Privacy Policy

Last updated: August 21, 2026

mailpigeon is run by a private individual as a non-commercial student project, and acts as the data controller for the processing described below. This policy describes what data mailpigeon actually collects and why.

Message content

Any message sent to a mailpigeon address (sender, subject, body, timestamps) are stored so they can be shown to whoever checks that address. This is the core function of the service. Messages are deleted automatically 48 hours after they arrive, except under a permanently claimed address, which doesn't expire on its own.

Senders haven't agreed to this

Whoever sends mail to a mailpigeon address is also, technically, a data subject and hasn't consented to or been informed about any of this, since they're a third party to the person who gave out the address. This is an inherent, unresolved tension in how any disposable-inbox service works, not something mailpigeon has solved. The 48-hour auto-deletion (and immediate deletion on request, or upon release of a reserved address) is the main mitigation in place.

Account data

Creating an account stores a username, a hashed password (never the password itself), an account role, and a creation timestamp. No email address is collected for account creation as signup is username-based. A single-use invitation code and who redeemed it is also recorded, to keep signup invite-only.

Login sessions

Logging in issues a short-lived access token and a longer-lived refresh token; refresh tokens are stored hashed, not in plain text, and can be individually revoked (e.g. by logging out).

IP addresses

Requests are rate-limited per IP address to prevent abuse (e.g. address-guessing, bulk account creation). This happens transiently, within each rate-limit window, and isn't stored in any log or report you could request a copy of.

Recipients and third parties

Inbound mail is routed through Cloudflare (Email Routing) before it reaches mailpigeon's own server. Cloudflare processes message content in transit as part of that delivery. The server itself, including its database, is hosted with netcup, a German provider. Data isn't sold, and isn't shared with anyone else beyond what's needed to run the service.

Data retention

Message content: 48 hours, or until deleted by whoever's checking that address, whichever is sooner (permanently claimed addresses are the one exception). Account data: kept until the account is deleted. There's no self-service account deletion yet. Account deletion can be done by requesting it via the contact address below in the meantime.

Changes to this policy

This policy may change as mailpigeon does. Continuing to use the service after a change means you accept the updated policy.

Contact

Contact contact@mailpigeon.io for questions about this policy or a request regarding your data.