Privacy Policy
This page says what emailfake.com does with information, in ordinary words. Using the site means accepting what is described here; if any of it does not suit you, the honest answer is not to use it.
Read this part even if you skip the rest
An inbox here has no password. Anyone who knows or guesses the address opens the same mailbox and reads the same messages. That is not a hole we failed to close; it is the entire reason the service can work without registration. Treat every inbox as a public surface. Nothing private, nothing financial, nothing you would mind a stranger reading.
If you point your own domain here
Connecting a domain of yours by MX record changes who the mail belongs to, not how it is stored. Mail sent to anything@your-domain.com arrives on our servers, is held for the same short period, and is readable by anyone who knows the address — including addresses at your domain that you never handed out, if someone guesses them. A private domain is protection against block-lists, not against being read. The setup itself is described in add a new domain.
What is stored
- Received messages — held so you can read them, then deleted automatically after a short retention window. There is no backup and no archive.
- Operational records — IP address, browser User-Agent, request time. Used for rate-limiting, blocking abuse and finding faults; not for building a picture of anyone.
- Things that never leave your browser — the list of inboxes you have opened is kept in your own browser's storage. We do not receive it. Clearing browser data erases it.
What is not done
- No registration, so there is no account profile to leak.
- No selling or renting of data.
- No linking of inboxes to a person: there is no identity collected to link them to.
- No marketing mail. We have no address of yours to write to.
Cookies this site actually sets
The names below are the real ones, and they are ours. Google sets its own on top of them; those are listed in the next section.
chanstate— which mailbox you are currently reading, so a page reload does not lose it.sitelang— the interface language you chose.gdpr-ok— your answer to the cookie question, so it is asked once rather than every visit.gdpr-barhides the reminder strip if you declined.notifwin,notifsnd,winlimit,sndlimit,winmute— notification settings from the settings panel: pop-ups, sound, how often, silent mode.subdoms— whether second-level domains are offered in the domain list.noconfirm— you asked not to be asked again before deleting.
Blocking them costs you those conveniences and nothing else. Mail still arrives.
Cookies set by Google, not by us
Two Google services run on this site, and each stores its own cookies in your browser once you have agreed to them. We can switch the services on or off; we cannot rename their cookies, read them, or promise what they will be called next year. After you agree, expect to see:
_gaand names beginning_ga_— Google Analytics. They hold a random number that lets one visit be told apart from another. Nothing in them identifies you by name.__gads,__eoi,__gpiand similar — Google's advertising side, present only while ads are being shown. They exist to limit how often an ad repeats and to detect fake clicks.
Decline, and none of the above is written at all: analytics falls back to a mode that stores nothing on your machine, and ads are non-personalised. The site works exactly the same either way, and you can change your mind later from the same banner. You can also go over our head: Google's ad settings apply everywhere you browse, and the Analytics opt-out add-on switches Analytics off across every site that uses it.
Analytics
Google Analytics 4 counts visits in aggregate: how many people come, which pages help, where the site is slow. It runs under consent mode: until you agree, it behaves in a cookieless, non-identifying way. Email addresses and message contents are never sent to it.
Advertising
The service may carry advertising to stay free. Where ads are shown, whether they are personalised follows your consent choice; without consent, non-personalised ads are served. Google's side of that is described in its advertising privacy policy. Ads never appear inside the body of a received message, and no advertiser is given the address of an inbox or anything sent to it.
How long anything is kept
Messages are erased automatically after their retention window, and you can clear an inbox yourself at any time. Operational records are short-lived. Since nothing is attached to an identity, expiry is the normal outcome rather than something you have to request.
Security, and what it does not cover
Traffic is encrypted in transit and stored mail is not openly browsable. That protects the pipe. It cannot protect an inbox whose address someone else can type; see the first section. For correspondence that genuinely matters, use a real mailbox with a password on it.
Abuse
The operational records above exist so that fraud, harassment and attempts to trawl other people's inboxes can be stopped. Rules are in the acceptable use policy. Lawful requests are answered where we are required to answer them.
Children
The service is not meant for children under 13, and nothing here is knowingly collected from them. Since no identifiers are collected at all, no one can be targeted by age either.
Where processing happens
The site is reachable worldwide and the limited technical data above may be processed on servers in another country. Using the service accepts that.
Changes
This page is revised as the service changes. Continuing to use the site after a change means accepting the current version.
Contact
Privacy questions go through the Feedback link in the footer of every page.