Legal

Privacy Policy

Last updated: 20 July 2026

This is a good-faith summary written in plain language — not legal advice. Please have your own counsel review it before relying on it.

The short version

  • MailMatter is a disposable-mail tool for development and testing.
  • Email sent to your inboxes is held only until a short retention timer purges it — then it's gone.
  • We don't sell your data and we run no advertising trackers. Analytics is cookieless and aggregate.
  • Don't send real personal data, credentials, or production secrets to a disposable inbox — anyone who knows the address can send to it.

1. Who we are

MailMatter (“MailMatter”, “we”, “us”) is a disposable-email service for software development and testing, operated as a sole proprietorship based in Taiwan. This policy explains what personal data we handle and the choices you have. You can reach us any time at team@mailmatter.dev.

2. What we collect

  • Received email content. The messages sent to your inboxes — including full headers, bodies, attachments, and sender addresses. Receiving and displaying this is the core function of the service. It is held transiently and purged automatically (see retention).
  • Account data (only if you sign in). When you authenticate with Google or GitHub we receive a basic profile: your email address, display name, avatar URL, and the provider's user ID. We never receive your Google or GitHub password.
  • Namespaces and handles you create, and their settings.
  • API keys you generate. Keys are stored hashed; the plaintext is shown once, at creation, and never again.
  • Billing data. Payments are handled by Paddle, our Merchant of Record. We store the Paddle customer and subscription identifiers and your plan state. We never see or store your card number or full payment details.
  • Limited technical data. Standard server and security logs (e.g. IP address and request metadata) generated when you use the service, kept briefly for operation, abuse-prevention, and debugging.

3. How we use it

We use the data above only to run the service: to receive and show your mail, authenticate you, enforce plan quotas, process payments through Paddle, keep the platform secure, debug problems, and comply with the law. We do not sell your personal data, and we do not use it to build advertising profiles.

4. How long we keep it

Email is ephemeral by design. Anonymous inboxes expire on an idle timer. For signed-in accounts, retention depends on your plan:

  • Free — 72 hours
  • Pro — 30 days
  • Team — 90 days

After the window, messages are purged automatically. Account and billing records are kept while your account is active and for as long afterward as the law requires.

5. Who we share with

We don't sell data or share it with advertisers. We rely on a small set of service providers (“sub-processors”) to run MailMatter:

  • Cloudflare — hosting, storage, and network (compute, database, object storage, cache, and queues).
  • Google and GitHub — optional sign-in (OAuth).
  • Paddle — payment processing as Merchant of Record.

We may also disclose data if required by law or to protect the rights, safety, and security of our users and the service.

6. Cookies & analytics

We use only first-party, functional cookies — no advertising or cross-site tracking cookies:

  • mm_ns — holds the secret for an anonymous inbox (httpOnly).
  • mm_sess — keeps you signed in.
  • Short-lived OAuth state and team-invite cookies used during those flows.

For traffic measurement we use Cloudflare Web Analytics, which is cookieless and aggregate — it does not set cookies, does not track you across sites, and does not build a personal profile.

7. Your rights

Under Taiwan's Personal Data Protection Act (PDPA), and to the extent other data-protection laws apply to you, you may: inquire about and review the personal data we hold; request a copy of it; ask us to correct or supplement it; ask us to cease collecting, processing, or using it; and ask us to delete it.

To exercise any of these, email team@mailmatter.dev. We may need to verify your identity, and we'll respond within a reasonable period. Note that because mail is purged on a short timer, much of it is deleted before any request would reach us.

8. Security

We serve everything over HTTPS with HSTS, store session and inbox secrets in httpOnly cookies, and keep API keys and webhook secrets hashed or encrypted at rest. Message content is rendered in a locked-down sandbox that blocks remote images and never auto-visits links — so opening a message doesn't leak that you did. No system is perfectly secure, but we treat your data as the ephemeral test material it is.

9. Please don't send sensitive data

MailMatter is a test instrument, not a mailbox. Anyone who knows an address can send mail to it, and reading requires the secret — but you should still never route real personal data, account credentials, financial information, or production secrets through a disposable inbox. Use it for development and testing only.

10. Children

MailMatter is a developer tool and is not directed to children. We do not knowingly collect personal data from children (under 15 under Taiwan's framing, or the equivalent age where you live). If you believe a child has provided us data, contact us and we'll remove it.

11. International transfers

Our infrastructure runs on Cloudflare's globally distributed network, and our sub-processors operate in multiple countries. By using MailMatter you understand that your data may be processed outside your country of residence.

12. Changes to this policy

We may update this policy from time to time. When we make material changes we'll update the “last updated” date above. Continued use after a change means you accept the revised policy.

13. Contact

Questions about privacy, or want to exercise a right? Email team@mailmatter.dev.