Privacy Policy
Last updated: September 11, 2026
What we collect
EmptyInbox.me collects only what is necessary to operate the service:
- Account data: A username and a derived user identifier. Accounts created in a browser also store a passkey credential. Accounts created through the API have no passkey. No email address or password is stored in either case.
- Inbox and message data: Emails delivered to your disposable inboxes are stored temporarily and automatically deleted after 7 days.
- Usage data: Inbox quota usage and API key activity for billing and abuse prevention, including a count of the times an account reached its quota limit.
- Network address: The IP address a registration came from, and the name of the client software that sent it, where one identifies itself. We record this for every attempt to create an account, including attempts we turn away. It is how we tell a developer or a build server apart from someone creating accounts in bulk, and it is the only way we can do so without asking you for an email address or putting a CAPTCHA in front of the service.
- Payment data: Cryptocurrency transaction hashes and payment addresses processed via Blockonomics. No credit card or personal financial data is stored by us.
How we use it
- To deliver and display email messages to authenticated users.
- To enforce quota limits and prevent abuse.
- To decide how much free quota a new account receives. Accounts created in bulk from one network receive less, or none.
- To process payments and credit inbox quota.
Data retention
Inbox messages are deleted automatically after 7 days. You can delete individual inboxes at any time. Deleting all inboxes does not delete your account; contact us via GitHub to request full account deletion.
The record of account registrations, including the network address each came from, is deleted automatically after 90 days. The address a surviving account was registered from is kept for as long as the account exists, and goes when the account does.
Why we are allowed to hold this
For anyone in the UK or EU: we rely on legitimate interests, specifically keeping a free service from being consumed in bulk by automated signups. We have kept the amount to a minimum deliberately. There is no email address, no name, no payment identity and no tracking across sites, because the service is designed not to need them. If you object to us holding a network address against your account, ask us to delete the account and it goes with it.
Third parties
- Blockonomics — payment processing. Subject to Blockonomics Privacy Policy.
We do not sell or share your data with third parties for advertising purposes.
Cookies and storage
Signing in sets one cookie, session_token, which identifies your browser session to the server. It is marked HttpOnly, so scripts on the page cannot read it. We also use localStorage to keep your login state between visits.
Both exist only to keep you signed in, which is why the site asks no cookie consent: neither is used to track you, build a profile, or measure anything. We run no analytics, no advertising and no third-party scripts. Fonts are self-hosted, so loading a page contacts nobody but us.
Contact
Questions or deletion requests: open an issue on GitHub.