Privacy policy
Last updated
This policy explains what YelMail collects, why, how long we keep it and the choices you have. It covers the website at yelmail.com, the YelMail browser extension, the YelMail apps for iOS and Android, and the YelMail developer API (together, the "Service").
The short version
- You can use a free inbox without an account. We do not ask for your name or email address.
- Emails sent to your temporary address are deleted automatically when they expire: after 2 hours on Free and after up to 30 days on Premium.
- Only the browser or device that created an inbox holds its key. There is no public mailbox anyone can browse.
- We do not sell your personal data, and we never use the content of your emails for advertising, profiling or training AI models.
- Remote images and tracking pixels inside emails are blocked until you choose to load them.
- Free web pages show ads from Google, which may use cookies. Premium removes all ads.
Who we are
YelMail ("we", "us", "our") operates the Service and is the controller of the personal data described in this policy. For any privacy question or request, email [email protected].
What we collect
When you use a temporary inbox without an account
- The inbox: the address, when it was created and when it expires, and a one-way hash of its access key. The key itself stays in your browser (in a cookie) or inside the app or extension. We store only the hash, so we cannot use it to open your inbox.
- Emails you receive: sender name and address, recipient address, subject, text and HTML body, attachments, message ID, size, and the time each email was received and read.
- IP address: recorded when an inbox is created, so we can enforce per-network limits and stop abuse.
When you create an account
- Account details: name, email address, password (stored only as a salted hash, never in plain text) and whether your email is verified.
- Sign in with Google: if you choose it, Google shares your name, email address, profile photo and Google account ID, plus the sign-in tokens it issues. We request only basic profile access. We never access your Gmail, contacts, Drive or any other Google data.
- Sessions: the IP address and browser or device type of each signed-in session, so you can stay signed in and we can spot suspicious sign-ins.
- What you save: inboxes and labels, verified forwarding addresses, and the names of your API keys and when they were last used. API keys are stored only as hashes.
When you buy Premium
- On the website, payments are handled by Stripe. Stripe collects your card details, billing name, country or address and email address. We never see or store your full card number. We receive a Stripe customer ID, your plan, subscription status, renewal date and whether a payment succeeded.
- In the mobile apps, purchases may be handled by Apple (App Store) or Google (Google Play). We receive the transaction and subscription status needed to unlock Premium, not your payment details.
When you contact us
Your email address, your message and anything you choose to include, such as screenshots.
Collected automatically
- Server logs: IP address, time, requested URL, response status and user agent. We use them for security, debugging and preventing abuse.
- Aggregate statistics: daily totals such as the number of inboxes created or emails received. These do not identify anyone.
- Cookies and similar technologies: see our Cookie policy.
Emails sent to you by others
Emails that arrive in your temporary inbox contain personal data about their senders. We process that data only to receive, store, display and (if you set it up) forward the email to you, and we delete it when the email expires.
All incoming mail is automatically scanned for spam and malware. Mail sent to an address that has no active inbox, or from a sender we have blocked for abuse, is discarded without being stored.
How we use your data
| Purpose | Data used | Legal basis (EEA and UK) |
|---|---|---|
| Provide inboxes, receive and display emails, sync your inboxes across devices | Inbox data, emails, account | Performance of our contract with you |
| Sign-in and account security | Account, sessions | Contract; legitimate interest in keeping accounts secure |
| Premium billing, tax and accounting | Billing data | Contract; legal obligation |
| Forward mail to your verified personal address | Forwarding address, emails | Contract |
| Prevent spam, fraud and abuse; enforce limits and our terms | IP address, logs, inbox metadata | Legitimate interest in keeping the Service safe and available |
| Service emails: verification, password reset, forwarding confirmation, important changes | Email address | Contract; legitimate interest |
| Show ads on free web pages and in free apps | Cookies, device identifiers, IP address (processed by Google) | Consent where required by law; otherwise legitimate interest in funding the free Service |
| Understand and improve the Service | Aggregate statistics | Legitimate interest |
| Comply with the law and respond to valid legal requests | As required | Legal obligation |
We do not send marketing emails unless you opt in.
Who can read your emails
- You, or anyone who holds your inbox key or can sign in to your account.
- Our automated systems, to filter spam and malware, display messages and forward them to you.
- Authorised staff, only when needed to investigate an abuse report, fix a problem you asked us to look at, or comply with the law.
Anyone who knows your temporary address can send email to it. Once an address expires it may be issued to someone else, who would then receive any new mail sent to it. Do not use temporary addresses for accounts you need to recover later.
Sharing
We do not sell your personal data. We share it only with:
- Infrastructure providers that host our servers, database and mail servers, under contracts that limit them to processing data on our instructions.
- Stripe, to process website payments. See Stripe's privacy policy.
- Apple and Google, to distribute our apps, process in-app purchases and deliver push notifications.
- Google, if you choose Sign in with Google, and to serve ads to Free users through Google AdSense and AdMob. See Google's privacy policy.
- The forwarding address you verify, which receives copies of the mail you choose to forward.
- Authorities, when we are legally required to, or when it is necessary to protect someone's safety or the security of the Service. We review every request and push back on requests that are overbroad. Because emails are deleted when they expire, there is often nothing left to disclose.
- A successor business, if YelMail is merged, acquired or sold. This policy will continue to apply to your data.
YelMail's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Advertising
Free pages on the website show ads served by Google AdSense. Google and its partners may use cookies and similar technologies to show ads, limit how often you see them, measure their performance and, if you allow it, personalise them based on your visits to this and other websites. Learn more in How Google uses information from sites that use its services, and manage ad personalisation at myadcenter.google.com.
Where the law requires consent (for example in the EEA, the UK and Switzerland), we ask for it before advertising cookies are used, and you can withdraw it at any time.
Ads never have access to the content of your emails. Premium removes all ads, and we do not load any advertising code for Premium users.
Browser extension
The YelMail extension lets you create a temporary address, copy it and read new mail without leaving the page you are on. It works with the same inboxes and account as the website.
Stored on your device. Your current inbox addresses and their access keys, your sign-in token if you sign in, and your extension settings are kept in the browser's extension storage. Removing the extension deletes them.
Sent to us. Requests to the YelMail API to create inboxes and fetch messages, authenticated with your inbox key or sign-in token. We handle these requests exactly as we handle requests from the website.
Permissions. The extension asks only for what it needs:
| Permission | Why |
|---|---|
| Storage | Save your inbox keys and settings on your device |
| Notifications | Tell you when new mail arrives. You can turn this off in the extension settings |
| Alarms | Check for new mail in the background at regular intervals |
| Clipboard (write) | Copy your temporary address when you click Copy |
| Context menu, active tab and scripting | Insert your temporary address into the form field you right-clicked, only when you choose that action |
| Access to yelmail.com | Talk to the YelMail API |
The store listing for your browser shows the exact permissions of the current version. If we ever need a new permission, we will update this section before releasing it.
What the extension never does. It does not read or collect your browsing history, the content of the pages you visit, form data, keystrokes or other websites' cookies. It does not show ads and contains no third-party analytics or tracking code. We do not sell or transfer extension data to third parties, use it for advertising, or use it to determine creditworthiness.
YelMail's use of information received through the browser extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Mobile apps
The YelMail apps for iOS and Android use the same inboxes, account and API as the website.
- Stored on your device: your sign-in token and inbox keys, kept in secure system storage (the iOS Keychain or the Android Keystore), and a cache of recent messages so the app opens quickly. Cached messages are removed when they expire or when you sign out.
- Push notifications: if you allow notifications, we store a push token issued by Apple or Google and link it to your inboxes, so we can tell you when new mail arrives. Notifications show the sender and subject; you can hide previews in your device settings. Turning off notifications or signing out deletes the link.
- Purchases: in-app purchases are processed by Apple or Google as described above.
- Ads in the free app: the free version may show ads served by Google AdMob, which may use your device's advertising identifier. On iOS the identifier is used only if you allow tracking when asked. On Android you can reset or delete it in your device settings. Premium removes all ads.
- Crash reports: if the app crashes, we may collect the device model, operating system version, app version and a technical crash log so we can fix the problem. Crash reports never include your emails.
- Device permissions: the apps ask only for notification permission, and only if you turn notifications on. They do not access your contacts, location, camera, microphone or photo library. Saving an attachment uses the system share sheet or file picker, so the app sees only the file you choose.
You can delete your account inside the app (Settings → Delete account) or as described on our Delete your account page.
Developer API
When you use the API we process your API key (checked against its stored hash) and log each request's time, endpoint, response status, IP address and key ID, for rate limiting, security and troubleshooting. You are responsible for how you handle emails and data that you retrieve through the API.
How long we keep data
| Data | How long |
|---|---|
| Emails and attachments | Until they expire under your plan (2 hours on Free, up to 30 days on Premium), or sooner if you delete them. Expired items are purged within minutes |
| Guest inbox address, key hash and creation IP | Until the inbox expires |
| Account data, saved inboxes, forwarding addresses and API keys | Until you delete them or your account |
| Signed-in sessions (IP address, device) | Until you sign out, or 30 days after the session was last used |
| Subscription status | While your account exists. Stripe, Apple and Google keep payment records as required by tax and accounting law |
| Support conversations | Up to 24 months after the conversation ends |
| Server and security logs | Up to 30 days |
| Aggregate statistics | Indefinitely (they contain no personal data) |
We may keep specific data for longer if the law requires it, or while it is needed to investigate abuse or handle a legal claim.
Security
- All connections to the Service use HTTPS (TLS).
- Passwords are stored as salted hashes. Inbox keys, API keys and verification tokens are stored as one-way hashes.
- Email HTML is sanitised and shown in an isolated frame, so scripts and forms inside emails never run. Remote images are blocked until you load them.
- Forwarding addresses must be confirmed before we send any mail to them.
- Access to production systems is limited to the people who need it to run the Service.
No system is perfectly secure. If you believe you have found a vulnerability, please email [email protected]. If a breach affects your personal data, we will notify you and the authorities as the law requires.
Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy in a portable format;
- correct inaccurate data;
- delete your data;
- object to or restrict certain processing, including processing based on legitimate interests;
- withdraw consent at any time, where we rely on consent (for example for advertising cookies);
- complain to your local data protection authority.
You can do most of this yourself: change your name, email address or password under Account → Settings, remove forwarding addresses and API keys, delete inboxes, or delete your account. For anything else, email [email protected] from the email address on your account. We reply within 30 days. We will not treat you differently for exercising your rights.
A guest inbox is not linked to your identity, so the simplest way to remove it is to delete it from the inbox menu. It is also deleted automatically when it expires.
US state privacy rights
In the past 12 months we have collected the categories of personal information described in "What we collect": identifiers (such as email address, IP address and device identifiers), commercial information (subscription status), internet activity (server logs and ad interactions) and the content of the emails you receive. We use and disclose them only for the purposes described above.
We do not sell personal information for money. Advertising cookies on free pages may count as "sharing" for cross-context behavioural advertising under some US state laws. You can opt out by declining advertising cookies, by adjusting your settings at myadcenter.google.com, by upgrading to Premium, or by emailing [email protected]. We do not knowingly sell or share the personal information of anyone under 16.
We use your password (sensitive personal information) only to sign you in.
Children
The Service is not directed at children. You must be at least 13 years old to use it, or older if your country requires it (up to 16 in parts of the EEA). We do not knowingly collect personal data from children below that age. If you believe a child has given us personal data, email [email protected] and we will delete it.
International transfers
Our servers and service providers may be located in countries other than yours. When personal data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on safeguards such as the European Commission's Standard Contractual Clauses.
Changes to this policy
We update this policy when the Service or the law changes. The date at the top shows the latest version. If a change materially affects how we use your data, we will tell you in advance by email (if you have an account) or with a notice in the Service.
Contact
- Privacy questions and requests: [email protected]
- Everything else: see our Contact page