Temporary inboxes
Accessed with a random token and available for up to 24 hours; after expiry, recovery is not guaranteed.
Privacy Policy · Updated September 2026
This policy explains what information Msgforward processes when you use disposable email, dedicated forwarding addresses, and support channels. We set retention limits by function, never sell personal information, and do not build advertising profiles from email content.
Accessed with a random token and available for up to 24 hours; after expiry, recovery is not guaranteed.
Your receiving email is used for verification-code login and as the delivery target; account actions require a valid token.
Forwarding records help verify delivery and are generally retained for 30 days before deletion begins.
You can delete individual records or dedicated addresses, or contact us about an account privacy request.
| Data category | Purpose | Typical retention limit |
|---|---|---|
| Temporary addresses, tokens, and emails | Create and restore a short-lived inbox in your current browser | Three hours by default; extendable up to 24 hours |
| Receiving email and account settings | Verification-code login, forwarding targets, and security settings | While the account exists, or until deleted on request |
| Forwarded emails and delivery status | Display records, download attachments, retry delivery, and classify spam | Typically 30 days |
| Security and access logs | Prevent abuse, troubleshoot issues, and secure the service | Retained for a limited period as needed for security |
| Support communications | Respond to requests and retain a record of how they were handled | As long as needed to resolve the request |
This policy applies to the web-based temporary inboxes, forwarding-address management, mail records, and support communications provided by msgforward.com. Emails sent to you by third-party websites, and their own data practices, are governed by those parties’ policies.
When an email contains external links or remote resources, accessing them may send information to third parties. We display genuine HTML emails in a restricted viewer, but you should still check the destination before clicking.
The temporary inbox feature processes generated addresses, access tokens, arrival times, sender details, subjects, message bodies, and attachments. The forwarding feature also processes your receiving email, dedicated addresses, statuses, creation times, and delivery results.
Your browser may store the current temporary inbox credentials and login email so you can continue the current process after refreshing. The server generates necessary access and error logs for security, rate limiting, and troubleshooting.
We use this information to receive, display, and forward emails, verify codes, maintain address status, and provide retry, deletion, and security settings. Processing also helps prevent automated abuse, malicious attachments, spam delivery, and attacks on our infrastructure.
We do not read message bodies for targeted advertising or sell receiving email addresses or message content. If analytics are used, they are aggregated so they do not directly identify specific emails or accounts.
Temporary addresses are controlled by random credentials and do not require account login. Anyone with a valid token may be able to access the corresponding inbox, so you should not share tokens or use a temporary address for sensitive, long-term accounts.
After an address expires, is replaced, or browser storage is cleared, the old entry may not be recoverable. Because the service is short-lived, it should not be treated as a backup, archive, or long-term identity.
Forwarding accounts use your receiving email as the login identity and delivery target. Emails sent to a dedicated address are processed to complete forwarding, with their status, body, and attachments shown in the records area.
Records are generally retained for 30 days so you can verify delivery, handle failures, and assess false positives. Manual deletion may remove them from the interface immediately; underlying copies are cleared through backup and security procedures.
We process information to provide the services you request, pursue our legitimate interests in keeping the service secure, and, where applicable, based on your consent. Where the law requires specific records to be retained, processing may also be based on a legal obligation.
You can stop using a temporary inbox, delete a dedicated address, or ask us to process your account to end processing that is no longer necessary. Some security records may still be retained briefly after a deletion request where legally permitted.
Hosting, network, security, and email-delivery providers may process data as needed to provide their infrastructure. We require them to process data only on our instructions and to apply appropriate security and confidentiality measures.
We do not authorize service providers to use email content for their own advertising activities. If our business is reorganized, transferred data will remain subject to this policy or equivalent protections.
Internet infrastructure may transmit or store information outside your region. When data is processed across borders, we use contracts or other safeguards recognized by applicable law.
Data-protection rules differ between regions. You can contact support to ask where processing related to your request takes place and which safeguards apply.
We use access tokens, email verification codes, optional authenticator codes, encryption in transit, and access controls to reduce the risk of unauthorized access. HTML emails are displayed in a restricted environment, and downloading attachments requires the relevant credentials.
No system can guarantee absolute security. Do not use temporary email to receive financial, medical, government, or other highly sensitive information, and report suspected security issues promptly.
Depending on the laws where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your personal information, and to request a portable copy. We may need to verify your receiving email or other reasonable information to avoid giving data to the wrong person.
Some requests can be completed directly in the interface, such as deleting emails, deleting dedicated addresses, or signing out. Requests that cannot be completed self-service can be sent to support@msgforward.com.
This service is not intended for children who cannot legally consent to data processing, and we do not knowingly collect their personal information. If a guardian believes a child has provided information to us, they can contact us to request verification and deletion.
We may restrict access used for harassment, fraud, bypassing security controls, or other unlawful purposes. Minimal evidence retained to investigate serious abuse is handled as required by law and security needs.
We may update this policy when our features, legal requirements, or infrastructure change, and will mark the update date at the top of the page. We will provide reasonable notice of material changes, but you should also review the current version regularly.
Send privacy requests or questions to support@msgforward.com. Do not include passwords, full verification codes, or unnecessary sensitive message content in your first support email.