Last updated: August 25, 2026

Privacy isn’t a slogan;
every type of data has boundaries

This policy explains what data Hide processes when providing temporary inboxes and permanent forwarding, why it is processed, how long it is kept, and how you can exercise your rights.

1. Scope and roles

This policy applies to the disposable email, permanent forwarding, dashboard, and related support services provided by Hide on hidesend.com. Third-party senders, websites where you use a temporary address to register, and external email services have their own privacy practices, and we cannot make commitments on their behalf.

For data required to operate the service, Hide determines the purposes and essential methods of processing. When messages are delivered through other email networks, those networks may process transmission data as independent service providers under their own rules.

2. Temporary inbox data

When you create a temporary inbox, the system generates a random address, access token, creation time, and expiration time. The token is stored in your browser and sent with requests to the service to verify that you are authorized to read the inbox.

We process the sender, subject, content, time, and necessary delivery metadata of messages sent to the address so they can be displayed on the page. Temporary inboxes are not designed for permanent storage and should not contain medical, financial, identity-document, or other sensitive information that needs to be retained long term.

3. Forwarding accounts and aliases

When you use permanent forwarding, we process your destination email address, login verification status, aliases you create, alias status, and creation time. The destination address is used to deliver messages and complete passwordless login; it is not shown publicly to people sending mail to an alias.

If you enable two-step verification, we retain the encrypted or derived security data needed for verification and its enabled status. Time-based codes in your authenticator are used only for verification and are not stored as long-term content that employees can view.

4. Email content and attachments

To receive, filter, and forward messages, the system must process email headers, content, and attachments during transmission. The forwarding archive keeps available records from the past 30 days so you can check delivery status, identify spam, and retry failed deliveries.

Large attachments may be forwarded with the message without entering the web archive. This reduces unnecessary data retention and the risk of file abuse. Deleting a web record does not recall copies already delivered to your destination mailbox.

5. Technical logs and abuse prevention

We may record request times, network addresses, browser information, response statuses, rate-limit events, and unusual characteristics to maintain reliability and prevent automated abuse. Log access is limited to operational and security purposes, and logs are rotated or aggregated after the necessary period.

This information is not used to build advertising-interest profiles or sold to data brokers. If a security incident or dispute occurs, or the law requires it, relevant portions may be isolated and retained for as long as needed to resolve the matter.

6. Legal bases and choices

We provide the inbox, forwarding, and account functions you request on the basis of performing the service agreement. Preventing fraud, ensuring delivery, and maintaining security are based on our legitimate interest in providing a reliable service. When the law requires us to retain or disclose specific records, we process them within the required scope.

You can choose not to create a forwarding account and use only the temporary tool, which requires no registration. If you do not provide a destination email address, we cannot provide permanent forwarding or verification-code login, but you can still browse our public information pages.

7. Service providers and disclosures

To provide hosting, network transmission, email delivery, and security maintenance, we may use vetted infrastructure service providers. They may access data only on our instructions and as needed to provide the service, and must apply safeguards proportionate to the risks.

We do not sell personal information or provide email content to advertisers. If we receive valid legal process, need to protect users or public safety, or investigate abuse targeting the service, we disclose only information that is reasonably necessary.

8. Retention and deletion

Different data has different retention periods: temporary inboxes are measured in hours, forwarded email archives are typically kept for 30 days, and accounts and aliases are retained while the account exists. Backup, audit, or security-isolation copies may require an additional limited period before they can be rotated out.

You can delete aliases and individual archived messages in the dashboard, or request account deletion through our support email. Minimal records that must be retained to prevent repeated abuse or meet accounting or legal obligations will not disappear immediately after a standard deletion request.

9. Security measures and limitations

We use access controls, encryption in transit, short-lived tokens, rate limiting, and least-privilege access to protect the service. Permanent forwarding accounts can also enable time-based one-time codes to reduce the risk after an email verification code is exposed.

No internet or email system can promise absolute security, and other providers may control messages while they travel across external networks. Do not treat Hide as an encrypted vault, and save important information that you need to keep long term without delay.

10. Your rights

Where applicable law allows, you may request access, correction, deletion, restriction of processing, objection to certain processing, or a portable copy of your data. We verify the requester’s relationship to the account or destination email address to avoid disclosing data to an impersonator.

Some rights are subject to legal exceptions, the rights of others, and security requirements. If we cannot fully comply, we will explain the main reasons. You may also lodge a complaint with the data protection authority that has jurisdiction where you live.

11. Children and international processing

This service is intended for general internet users who can understand the privacy implications of using email, and is not directed at children. If a parent or guardian believes that a child has improperly submitted personal information, they can contact us so we can verify and address the matter.

Because email and internet infrastructure are global, data may be routed or processed outside your region. We manage cross-border risks using contracts, access restrictions, and other safeguards as required by applicable law.

12. Updates and contact

We may update this policy when our features, legal obligations, or security practices change, and will show the new date at the top of the page. We will make reasonable efforts to highlight significant changes on the site, but you should still review the current version regularly.

For privacy requests or questions, email support@hidesend.com and tell us whether your request concerns a temporary inbox or a forwarding account. Please do not send passwords, complete verification codes, or unnecessary sensitive identity documents by email.