Security

GoneMail is designed with privacy and security at its core. Here are the technical measures protecting your data.

1. Transport Security

All communications between your browser and the service are encrypted in transit using TLS/HTTPS (HTTP/2). The site enforces HTTPS via HSTS (HTTP Strict Transport Security), so browsers automatically refuse any unencrypted connection.

Security headers are applied on every response, including X-Frame-Options, X-Content-Type-Options and Referrer-Policy, to reduce common web attack vectors.

2. No Personal Data Collected

GoneMail requires no account, no name, no email and no phone number. You are anonymous by design: we never collect any identifiable personal data.

No tracking or advertising cookies are used. The only locally stored data is your mailbox session identifier in the browser's localStorage.

3. Data Retention & Automatic Purge

Temporary mailboxes and their messages are automatically and permanently deleted when they expire:

  • Mailbox lifetime: from 1 hour up to 7 days (chosen by you)
  • Messages: permanently deleted with the mailbox at expiration
  • Server logs: deleted after 30 days

Deletion is irreversible β€” no data can be recovered after expiration.

4. Third-Party Dependencies

GoneMail relies on the following technical partners, which process data solely for the operation of the service:

  • Mail.tm: public API used to create temporary mailboxes
  • EmailJS: contact form message delivery
  • Hostinger: website hosting (EU-based infrastructure)
  • Google Analytics: aggregated, anonymized visit statistics with consent (Consent Mode v2)

5. Anti-Abuse Protection

The service implements rate limiting and abuse prevention measures to keep the platform safe and available for everyone.

6. Vulnerability Reporting

If you discover a security vulnerability in GoneMail, please report it responsibly by contacting us at contact@gonemail.app

Last updated: August 1, 2026