back to blog
Regulations

are disposable inboxes gdpr-compliant?

March 2, 2026 7 min readregulations
Shield made of cyan and magenta light rays
on this page

// controller vs processor

controller vs processor

When you (the customer) send a verification email to a disposable address, you are the controller for that data. ephemail acts as a processor — we receive, store, and serve the message strictly on your behalf.

The legal basis for processing the recipient's data is usually your own legitimate interest in testing your product, plus the consent of any human tester whose name shows up in the message body.

// retention is the easy part

retention is the easy part

Short, hard-coded retention is the single most important compliance control for a disposable inbox. Our public addresses delete messages after 10 minutes; private addresses inherit the workspace policy (default 24 hours).

"the best way to comply with data minimization is to not store the data."

// the dpa

the dpa

We publish our Data Processing Addendum at /dpa. It includes the EU SCCs, the UK Addendum, and a list of sub-processors. You don't have to sign anything — accepting the terms of service incorporates it.

Amine Gharby
// written by
Amine Gharby
Founder, ephemail

Amine builds ephemail and writes about email plumbing, developer tooling, and the small annoyances of testing software.

// try it

spin up a throwaway inbox

no signup. instant. gone in ten minutes.

open inbox
// related posts

keep reading