Privacy Policy
Draft — last reflects the app as of July 2026.
This is a draft, written to accurately describe what the software actually does. It has not been reviewed by a lawyer and is not a binding legal document. Don’t rely on it as legal compliance for a real deployment — get real counsel for that.
What we store
An anonymous inbox stores only the generated address and whatever emails arrive at it, tied to a random access token — no account, no name, no personal details. A registered account stores a username, email address, and a hashed password (or, if you sign in with Google/GitHub, no password at all — we never see or store it). Signing in with Google or GitHub shares your email address and account ID with BlinkMail, nothing else from those providers.
What we don’t do
No ads, no ad trackers, no selling or sharing data with marketing or analytics third parties. Emails delivered to your inbox are stored so you can read them and so the OTP/link detection can run — they aren’t read by anyone else.
Retention
Anonymous inboxes expire automatically after a fixed period. Persistent (registered-account) inboxes are kept until you delete them or your account. The exact retention window for anonymous inboxes is still being finalized — currently a placeholder value in the backend, not a committed number.
Your options
Don’t want any of this stored longer than a browser session? Stick to anonymous inboxes — nothing about them requires an account, and they’re gone once they expire.