Privacy
This policy explains how Thirtel handles information for the temporary email product and companion tools. It is written in plain language. We will refine legal wording with counsel before a public AdSense-scale launch; the technical commitments below match how the product is built today.
What Thirtel is
Thirtel provides short-lived, receive-only inboxes and browser-local utilities (password generation, synthetic test identity fields). Temporary contact is the point — not a permanent mail account.
Inbox data and TTL
When you create an inbox, we store mailbox metadata and message content in Cloudflare Workers KV with an expiration TTL (default 30 minutes). When the TTL elapses, those keys expire. We do not operate a traditional long-lived database of inboxes for ordinary product use.
While an inbox is alive, message content must exist on our infrastructure so we can show it to you. Treat the address as sensitive for that window: anyone who knows it may be able to read mail until expiry.
Receive-only scope
v1 does not send outbound mail from temporary addresses. That reduces abuse surface and keeps the product honest.
Companion tools
Password and test-identity generators run in your browser. Their outputs are not uploaded to Thirtel as part of generation. We encourage storing important credentials in a password manager you trust.
Operational logs and security
We may process standard operational data needed to run and secure the service — for example request metadata, rate-limit counters, error logs, and platform analytics provided by Cloudflare. We use this to keep the service available and to limit abuse, not to build advertising profiles from your message bodies.
Inbox creation is protected with Cloudflare Turnstile (a bot check). Turnstile runs in your browser and is verified on our Worker before a mailbox is issued. We do not use it to build advertising profiles from message bodies.
Cookies and third parties
The core inbox experience does not require an account cookie. Cloudflare Turnstile may set challenge-related storage as part of the bot check. If we add analytics or advertising later, we will update this page and provide required notices/consents for your region.
What you should not send
Do not send highly sensitive personal data (government IDs, health records, financial secrets) to a temporary inbox you do not control long-term. Prefer durable addresses for anything you must recover later. See when not to use temp email.
Children
Thirtel is not directed at children under 13 (or the equivalent minimum age in your region).
Changes and contact
We may update this page as the product evolves. Material changes will be reflected here with an updated date. Questions: Contact.
Last updated: 2026-07-26