Addresses are valid for 3 hours by default and can be extended, but never beyond 24 hours in total; after expiry, they enter the cleanup process.
Privacy Notice · Updated September 7, 2026
Where your data goes, how long we keep it, is all laid out clearly.
This notice applies to the temporary inboxes, long-term forwarding aliases, passwordless login, and support services provided by fwdrelay.com. We process data only to the minimum extent needed to deliver the service, do not sell personal information, and do not build advertising profiles from message content.
Your receiving email address, aliases, and security settings are retained while your account exists and managed from the dashboard.
Forwarding activity records are retained for up to 30 days to review outcomes, retry delivery, and address abuse.
Send privacy inquiries, access requests, or deletion requests to support@fwdrelay.com.
1. Scope and roles
This notice covers data processing when you visit this site directly, create a temporary address, log in to the long-term workspace, or contact support. This notice does not govern how third-party websites obtain or use your information when they send email to an address on this site.
As the service operator, FwdRelay determines the processing needed to receive, forward, secure, and support the service. You decide which websites receive an address from this site and whether to use message content.
2. Data we process
Temporary features process email addresses, random access tokens, creation and expiry times, sender information, subjects, and message bodies. Long-term features also process your receiving email address, verification-code login records, alias status, delivery results, and authenticator status.
To prevent abuse and troubleshoot problems, servers may record request times, IP addresses, browser types, API results, and security events. We do not ask for government ID numbers or require a personal profile for a temporary inbox.
3. Specific purposes for using data
Data is primarily used to generate addresses, receive and display email, forward messages, maintain login sessions, show delivery records, and respond to support requests. Technical logs help limit automated abuse, protect infrastructure, and diagnose issues such as failed delivery.
We do not read messages to infer interests, nor do we sell receiving email addresses, aliases, or message bodies to data brokers. If we need to use data for a new, incompatible purpose, we will update this notice first and obtain consent where applicable.
4. Retention schedule
Retention periods are based on functional needs; “permanent storage” is not the default. Deletion from backups may require a limited rotation cycle, but backups are not reused for routine product functions.
| Data category | Typical period | After expiry |
|---|---|---|
| Temporary addresses and email | 3 hours by default; 24 hours maximum | Automatically cleaned up after expiry or destruction |
| Long-term forwarding records | Up to 30 days | Deleted on a rolling basis |
| Account and alias settings | While the account exists | Cleaned up after a valid deletion request |
| Security and rate-limit logs | Limited period needed for security investigations | Rotated or de-identified |
| Support correspondence | Until the issue is resolved and for a reasonable review period | Deleted or archived in minimized form |
5. Message bodies and attachments
Message content is processed only to display and forward it, detect spam, and retry delivery at your request. Temporary inboxes do not retain attachments, and messages over 100 MB are rejected; long-term aliases can forward and retain attachments up to 50 MB, while messages from 50 MB to 100 MB are forwarded without retaining attachments.
Long-term incoming messages over 100 MB are also rejected. Do not use an address on this site to exchange medical records, financial credentials, government identity documents, or other content whose disclosure could cause serious harm.
6. Security and access controls
Temporary inboxes are protected by unpredictable access tokens, so anyone holding the token may read the corresponding messages. The long-term workspace uses short-lived verification-code login and can enable TOTP-based authenticator codes.
We use encryption in transit, access restrictions, rate limiting, and activity auditing to reduce the risk of unauthorized access. However, no internet service can promise absolute security, so avoid using temporary addresses for account recovery or high-risk transactions.
8. Access, correction, and deletion
In the workspace, you can view aliases, pause delivery, delete entry points, and manage authenticator settings. Temporary inboxes can be replaced or destroyed directly; because they do not create identity-verified accounts, we may be unable to verify who requested access to a box after its token is lost.
For access, correction, export, or deletion requests related to a long-term identity, contact support from the verified receiving email address. After verifying your identity, we will respond within the time required by applicable law and explain specifically why we cannot fulfill any request.
9. Children
This site is intended for general internet users who can independently understand the risks of temporary addresses, not specifically for children. We do not knowingly collect children’s personal information where the law requires parental consent.
If a parent or guardian believes a child has provided personal data to this site, contact support with enough information to locate the records. After reasonable verification, we will delete the data or restrict its processing.
10. Processing locations and international transfers
To provide global network access, our infrastructure and service partners may be located outside your country or region. Data protection rules vary by location, but we still require processing activities to follow this notice’s purpose limitations and security obligations.
Where required by law, we use contractual clauses or other appropriate safeguards for international transfers. You can contact support to learn about processing locations and safeguards relevant to your request.
11. How this notice is updated
We may revise this notice when product capabilities, legal requirements, or infrastructure change. Material changes will update the date at the top of the page and, where reasonably practical, be explained through a prominent notice on the site.
Revisions will not automatically make previously collected data available for incompatible new purposes. Before continuing to use the service, review the changes and decide whether it remains suitable for your email needs.
12. Privacy questions and complaints
Send privacy requests to support@fwdrelay.com, and specify whether they concern temporary email or a long-term identity. Do not include verification codes, one-time passwords, complete message bodies, or other unnecessary sensitive information in your email.
We will confirm receipt of your request and explain the next verification steps. If you are dissatisfied with the outcome, you may also lodge a complaint with the data protection authority with jurisdiction under the laws where you live.