are disposable inboxes gdpr-compliant?

// controller vs processor
controller vs processor
When you (the customer) send a verification email to a disposable address, you are the controller for that data. ephemail acts as a processor — we receive, store, and serve the message strictly on your behalf.
The legal basis for processing the recipient's data is usually your own legitimate interest in testing your product, plus the consent of any human tester whose name shows up in the message body.
// retention is the easy part
retention is the easy part
Short, hard-coded retention is the single most important compliance control for a disposable inbox. Our public addresses delete messages after 10 minutes; private addresses inherit the workspace policy (default 24 hours).
"the best way to comply with data minimization is to not store the data."
// the dpa
the dpa
We publish our Data Processing Addendum at /dpa. It includes the EU SCCs, the UK Addendum, and a list of sub-processors. You don't have to sign anything — accepting the terms of service incorporates it.
Amine builds ephemail and writes about email plumbing, developer tooling, and the small annoyances of testing software.


