Three hours by default
The address, access token, and incoming messages are cleared when the validity period ends. You can also change the address or delete individual messages earlier.
DATA NOTE / 2026-09-10
This notice explains how MsgQuick handles information when providing temporary inboxes, long-term addresses, and security verification. We list what we collect, why we use it, how long we retain it, and how to delete it all in one place, so you can make an informed choice before using the service.
Temporary inboxes and long-term addresses created after login use different credentials and retention periods. Using the same browser does not merge them into one public identity.
The address, access token, and incoming messages are cleared when the validity period ends. You can also change the address or delete individual messages earlier.
Incoming mail sent to logged-in aliases retains its subject, sender, status, and body, then is automatically cleared after the retention period.
We use email verification codes to confirm access. When an authenticator is enabled, we store its encrypted configuration state, not one-time codes.
Email bodies are not sold, used for advertising profiles, or added to a public directory.
MsgQuick is the data controller for this service. This notice applies to the temporary email, passwordless login, long-term address, delivery archive, and two-step verification features on msgquick.com. When third-party websites send mail to your address, those parties are responsible for their own data processing.
If you reach our service from another website, please read that site’s privacy notice too. We cannot control external links, tracking pixels, or attachments placed in messages by senders, so we block some active content by default and recommend caution when opening external resources.
Temporary inboxes require us to process an automatically generated address, a random access token, its validity period, email envelope fields, message bodies, and attachments. Long-term addresses also involve your receiving email address, created aliases, delivery status, session tokens, and optional authenticator settings.
To keep the service available, we may record request times, broad error categories, browser identifiers, and network identifiers that have been shortened or hashed. We do not ask for your name, home address, government ID number, or payment information, and you do not need an account to use a temporary inbox.
We process email addresses and message content to receive, display, forward, and delete messages at your request and to maintain address validity. We process verification codes and session tokens to confirm that you are authorized to enter the workspace for the relevant long-term address.
Security logs help prevent abuse, diagnose delivery failures, and protect our infrastructure. The legal basis is service delivery and the maintenance of legitimate security interests. Where local law requires consent, we will offer the relevant choice before enabling non-essential storage.
Each temporary inbox is controlled by an unpredictable token, and the page does not publicly index that token. Knowing an address does not grant inbox access, but sharing the complete access link may give someone else the same reading capability.
A temporary address is not a long-term identity credential, and recovery after expiration is not guaranteed. Do not use it for assets, healthcare, work, or any account you may need to recover later.
Aliases created after login forward incoming messages to your verified receiving email address and keep a limited archive in the dashboard. You can pause an entry, copy its address, delete the entry, or delete an individual record; each action applies only to the relevant identifier.
After you delete an alias, new messages are no longer forwarded through it. Copies already delivered to your external inbox are not affected by deletion here; you must delete those copies through your email provider.
Temporary addresses are valid for three hours by default, and extending them updates the expiration time. After expiration, related messages enter the cleanup process. Delivery records for long-term addresses are generally kept for 30 days, while security logs use shorter or restricted periods based on troubleshooting and abuse-prevention needs.
Deletion from backups may be subject to a reasonable delay, but backups are used only for disaster recovery and do not return to routine product workflows. A very small amount of information that must be retained by law is access-restricted and deleted when the legal obligation ends.
| Data category | Primary purpose | Typical period | Your control |
|---|---|---|---|
| Temporary address and token | Open a separate inbox | 3 hours by default | Change the address or wait for expiration |
| Temporary email content | Display incoming mail | For the address validity period | Delete individual messages |
| Long-term alias archive | Verify delivery | Up to 30 days | Delete an individual message or entry |
| Verification codes and sessions | Confirm access | Short term or until logout | Clear the current session on logout |
We share limited data only with providers needed for hosting, email delivery, security protection, and troubleshooting. Providers are bound by contractual, confidentiality, and security requirements and may not use this information for their own advertising.
Our infrastructure may be located outside your country or region. We use applicable contractual mechanisms and access controls to protect transfers. If cross-border processing is prohibited by law, we will adjust the processing location or discontinue the relevant feature.
This site uses browser local storage to save temporary inbox tokens, login sessions, and interface state, so you can continue your current task after refreshing the page. These necessary storage technologies are not cross-site advertising cookies and do not track you across different websites.
Clearing browser data removes credentials from this device and may prevent you from re-entering a temporary inbox that has not yet expired. On a shared device, log out of the long-term address dashboard and clear browser data when you finish.
We use encryption in transit, token isolation, access controls, content sanitization, and restricted logging to reduce risk. Email is an open communications protocol, so senders, forwarding paths, and receiving email providers may still access the relevant content.
No online service can promise absolute security, and a temporary inbox should never be treated as an encrypted vault. If you notice unauthorized access, malicious content, or a leaked token, change the address immediately and contact us.
This service is not an identity or social product designed for children, and we do not knowingly ask minors to submit their name, age, or school information. If a parent or guardian believes a child has provided personal information to us, they may request its review and deletion.
If we cannot reasonably verify the requester’s relationship to the data, we may need a minimal amount of additional information. Once verification is complete, supplementary materials are used only to handle the request and deleted on the shortest practical schedule.
Under applicable law, you may ask what information we hold about you and request correction, deletion, restriction of processing, or a portable copy. When a temporary inbox has no account identity, you must provide valid access credentials to prevent someone else from using the request to read its messages.
We will respond within a reasonable period and explain the outcome or why the request cannot legally be fulfilled. We may limit requests that are clearly repetitive, excessive, or impossible to verify, but we will not charge unreasonable fees as a result.
We will update this notice when features, laws, or provider relationships materially change and will show the effective date at the top of the page. Where reasonable, significant changes will be explained through an in-service notice rather than quietly expanding how we use email content.
To exercise your rights, report a security issue, or ask about processing boundaries, email support@msgquick.com. Please do not attach unnecessary verification codes, complete access tokens, or sensitive files to support emails.