Security
GoneMail is designed with privacy and security at its core. Here are the technical measures protecting your data.
1. Transport Security
All communications between your browser and the service are encrypted in transit using TLS/HTTPS (HTTP/2). The site enforces HTTPS via HSTS (HTTP Strict Transport Security), so browsers automatically refuse any unencrypted connection.
Security headers are applied on every response, including X-Frame-Options, X-Content-Type-Options and Referrer-Policy, to reduce common web attack vectors.
2. No Personal Data Collected
GoneMail requires no account, no name, no email and no phone number. You are anonymous by design: we never collect any identifiable personal data.
No tracking or advertising cookies are used. The only locally stored data is your mailbox session identifier in the browser's localStorage.
3. Data Retention & Automatic Purge
Temporary mailboxes and their messages are automatically and permanently deleted when they expire:
- Mailbox lifetime: from 1 hour up to 7 days (chosen by you)
- Messages: permanently deleted with the mailbox at expiration
- Server logs: deleted after 30 days
Deletion is irreversible β no data can be recovered after expiration.
4. Third-Party Dependencies
GoneMail relies on the following technical partners, which process data solely for the operation of the service:
- Mail.tm: public API used to create temporary mailboxes
- EmailJS: contact form message delivery
- Hostinger: website hosting (EU-based infrastructure)
- Google Analytics: aggregated, anonymized visit statistics with consent (Consent Mode v2)
5. Anti-Abuse Protection
The service implements rate limiting and abuse prevention measures to keep the platform safe and available for everyone.
6. Vulnerability Reporting
If you discover a security vulnerability in GoneMail, please report it responsibly by contacting us at contact@gonemail.app
Last updated: August 1, 2026