Legal and data boundaries

Privacy Policy

This policy explains what data ZOSend processes when providing temporary inboxes and permanent forwarding aliases, why we process it, how long we retain it, and how to contact us. Effective date: August 20, 2026.

1. Scope

This policy applies to the webpages, temporary inboxes, and permanent forwarding console provided by zosend.com. Sender websites, email delivery services, and external links you access through email have their own policies, and we cannot make commitments on their behalf.

By using the service, you understand that email delivery must pass through networks and email infrastructure. If you use the service on behalf of an organization, make sure you are authorized to submit the relevant receiving addresses and email data.

2. Data We Process

Temporary services process random addresses, session tokens, envelope information and message content from incoming mail, and timestamps required to operate the service. Forwarding services also process your login email, aliases you create, forwarding status, archives, attachment metadata, and two-factor authentication status.

To protect the service, we may record request times, IP addresses, browser identifiers, API results, and abuse signals. Please do not receive highly sensitive identity, financial, or medical information in a temporary inbox.

3. Purposes and Legal Bases

Data is used to create inboxes, display incoming mail, forward messages, verify logins, carry out suspension or deletion requests, and respond to support requests. These activities are necessary to fulfill user requests and maintain service security.

Security logs help us limit automated abuse, diagnose failures, and protect other users. We do not use message bodies for targeted advertising or sell email content that identifies individuals.

4. Temporary Inboxes

Temporary addresses can be created without an account, and access is controlled by an unpredictable session token. Anyone with the complete credential URL may be able to open the inbox, so you should not share or publish it.

Once an address expires, it no longer accepts new mail and existing data enters an automated deletion process. Changing the address invalidates the old address and its messages, so save anything you genuinely need beforehand.

5. Permanent Forwarding Accounts

Your login email is used to send one-time verification codes and identify your console account; no traditional password is set. Aliases forward incoming messages to that email, and senders generally cannot see the real receiving address.

Console tokens are stored in the current browser; signing out clears the token. After 2FA is enabled, the authenticator secret and status help strengthen login protection, but recovery remains the user's responsibility.

6. Message Content and Attachments

We must process message content temporarily to display it in an inbox or complete forwarding. The system may sanitize executable scripts and dangerous links, but cannot guarantee that any email is safe or authentic.

Temporary inboxes do not retain attachments, and oversized messages may be rejected. Forwarding services may process attachments and provide authenticated downloads; open only files you expected to receive from a trusted source.

7. Retention Periods

8. Sharing and Service Providers

We disclose only the data necessary to provide the service to hosting, email delivery, security, and infrastructure providers, and require them to process it under our instructions and confidentiality obligations. Email itself also passes through the mail operators chosen by the sender and recipient.

We may disclose necessary data when required by law, to protect the service and user safety, or to handle a corporate reorganization. We do not share mailbox content to sell lists or for advertising transactions.

9. International Transfers

The internet and email infrastructure may cause data to be processed outside your region. We select contracts, access controls, and security measures in accordance with applicable law, but rules may differ between jurisdictions.

If your organization has data residency requirements, assess whether the service is suitable before submitting information. Temporary email should not be used as the default channel for regulated data.

10. Security Measures and Limits

We use encryption in transit, token-based access, least-privilege controls, rate limiting, and monitoring to reduce risk. No online service can guarantee absolute security, and separating email addresses does not hide your IP address, device, or payment identity.

You should protect session URLs and console tokens, and use a unique password and two-step verification for important accounts. If you notice unusual activity, immediately suspend the relevant alias and contact us.

11. Your Choices and Rights

You can let a temporary address expire naturally, change the address, or suspend and delete aliases in the console. Depending on where you live, you may also have the right to request access, correction, deletion, restriction, or objection to certain processing.

When submitting a request, contact support using the relevant login email; we may need to verify control of the account. We cannot restore temporary inboxes deleted as designed or remove copies held in third-party mailboxes.

12. Children, Changes, and Complaints

The service is not intended for children who are legally unable to independently consent to data processing. If a guardian believes a child has submitted information, they can contact us to investigate and delete data that still exists.

If the policy changes materially, we will update the effective date and provide notice where appropriate. You may also complain to your local data protection authority, although we welcome the opportunity to resolve the issue first.

13. Contact Us

Send privacy requests, data questions, and security reports to support@zosend.com. Please state whether your request concerns a temporary inbox or forwarding service, and do not include verification codes or complete session tokens in your email.

We will acknowledge requests within a reasonable period and handle them based on applicable law and the verification results. For content involving a third-party sender, we may suggest contacting that sender as well.