Privacy Policy

What PHMail is

PHMail provides short-lived, receive-only email inboxes. The service is designed around data minimization: temporary data is stored only for as long as the inbox exists.

What we store

What we don't collect

PHMail itself does not require an account to use the free service, and does not collect names, browser fingerprints, or your raw IP address. We never sell personal data, and we never read your messages for advertising or profiling.

Analytics and advertising

PHMail uses two Google services, and both set their own cookies in your browser:

These are third-party services governed by Google's own terms, not ours. You can review how Google uses this data at policies.google.com/technologies/partner-sites, and opt out of personalised advertising at adssettings.google.com.

Ads are shown on the free tier only. Paid plans are ad-free.

Retention and deletion

Messages are retained for the plan retention window (7 days free, 14 days Plus, 30 days Developer) and then permanently deleted by a scheduled cleanup, together with any associated files; empty unused addresses are pruned as well. Server hosting infrastructure may keep standard, short-lived technical logs.

Accounts and subscriptions

If you create an optional PHMail account, we store your email address, a securely hashed password (via PHP password_hash), and subscription/plan records. Password-reset tokens are stored only as hashes, expire, and are single-use. We never store plaintext passwords or raw API keys.

Private inboxes and the Developer API

Messages received by a private (Plus) inbox or a Developer API inbox are bound to your account and accessible only to you. Developer API usage is aggregated into daily counters (requests, inboxes created, messages retrieved) for quota enforcement — we do not log every individual request or fingerprint users. OTP/verification-code detection happens locally on our server; message content is never sent to external AI services for extraction.

Payments

Paid plans are currently paid by GCash transfer directly to us. We do not use a card processor and we never see or store card details.

When you tell us you have paid, we store what you submit so we can match it to your transfer: the plan and duration chosen, the amount, the GCash reference number, the sender name you enter, any note you add, and the date. This is kept as a record of the transaction and is visible only to PHMail administrators. We also keep your subscription status and its start and end dates.

Your GCash account itself is not connected to PHMail, and we receive nothing from GCash about you beyond what appears on the transfer you send.

Important limitations

PHMail inboxes are public: anyone who knows (or guesses) an address can read its messages. Email is also transported over standard mail infrastructure operated by third parties. PHMail therefore offers no confidentiality at all — never use it to receive sensitive, personal, financial, or confidential information, or for accounts you care about.

Contact

Questions about this policy: contact@phmail.space.