🤖 Robots start here mailhles
Sign in Get started

Privacy Policy

Last updated July 2026 · operated by mailholes, a sole proprietorship in Washington, USA

This policy explains what we process, why, and your choices. We do not sell personal information.

What we process

  • Account & billing: your email, subscription status, and a payment-provider customer id.
  • API keys: stored only as a one-way hash.
  • Addresses: the disposable addresses you create.
  • Inbound email: sender, recipient, subject, body, and headers of mail sent to your addresses, including the raw original message as received.
  • Transactional email we send you: account emails such as email verification, password resets, and account notices, sent to the address on your account.
  • Operational logs: IP address, timestamps, and request metadata for security and reliability.

Retention

Inbound email is automatically deleted on a short schedule (currently about one hour after receipt). Account, address, and billing records persist while your account is active and for a reasonable period afterward as required for legal, tax, and security purposes. Logs are kept for a limited period.

Payments & subprocessors

Payments are handled by Lemon Squeezy (merchant of record); we do not store full card details. We also rely on Cloudflare for hosting, inbound email routing, and database; Brevo to send our transactional account emails (verification, password resets, and notices); and GitHub where sponsorships are used. These providers process data under their own terms.

Email content & third parties

Mail sent to your disposable addresses may contain personal data about third parties. We process it transiently on your behalf to deliver the Service and delete it on the retention schedule above. You are responsible for handling any data you retrieve lawfully.

Your rights

Depending on where you live (e.g. GDPR in the EEA/UK, CCPA/CPRA in California, and Washington state law), you may have rights to access, correct, delete, or port your data, and to object to or restrict certain processing. Contact privacy@mailholes.com. You can also delete your addresses and account at any time; inbound mail self-expires.

Security

API keys are stored hashed, data is isolated per account, and access is gated by per-key authentication. No system is perfectly secure; see the limitation of liability in our Terms.

Children & international transfers

The Service is intended for adults: our Terms require you to be at least 18. It is not directed to children, and we do not knowingly collect data from anyone under 18 (or under the minimum age of digital consent where you live). We operate on globally distributed infrastructure; data may be processed in the United States and other countries.

Changes

We may update this policy; material changes will be posted here with a new date.

Questions about this page? legal@mailholes.com

© mailholes · for agents · Terms · Privacy · Acceptable Use · report abuse