Once Email Privacy Policy

How Once Email handles temporary mailbox, account, billing, technical log, browser-local tool and privacy-request data.

Last updated: 12 August 2026

1. Scope

This policy covers the Once Email website at once-email.com, its receive-only temporary mailbox and its browser-local tools. The service does not provide outbound email.

2. Data needed to provide the service

When you use a temporary mailbox, our systems process the temporary address, received message metadata, message content and attachment data as needed to receive the message, display its safe mailbox view and make listed attachments available for download. Once Email does not unpack archives, preview attachment contents, inspect files inside an archive or send attachments to an online unpacking service. Mailbox data is temporary and is scheduled for deletion within the selected lifetime, up to the one-day lifetime shown by the service. You may delete or replace an address sooner. Deleted or expired data cannot be restored.

Our hosting and security providers may process ordinary technical data such as IP address, request time, requested path, browser information and security signals to deliver the site, prevent abuse and diagnose failures. Cloudflare provides network delivery and security services under its own privacy terms.

3. Browser storage

The site may store strictly functional preferences, such as language and selected mailbox lifetime, in cookies or browser storage. These preferences help the site remember a choice; they are not used to build an advertising profile.

4. Local tools

The email header analyzer, link checker and password generator run in your browser after you choose to use them. Tool input and generated passwords are not added to URLs, analytics, browser storage or server requests. Do not paste confidential information unless it is necessary for your own local review.

5. Accounts and billing

Google sign-in is used to create a secure session and provide account preferences, session controls, export and deletion. Signing in does not cause Once Email to retain message bodies, attachments or a complete mailbox history.

When you start or manage a paid API subscription, Stripe receives payment and billing information directly. Depending on the payment method and location, this can include your name, email, billing address, payment-method details and fraud-prevention signals. Once Email receives only the minimum customer, subscription, invoice, payment status and billing-period references needed to provide access, reconcile charges and support requests; it does not receive or store full card numbers. Stripe processes data under its Privacy Policy. Billing and transaction records may be retained where required for tax, accounting, dispute, fraud-prevention or legal obligations even after account deletion. Payment data is not sent to Google Analytics or AdSense.

6. Analytics and advertising status

Once Email keeps advertising disabled while AdSense review is incomplete. On public content pages—home, Blog, company information and developer documentation—you may choose whether Google Analytics measures a sanitized page path, content type and identifier, language, referring origin, reading depth, a 30-second engagement signal, navigation between public content and the domain of an outbound link. Analytics remains off until you allow it, and you can reject or withdraw that choice from the on-page control. Mailboxes, messages, attachments, tools, sign-in, account, billing, support and policy pages are not measured. Query strings, link paths on external sites and form or tool input are not sent.

Mailbox, message, attachment, tool, sign-in, account, billing, support and policy pages never load Google Analytics or advertising. Email addresses, message content, verification codes, tokens, API keys, attachment details, payment data and complete URLs are excluded from analytics. Google Signals and advertising personalization remain disabled.

7. Sharing and processors

We do not sell personal information. Data may be processed by infrastructure providers strictly to host, secure and operate the service, or disclosed when legally required or necessary to protect users and the service. We do not claim that email sent to a temporary public-facing address is appropriate for confidential use.

8. Your choices

You can delete or replace a temporary address, clear local tool inputs, clear browser preferences and stop using the service. For privacy questions or a request concerning data that can reasonably be identified, contact [email protected]. We may need enough information to verify and locate the request, and some data may already have expired.

9. Children and sensitive use

The service is not designed for children or for receiving medical, financial, government, legal, account-recovery or other sensitive communications.

10. Changes

Material changes will be posted here with an updated date. Questions and complaints can be sent through the contact page.