Privacy Policy
Last updated 3 August 2026
TMailr keeps as little about you as the service can run on. This policy says exactly what that is, why we hold it, how long, and what you can do about it. No hedging.
Who we are
TMailr is a service of Bolrach Technologies Limited, which is the data controller for the personal data described here. This policy covers tmailr.com and the mail handled through our receiving domains. For anything in it, the privacy contact is dpo@tmailr.com.
What we collect
For each message that arrives we keep the original file, the sender and recipient, the subject, the time it arrived, the authentication results our server calculated, and the sending server's IP address. We keep a hashed form of the IP address that created an inbox, so we can stop abuse without holding your address in the clear.
An account is optional and nothing on the site needs one. If you sign in, AUTHVIO handles the credential and hands us an identifier that means nothing anywhere else. We store that identifier, the date you first appeared and the date we last saw you, and a link from your account to anything you chose to keep. We do not receive or store your email address, your name, or a password. An API key is stored as a hash and its first eleven characters; the secret is shown once and we cannot recover it.
If you buy credits or a plan, we keep a record of the purchase. Card details are entered on the payment provider's own page and never reach us.
Why we use it, and our legal basis
Under the GDPR every use of your data has a lawful basis. Here they are, in full:
| Purpose | Data | Legal basis |
|---|---|---|
| Deliver the inbox, alias or test you asked for | The message and its metadata; the address you gave | Performance of a contract, Art. 6(1)(b) |
| Keep the service safe and stop abuse | Hashed creator IP, rate-limit counters | Legitimate interests, Art. 6(1)(f) |
| Sign you in and hold your account | The pairwise AUTHVIO identifier, first- and last-seen dates | Performance of a contract, Art. 6(1)(b) |
| Take payment for credits or a plan | Purchase records (no card data) | Contract, Art. 6(1)(b); records, Art. 6(1)(c) |
How long we keep it
A guest inbox lasts one hour by default and can be extended up to twenty-four hours. When it expires or you delete it, we remove the stored message files and the database records. Deletion is permanent, not a flag. An account keeps its identifier until you close it; purchase records are kept only as long as the law requires us to hold them.
Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable form, and to withdraw any consent you gave.
Most of this is self-service and instant: delete an inbox, alias, domain or report from its own page, or close your account from the dashboard, which removes the identifier and every link to what you kept and revokes every API key. For anything a page cannot do for you, write to dpo@tmailr.com and we will answer within the time the law allows. If you think we have handled your data wrongly, you also have the right to complain to your data protection supervisory authority.
Where your data is handled
Your data is processed on infrastructure Bolrach Technologies Limited operates. Where a processor we rely on sits outside your region, that transfer is covered by Standard Contractual Clauses (and the UK Addendum where the UK GDPR applies), so the protection travels with the data.
Security
We encrypt what we store and require modern transport security where the sender supports it. An inbox is reached only by a 256-bit secret link, of which we hold only a hash; the address alone opens nothing and there is no way to enumerate what exists. Incoming HTML is sanitized on the server and shown in a locked-down frame that cannot run code. The full picture is on the security page.
Children
TMailr is not directed at children and we do not knowingly collect data from anyone under the age at which they can consent for themselves under local law. If you believe a child has used the service, tell us at dpo@tmailr.com and we will remove what we hold.
What we never do
- We never open links or load tracking images unless you press the button that asks for them.
- We never let anyone read an inbox from the address alone. Only the secret link opens it.
- We never sell message content, mine it for advertising, or use it to train anything.
- We never send mail from a guest inbox, so your address cannot be used to reach anyone.
A limit worth stating
Mail arrives over the public internet. We encrypt what we store, but a message is not end-to-end encrypted just because we hold it safely. Do not use a disposable inbox for anything genuinely sensitive.
Contact
Privacy questions go to the data protection contact for Bolrach Technologies Limited at dpo@tmailr.com. Formal legal notices go to legal@tmailr.com. The cookies we use are listed in full on the cookie policy.