← back

Privacy Notice

Last updated: June 5, 2026

1. Who we are

ephemail is operated by Azla Managers LLC dba ephemail. We are the data controller for personal data we collect about you when you use the Service. Contact: privacy@ephemail.io.

2. What we collect and why

We collect only what we need to run the Service:

  • Account data (email address, hashed password, OAuth identifier). Used to create and secure your account.
  • Subscription and billing data (plan, status, period dates, payment provider customer ID). Used to provision paid features. Card details are handled by Paddle; we never see them.
  • Disposable inbox data (generated addresses, message bodies, sender headers, attachments). Used to deliver inbox functionality. Free-tier mailboxes and their messages are deleted ten minutes after creation; paid-tier mailboxes are deleted when their custom lifespan expires.
  • Technical data (IP address hash, request timestamps, user-agent). Used for rate limiting, fraud prevention, and debugging.
  • Support correspondence when you contact us. Used to answer you.

3. Legal bases

  • Contract — to provide the Service you signed up for.
  • Legitimate interests — security, fraud prevention, and improving the Service.
  • Legal obligation — tax records, responding to lawful requests.
  • Consent — where we ask for it (e.g. optional cookies).

4. Who we share data with

  • Paddle — our Merchant of Record. Paddle processes payments, handles billing, calculates and remits taxes, and manages refunds. See Paddle's privacy notice.
  • Infrastructure providers — cloud hosting, database, and email delivery providers acting as our processors under written agreements.
  • Professional advisers — accountants and lawyers when needed.
  • Authorities — when required by law or to protect our rights and users.

5. Retention

  • Free inbox addresses and messages: deleted automatically after 10 minutes.
  • Paid inbox addresses and messages: deleted when their custom lifespan expires.
  • Account data: kept while your account is active and for up to 12 months after closure.
  • Billing records: kept for 7 years to meet tax/accounting obligations.
  • Logs (IP hash, request metadata): up to 30 days.

6. Security

We apply industry-standard technical and organisational measures: encryption in transit (TLS), encryption at rest, access controls, least-privilege service accounts, and audit logging. No system is perfectly secure; we'll notify affected users and regulators of any breach as required by law.

7. Your rights

You can ask us to:

  • Access or export your personal data.
  • Correct inaccurate data.
  • Delete your account and associated data.
  • Restrict or object to certain processing.
  • Withdraw consent where processing is based on it.

Email privacy@ephemail.io and we'll respond within 30 days. If you're in the UK/EEA you can also complain to your local supervisory authority.

8. International transfers

Our infrastructure and Paddle may process data outside your country, including in the United States. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

9. Cookies

We use a small number of essential cookies and local-storage entries to keep you signed in and to remember your active disposable inbox. We do not use third-party advertising cookies.

10. Changes

We'll post material changes here and, where significant, email registered users at least 14 days before they take effect.