Privacy
Privacy notice
Effective 31 August 2026
Junkmail is a private, receive-only disposable-email service. This notice explains the data the Junkmail service handles and the controls available to you. It does not turn your aliases into public inboxes, and Junkmail does not forward received mail to your real address.
Data we handle
- Account data: your real email address, password hash, verification and password-reset state, optional two-factor setup, plan and preference settings.
- Alias and mailbox data: claimed alias addresses, labels and notes, received message content and headers, extracted verification codes and links, attachments, tags, and mailbox state such as read, starred, pinned, or archived.
- Security and operations data: session identifiers stored only as hashes, IP address and browser information for session security, rate-limit state, delivery and abuse counters, and service diagnostics.
- Integrations you configure: API-token metadata, webhook URLs and delivery state, and browser push-subscription endpoints and keys.
- Optional billing data: the selected Premium or Pro tier, a random order identifier, BTCPay invoice identifier and status, quoted amount and currency, settlement and paid-through times, and typed webhook-delivery metadata. Junkmail never stores your wallet private key, seed phrase, card, or payment credential.
Passwords, personal access tokens, recovery codes, and webhook signing secrets are stored only in hashed or encrypted form appropriate to their use. A newly issued token, recovery code, or webhook secret is shown only when it is created.
Why we use it
We use this data to authenticate you, receive and display mail for aliases you control, search and organize your mailbox, deliver notifications or webhooks you request, prevent abuse, enforce service limits, protect the service, and operate backups and diagnostics. The receiving domains cannot send or reply, and received messages are never forwarded.
Legal bases
Account, alias, mailbox, API, requested-integration, and optional paid-plan processing is necessary to provide the service you ask for and perform the Terms of service. Security, fraud prevention, rate limits, aggregate reliability statistics, and service defense rely on the operator’s legitimate interests in keeping the shared service safe and available. Billing records required by tax, accounting, or other applicable law are processed to comply with those obligations. Optional browser notifications are enabled only at your request and can be withdrawn by removing the subscription or disabling push.
Retention and deletion
- Unpinned messages are automatically deleted after the retention period for your plan; the launch Free plan uses 60 days. Pinned messages remain until you unpin or delete them, reach a storage limit, or delete the account.
- Rejected mail is count-only. Junkmail does not retain rejected message content as a quarantine.
- Sender and recipient metadata in operational logs is kept for no more than 30 days.
- When an account is deleted, its mailbox content, stored files, integrations, credentials, and sessions are purged from the live service. Claimed alias addresses remain as anonymized, permanently burned tombstones so they can never be reassigned; labels, notes, and account ownership are removed.
- Immutable operator-audit entries are preserved indefinitely for audit integrity. They contain administrator and affected-account identifiers, the administrator request IP address and bounded browser user-agent string, and safe action metadata. They never contain message bodies or stored message content. Once an affected account has been deleted, its numeric identifier no longer resolves to an account record.
- Mail sent to
abuse@,postmaster@, orprivacy@junksink.combecomes a private operator report containing the sender address, subject, and a bounded plaintext description; attachment bodies and the raw message are not retained. Open reports remain until handled, then resolved or dismissed reports are deleted after 90 days. - Operational recovery copies, when enabled, follow the documented retention and deletion controls for the active storage configuration. Deleted data is not used for ordinary processing and, if a recovery copy must be restored, deletion controls are reapplied before normal service resumes.
- Account exports requested by you or an administrator are generated by a background worker, kept in private storage for at most 24 hours, and downloadable only by the account owner.
- Typed BTCPay delivery events that are not needed to prove an entitlement are deleted after the configured operational retention period. Checkout URLs and transient error fields are cleared on that shorter operational schedule. On account deletion, an active subscription is removed and retained invoice, entitlement, and exact-once event records are detached from the account and stripped of checkout/error data; only the minimum invoice and delivery identifiers, fingerprint, amount, currency, term, status, and accounting timestamps remain for the approved accounting period where legal or operational integrity requires them.
Service providers and destinations you choose
Junkmail uses infrastructure needed to host, store, search, and protect the service. When account verification and password-reset delivery is enabled, that mail goes through a dedicated transactional provider, never through a Junkmail receiving domain. If you enable browser push, the push service associated with your browser receives only the alias, sender, and subject—not the body or extracted code. If you configure a webhook, its metadata-and-code payload is sent to the HTTPS endpoint you choose.
Premium and Pro checkout is served by Junkmail’s self-hosted BTCPay Server. It processes the invoice, Bitcoin address, payment and network data needed to observe settlement. Bitcoin transactions are also recorded on the public Bitcoin network. Junkmail’s application receives only signed invoice events and reads the canonical invoice status; it does not receive or store a wallet private key or seed phrase.
Hosting, DNS, and transactional-mail suppliers process only the data needed for their role under the operator’s instructions and contractual safeguards. A webhook destination is selected by you, and a browser push service is selected by your browser vendor. If a provider or destination processes data outside your country or the European Economic Area, the operator uses an applicable adequacy decision or appropriate safeguards such as standard contractual clauses where the law requires them.
Junkmail has no ads and no cross-site tracking. It does not sell mailbox data. Authentication and security cookies are used only to provide sign-in, session, remember-me, and CSRF protection; aggregate service metrics do not require tracking cookies.
Your controls
From Your data, an authenticated user can download a ZIP containing JSON account, alias, message, billing, session, security-activity, and integration metadata plus the raw .eml files still retained, or permanently delete the account after confirming the current password. Password and two-factor secrets, token and recovery-code hashes, webhook secret ciphertext, push encryption keys, payment credentials, and internal storage paths are excluded from the export because disclosing credential material would weaken account security. You can also delete individual messages, burn aliases, revoke sessions and API tokens, remove webhooks and push subscriptions, and disable optional two-factor authentication.
Depending on where you live, you may also have rights to access, correct, erase, restrict, port, or object to processing, and to withdraw consent without affecting earlier processing. Use the self-service controls where they cover your request, or email privacy@junksink.com for a privacy question that cannot be completed in the product. You may lodge a complaint with the data-protection supervisory authority responsible for your habitual residence, workplace, or the place of an alleged infringement.
Security boundary
Message HTML is treated as hostile input: it is sanitized, displayed in a sandboxed frame, and remote images are blocked by default. Mailbox content has no operator-console reading route. No system can make internet email risk-free, so protect your account password and recovery codes and revoke access you no longer use.