Cookie Policy
Last updated: 25.08.2026
1. Introduction
This Cookie Policy explains how Red Phoenix Team ("we", "us", or "our") uses cookies and similar technologies when you access getrandom.email. By continuing to use our service, you acknowledge that you have read and understood this policy.
2. What Are Cookies
Cookies are small text files that are placed on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work more efficiently and to provide information to the site operators. Similar technologies include local storage and session storage, which allow websites to store data locally in your browser.
3. Why We Use Cookies
We use cookies and similar technologies for the following purposes:
- Operating the service — maintaining your session so the service functions correctly.
- Session management — identifying your anonymous mailbox, or your account if you are signed in, so that the right inbox is shown to you.
- Security — protecting against cross-site request forgery (CSRF) attacks.
- Remembering preferences — storing your chosen theme (light or dark mode), and whether you left the mailbox panel open or closed, so that both are as you left them between visits.
4. Types of Cookies We Use
Strictly Necessary Cookies
These cookies are essential for the service to function and cannot be switched off. They are set without requiring consent because the service cannot operate without them.
All three are first-party cookies, set on getrandom.email itself. This is the complete list — the Service sets no other cookies.
guest-session— Identifies the temporary mailbox created for you when you visit without an account, so that your inbox is still yours when the page reloads. It holds the mailbox's identifier and nothing else: no name, no email address of yours, and nothing that identifies you. Set the first time a temporary mailbox is created for you, httpOnly, SameSite=Lax, and Secure. It expires after 30 minutes, which is the lifetime of the mailbox itself.sessionid— The Django session cookie that keeps you signed in to an Account. Set only when you sign in, and not at all if you use the Service anonymously. httpOnly, SameSite=Lax, and Secure. It lasts 14 days, and it is not cleared when you close your browser — sign out to end the session sooner.csrftoken— The Django cross-site request forgery token. Every request that changes something must carry a matching value in a header, which proves the request came from a page of ours rather than from another site. Unlike the two above it is deliberately readable by JavaScript, because the page itself has to read it in order to send that header; it is a public token that grants nothing on its own. Like sessionid it is issued when you sign in. SameSite=Lax and Secure, and it lasts one year.
Functional Cookies / Storage
These enhance your experience by remembering your preferences.
None of these is a cookie. They are stored by your browser and are never sent to us, but we list them because they are storage on your device and this policy would be incomplete without them.
- Theme preference — Your light or dark mode choice, stored in localStorage under the key
themeby the next-themes library, so that the site does not change appearance between visits. - Sign-up address — If you type an email address on the sign-in page and then follow the link to create an account, that address is held briefly in sessionStorage under the key
tempmail:signup-emailso the sign-up form can be filled in for you. It is removed as soon as the form reads it, and in any case when you close the tab. - Mailbox panel — Whether you opened or closed the mailbox panel on the home page, stored in localStorage under the key
tempmail:mailbox-panelas the single wordopenorclosed, so that the panel is as you left it when you return. That word is the whole of it: no address, no mailbox, no record of when you were here. It is written when you actually open or close the panel — using its own control, or by pressing Escape while it is open. Pressing Escape when the panel is already closed moves nothing and stores nothing, and if you never touch the panel at all, nothing is stored. - A session-ending notice you dismissed — If you are signed in, we tell you before your session ends, so that you are not signed out in the middle of something. Dismissing that notice stores the fact under the key
tempmail:session-warningin localStorage, so that it does not reappear on every page you visit. The value is which of the two notices you dismissed and the moment your current session ends — nothing about you, your addresses or your mailboxes. Nothing is stored unless you press Dismiss, and the site deletes it by itself as soon as it stops applying: when you sign in again, and once the session it refers to has ended.
Note: We do not currently use any analytics, advertising, or tracking cookies.
5. Legal Basis
Our use of cookies is based on the following legal frameworks depending on your location:
- United Kingdom — We rely on legitimate interests for strictly necessary cookies and obtain consent where required under the UK GDPR and the Privacy and Electronic Communications Regulations (PECR).
- United States — We comply with applicable state privacy laws, including the California Consumer Privacy Act (CCPA) and similar legislation.
- Canada — We rely on implied consent for strictly necessary cookies and obtain express consent where required under the Personal Information Protection and Electronic Documents Act (PIPEDA).
6. Consent and Management
You can manage cookies through your browser settings. Most browsers allow you to view, delete, and block cookies from websites. You can also clear localStorage data through your browser's developer tools or settings.
Please note that disabling strictly necessary cookies may affect the functionality of getrandom.email. For example, without the guest-session cookie we cannot tell which temporary mailbox is yours, so a reload will give you a different address and the mail already delivered to the previous one becomes unreachable.
7. Third-Party Cookies
We do not use third-party cookies on getrandom.email. However, if you subscribe to a paid plan, payment processing is handled by Stripe. Stripe may set its own cookies on its domain during the checkout process. These cookies are governed by Stripe's Privacy Policy.
8. Data Collected Through Cookies
The data collected through our cookies is limited to:
- The identifier of the temporary mailbox issued to you, if you are using the Service without an account
- A session identifier, if you are signed in to an Account
- A cross-site request forgery token
- Your theme preference and your mailbox panel choice, and briefly a sign-up address you typed
This data is not used for profiling, advertising, or any purpose beyond the operation and security of the service.
9. Data Retention
guest-session— 30 minutes, the same lifetime as the temporary mailbox it points at.sessionid— 14 days, or until you sign out.csrftoken— One year, then automatically replaced.- Theme preference — Persists in localStorage until you clear your browser data.
- Sign-up address — Removed as soon as the sign-up form reads it, and in any case when you close the tab.
- Mailbox panel — Persists in localStorage until you clear your browser data, and is overwritten each time you open or close the panel.
- A session-ending notice you dismissed — Removed by the site itself once it no longer applies: when you next sign in, or once the session it refers to has ended.
10. Changes to This Policy
We may update this Cookie Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. Material changes will be communicated through a notice on the service. We encourage you to review this page periodically.
11. Contact
If you have any questions about this Cookie Policy or our use of cookies, please contact us:
Red Phoenix Team
[email protected]