms.
Email content & third parties
Mail sent to your disposable addresses may contain personal data about third parties. We process it transiently on your behalf to deliver the Service and delete it on the retention schedule above. You are responsible for handling any data you retrieve lawfully.
Your rights
Depending on where you live (e.g. GDPR in the EEA/UK, CCPA/CPRA in California, and Washington state law), you may have rights to access, correct, delete, or port your data, and to object to or restrict certain processing. Contact privacy@mailholes.com. You can also delete your addresses and account at any time; inbound mail self-expires.
Security
API keys are stored hashed, data is isolated per account, and access is gated by per-key authentication. No system is perfectly secure; see the limitation of liability in our Terms.
Children & international transfers
The Service is intended for adults: our Terms require you to be at least 18. It is not directed to children, and we do not knowingly collect data from anyone under 18 (or under the minimum age of digital consent where you live). We operate on globally distributed infrastructure; data may be processed in the United States and other countries.
Changes
We may update this policy; material changes will be posted here with a new date.