Privacy Policy
Site-owner note: this is placeholder legal language. Have it reviewed and adapted to your jurisdiction before production use. Last updated: [DATE].
What PHMail is
PHMail provides short-lived, receive-only email inboxes. The service is designed around data minimization: temporary data is stored only for as long as the inbox exists.
What we store
- Temporary inbox records — the generated address, a cryptographic hash of your access token, and creation/expiry timestamps.
- Incoming messages — sender, subject, and message content, stored only while the inbox is active.
- Abuse-protection identifiers — a keyed cryptographic hash derived from your IP address, used solely for rate limiting. We do not store your raw IP address in the application database.
- Local browser storage — your inbox access token and theme preference are kept in your own browser's localStorage, not on our servers.
What we don't collect
No accounts, names, passwords, browser fingerprints, advertising identifiers, or third-party analytics.
Retention and deletion
Inboxes expire after their lifetime (60 minutes by default, extendable within limits). A scheduled cleanup process permanently deletes expired inboxes, their messages, and any associated files. Server hosting infrastructure may keep standard, short-lived technical logs.
Important limitations
Email is transported over standard mail infrastructure operated by third parties. PHMail cannot guarantee confidentiality of email in transit and does not claim to make you anonymous or untraceable. Do not use temporary addresses for accounts you care about.
Contact
Questions about this policy: [CONTACT EMAIL].