zephbox

Developer API for Automated Signups

See the API →

Privacy · By zephbox Team · November 4, 2026

GDPR and Temporary Email: What Data We Actually Keep (and Delete)

Most "GDPR compliance" pages are written by legal teams for legal teams, and answer approximately none of the questions a privacy-conscious user actually has. This is the plain-language version of that same information, specific to what a temp mail service like zephbox actually stores.

What gets stored while an alias is active

The alias address itself, the messages it receives, and, for account-holders, whatever identifying information you provided to create an account. That's an email in the premium case; nothing at all for anonymous free-tier use, which is device-tracked rather than identity-tracked. No content analysis beyond what's needed to extract OTP codes for the developer API, and that extraction happens on request, not as background profiling.

What happens on expiry

The alias and every message tied to it are deleted from the database. Not soft-deleted, not archived, not retained for "analytics." Free-tier aliases without an owner are hard-deleted on a schedule after their grace window; the row and everything cascading from it (messages, associated stats) is actually gone, not just hidden from the UI.

Your right to erasure, concretely

If you have a registered account, you can request a full data export or account deletion directly. The export gives you a JSON dump of your profile, aliases, messages, devices, and API keys. Deletion anonymizes your account (scrubbed username/email, unusable password, account deactivated) and hard-deletes your aliases, messages, devices, and API keys. What it deliberately does not delete is billing/subscription records, retained for the legal and financial record-keeping period most jurisdictions require regardless of an erasure request, but detached from any personally identifying data and not tied back to "you" in any usable way.

Why "built to delete itself" is the actual compliance story

GDPR's data-minimization principle is about not retaining personal data longer than necessary. A service whose entire product is built around addresses that expire on a timer is, by construction, aligned with that. The alternative, retaining every temp inbox forever "just in case," is both a worse privacy posture and a real infrastructure cost nobody would actually choose to carry.

Full details in Security & Privacy, including what this doesn't protect against. A temp address is spam and address-hygiene protection, not a general anonymity tool.

Gmail & Outlook Temp Mail That Services Can't Block

95%+ acceptance rate for Facebook, Instagram, Netflix & OTP signups.

Try zephbox Premium →

Related guides

← Generate a temporary email now
zephboxDeveloper API for automated signups
Learn more