zephbox

Developer API for Automated Signups

See the API →

Privacy Policy

Last updated: September 6, 2026

This page covers data collection, cookies, and advertising on zephbox.com. For what happens to the actual contents of a disposable mailbox — retention, encryption, deletion — see Security & Privacy, which is the more detailed product-specific page. This one exists to name the general-purpose data practices plainly, including the ones that don't fit neatly under "zero logs."

What "zero logs" actually means here

zephbox's own marketing says "zero logs," and that claim is specifically about mailbox content and reading activity — we don't build a profile of what arrives in your temporary inbox or when you check it. It does not mean zephbox collects literally nothing. Like almost every website, we retain the technical and account data described below, and — once advertising is enabled — ad vendors set their own cookies independent of anything zephbox itself logs. Reconciling the two claims honestly is the point of this page.

Data we collect

Device/session data: an anonymous device ID (stored in your browser's local storage) is used to associate a free-tier mailbox with the browser that created it, and to apply daily usage limits. Account data: if you register, we store your username, email address (if provided), and a hashed password — never the password itself. API usage: for Full Access accounts, request counts and timestamps against your API key, so you can see your own usage on the dashboard. Abuse-prevention signals: IP address and basic device fingerprinting are used briefly to rate-limit and detect automated abuse; see Anti-Spam Policy.

Cookies and consent

zephbox uses a cookie consent banner that defaults to denied for anything beyond strictly necessary cookies, per Google's Consent Mode v2 — no analytics or advertising cookie fires until you actively accept. You can change your choice at any time; look for the cookie settings link in the footer. Strictly necessary cookies (session state, your consent choice itself) are not optional and don't require separate consent under GDPR.

Advertising

zephbox is supported in part by display advertising, served through Google AdSense once the account is approved (until then, ad slots show zephbox's own promotional content instead — no third-party vendor is involved yet). Once live, Google and its advertising partners may use cookies — including the DoubleClick cookie — to serve ads based on your visits to zephbox and other sites, subject to your consent choice above. Google's own use of advertising data is governed by Google's advertising policy. You can opt out of personalized advertising at adssettings.google.com, or more broadly via the Digital Advertising Alliance.

Legal basis for processing (GDPR)

Where GDPR applies, zephbox relies on a mix of legal bases depending on the data in question. Technical and abuse-prevention data (device ID, IP address, fingerprinting signals) is processed under legitimate interest — running a disposable-mail service that isn't immediately overrun by automated abuse requires some minimal signal to distinguish real usage from a scraping script. Account data (username, email, password hash) is processed to perform the contract you enter into by registering. Analytics and advertising cookies are processed only with your consent, captured through the cookie banner described above and revocable at any time.

Who we share data with

We don't sell personal data, full stop. We do share a limited amount of data with the vendors necessary to actually run the service: our hosting provider (which processes traffic and stores the database), Google Firebase (push notification delivery and, once approved, AdSense advertising), and our transactional email provider (password-reset and account emails). Each of these processes data strictly to provide their specific function, not for their own independent marketing purposes, and none of them receive the contents of your disposable mailbox beyond what's needed to sync and display it to you.

International data transfers

zephbox's infrastructure and the third-party providers listed above may process data outside your own country, including in the United States. Where that applies to EEA/UK/Swiss users, we rely on those providers' own standard contractual clauses or equivalent safeguards rather than maintaining separate agreements per user — the same arrangement almost every cloud-hosted service depends on.

Data security

Traffic to and from zephbox is encrypted in transit (TLS/HTTPS). Account passwords are stored as salted hashes, never in plain text — even zephbox staff cannot see your actual password. Access to the production database and infrastructure is restricted to the small team operating the service. No system is unbreachable, and if a breach affecting your account data ever occurred, we'd notify affected users and relevant authorities as required by applicable law.

Children's privacy

zephbox is not directed at children and we don't knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with account data, contact us via the form below and we'll delete it.

Do Not Track signals

Some browsers send a "Do Not Track" (DNT) signal. There's no single agreed-upon standard for how sites should respond to DNT, so zephbox doesn't currently change its behavior based on that signal specifically — instead, use the cookie consent banner's opt-out controls described above, which have a concrete, enforced effect on whether analytics/advertising cookies fire at all.

GDPR & other regional privacy rights

If you're in the EEA, UK, or Switzerland, you have the right to access, correct, export, or delete your account data, and to object to or restrict certain processing. If you're a California resident, you have broadly similar rights under the CCPA/CPRA, including the right to know what's collected and to request deletion — and, as stated above, zephbox does not sell personal data, so there's nothing to opt out of on that front. Self-service export and deletion are available from your account settings; if you need help beyond that, use the contact form.

Retention

Free-tier mailbox content follows the expiry window shown in the product (24 hours by default, extendable) — see Security & Privacy for the full mailbox-content retention detail. Account data (username, email, hashed password) persists until you delete your account. Abuse-prevention signals (IP, fingerprint) are retained only as long as needed to enforce rate limits, not indefinitely.

Changes to this policy

We'll update this page if the advertising or data-collection picture changes materially — most notably when AdSense actually goes live — and update the "Last updated" date at the top when we do. We don't maintain a separate change-notification email list for policy updates; continued use of zephbox after an update constitutes acceptance of the revised policy.

Contact

Questions about this policy, or a data request, can be sent via the contact form.

← Generate a temporary email now
zephboxDeveloper API for automated signups
Learn more