Privacy Policy
Last updated: 25.08.2026
Red Phoenix Team ("we", "us", "our") operates getrandom.email, a temporary email service. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our service. Please read this policy carefully. By accessing or using getrandom.email, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy.
Scope and Purpose
This Privacy Policy applies to all personal data collected through our website, customer support channels, and payment systems. We process personal data only for lawful purposes and in accordance with applicable data protection laws. It covers you in whichever of these three ways you use getrandom.email:
- Without an account — a temporary disposable mailbox with a 30-minute time to live, no signup required.
- With a free account — signed in, without a Pro subscription. You can still create temporary mailboxes, and they expire the same way.
- With a Pro subscription — a paid plan, sold today, that adds persistent mailboxes which do not expire, and API access. Retention differs for these; see Data Retention below.
Legal Bases for Processing
Nevada Notice
Under Nevada law, certain consumers may opt out of the "sale" of personally identifiable information. We do not sell personal data as defined under Nevada law. If you are a Nevada resident and wish to submit an opt-out request, please contact us at [email protected].
California Privacy Notice (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information. We may collect the following categories of personal information:
- Identifiers — email address, IP address, online identifiers
- Customer records and account information — account credentials and profile data (Pro users)
- Commercial information — subscription details and transaction history (Pro users)
- Application activity and engagement metrics — service usage patterns and interaction data
- Geolocation data — approximate location derived from IP address
- Inferences — derived information about user preferences based on service usage
California Rights
California residents have the following rights under the CCPA:
- Right to access — you may request that we disclose what personal information we have collected about you
- Right to deletion — you may request that we delete personal information we have collected from you
- Right to opt-out — you may opt out of the sale of personal information (we do not sell personal data)
- Right to correction — you may request correction of inaccurate personal information
- Non-discrimination — we will not discriminate against you for exercising your privacy rights
- Shine the Light — California Civil Code Section 1798.83 permits you to request information about disclosure of personal information to third parties for their direct marketing purposes
UK GDPR Legal Bases
Where UK GDPR applies, we rely on the following legal bases for processing your personal data:
- Contract performance — processing necessary to provide the getrandom.email service to you
- Consent — where you have given clear consent for us to process your personal data for a specific purpose
- Legitimate interests — processing necessary for our legitimate interests, such as improving our service and ensuring security, provided these interests do not override your rights
- Legal obligation — processing necessary to comply with legal requirements
Personal Data Collected
We collect personal data in several ways: directly from you, automatically when you use the service, and occasionally from third parties such as payment processors.
Account Information
If you create an account — whether or not you subscribe to Pro — we collect your email address and your account credentials, and we hold them for as long as the account is open. If you sign in with Google, we also store the identifier Google gives us for your account. You do not need an account to use getrandom.email: if you only ever use a temporary mailbox without signing up, you give us no personal information at all.
Service Data
We process temporary email addresses generated through the service and collect interaction metrics related to your use of getrandom.email, such as the number of mailboxes created and emails received.
Technical and Usage Data
When you access getrandom.email, we automatically collect certain technical information including your IP address, device and browser information, and server log files. This data helps us maintain service security and diagnose technical issues.
Billing Data
For Pro users, we collect subscription status, payment history, and transaction identifiers. Payment processing is handled by Stripe, and we do not store full payment card details on our systems.
How We Use Personal Data
We use the personal data we collect for the following purposes:
- To provide and maintain the getrandom.email service
- To manage user accounts and subscriptions (Pro users)
- To respond to customer support inquiries
- To protect the security and integrity of our service, including preventing abuse and spam
- To comply with legal obligations and enforce our terms
- To improve and develop our service based on aggregated usage patterns
We do not use your personal data for automated profiling or decision-making.
Payment Processing
Payments are processed by Stripe. We do not store full payment card details. When you make a payment, your card information is transmitted directly to Stripe, which handles the transaction in accordance with their own privacy policy and PCI DSS compliance standards. We receive only transaction identifiers, subscription status, and payment confirmation details from Stripe.
Cookies and Tracking Technologies
getrandom.email uses only essential cookies that are necessary for the service to function properly. We do not use analytics tracking, advertising cookies, or third-party tracking technologies. There are three, all first-party, and this is the complete list:
- guest-session — set the first time a temporary mailbox is created for you, which happens without an account and so is the only cookie most visitors receive. It holds the mailbox's identifier and nothing that identifies you. It expires after 30 minutes, the lifetime of the mailbox.
- sessionid — the Django session cookie that keeps you signed in to an Account. Set only when you sign in, and not at all if you use the Service anonymously.
- csrftoken — a cross-site request forgery protection token required for security. Issued when you sign in.
Your light or dark mode choice is not a cookie. It is kept in your browser's localStorage and is never sent to us — as is a sign-up address you type on the sign-in page before following the link to create an account, and whether you left the mailbox panel on the home page open or closed, which is stored under tempmail:mailbox-panel as the single word open or closed and says nothing else about you. There is one more, and only if you are signed in and press Dismiss on it: the notice that tells you before your session ends records that you dismissed it, under tempmail:session-warning, as which notice it was and when the session ends. The site removes that one by itself once it no longer applies. Our Cookie Policy describes all seven in full, including how long each lasts and how to remove them. We do not currently use any analytics services.
Data Sharing and Disclosure
We do not sell personal data. We may share your personal information with the following categories of recipients only as necessary:
- Hosting provider — our infrastructure provider that hosts the getrandom.email service
- Payment processor — Stripe, for processing subscription payments (Pro users)
- Professional advisors — legal, accounting, and other professional advisors as needed
- Authorities when required — law enforcement or regulatory bodies when required by law, court order, or governmental regulation
We do not share data with advertisers, social media platforms, or marketing services. We do not use Meta Pixel or any advertising tracking technologies.
International Data Transfers
Your personal data may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from the laws of your country. When we transfer personal data internationally, we implement appropriate safeguards, including standard contractual clauses approved by relevant authorities, to ensure your data is protected in accordance with this Privacy Policy.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Temporary mailboxes and their mail — deleted automatically, with every message in them, when the mailbox expires. A mailbox created without an account expires 30 minutes after it is made.
- Persistent (Pro) mailboxes and their mail — not deleted on any timer while the mailbox is in your dashboard. A persistent mailbox has no expiry date, so nothing automatically removes it or the messages in it, and we keep them for as long as you keep the mailbox.
- After you remove one mailbox — removing a mailbox from your dashboard stops it accepting new mail immediately and takes it off your screen. The messages already in it are kept for 30 days and then deleted permanently. During those 30 days you can still download them with everything else we hold about you, using the export described under Your Rights below; after that they are gone and we cannot recover them. The address itself we keep for ever, so that it is never handed to anyone else. To have the mail from one mailbox deleted sooner than 30 days, ask us at [email protected]. To have all of it deleted, deactivate your account — the next bullet.
- After you deactivate your account — you can deactivate your account yourself, from your dashboard. Deactivating stops all of your addresses accepting mail immediately and signs you out; it deletes nothing at the time. Thirty days later, we delete your mailboxes and every message in them, your API keys, and your usage records. The thirty days begin when you deactivate.
- Your account record, after those 30 days — if you have never subscribed, the account record itself is deleted outright at the same time. If you have ever subscribed, it is anonymised rather than deleted: your email address and username are replaced with a random value that cannot be turned back into your address, any linked Google account is unlinked, and your password is destroyed. We do that rather than delete the record because your billing record is attached to it, and we are required to keep that — see the next bullet. What is left is a record of a subscription with no person attached to it.
- Billing records — retained for the period required by applicable tax and accounting laws. This is the one thing deactivating your account does not remove, and it is why the account record is anonymised rather than deleted for anyone who has subscribed. If you have ever started a checkout — including one you did not finish — our payment processor holds a customer record for you and we hold a copy of it; those are billing records, they keep the email address you signed up with, and deactivating your account does not delete them. Payment card details are held by Stripe and never by us; see Payment Processing above.
- Accounts you do not deactivate — retained for as long as the account is open. We do not delete inactive accounts on a timer, so if you want your data removed, use the route above.
Your Rights
UK GDPR Rights
If you are located in the United Kingdom, you have the following rights under the UK GDPR:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure of your personal data
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with the Information Commissioner's Office (ICO)
- Right to unsubscribe from marketing communications
US State Privacy Rights
Depending on your state of residence, you may have the following rights:
- Right to know what personal information is collected
- Right to access your personal information
- Right to delete your personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale of personal information
- Right to non-discrimination for exercising your rights
- Right to data portability
- Right to appeal if your privacy request is denied
- Right to request disclosure of information shared with third parties
Canadian Privacy Rights (PIPEDA)
If you are a Canadian resident, you have the following rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):
- Right to access your personal information held by us
- Right to request correction of inaccurate information
- Right to withdraw consent for data processing
- Right to file a complaint with the Privacy Commissioner of Canada
How to exercise these rights
Two of these rights you can exercise yourself, without asking us, from your dashboard once you are signed in. Both are in the panel headed Leaving.
- Access and portability — "Export my data" downloads a single JSON file containing your account details, every mailbox you own with its address and dates, and every message in them with its sender, subject, date and body. Where a message arrived with files attached, the export lists what arrived — the name, type and size of each one. The files themselves are never stored, so they are not in the export and we cannot supply them: what we keep is the record that they came, not their contents. API keys appear by name and last eight characters only; the keys themselves are not stored in a form anyone can recover, including us. JSON is a structured, machine-readable format, which is what the right to portability asks for.
- Erasure — "Deactivate my account" switches the account off and starts the 30 days described under Data Retention above, after which your mailboxes, your mail, your API keys and your usage records are deleted.
Two things to know before you use them. Export first. Deactivating signs you out and you cannot sign in again afterwards, so the export is not available to you once the account is off. Take the copy of your mail before you deactivate, or you will not be able to take it at all. If you have a Pro subscription, cancel it first. We will not cancel a subscription on your behalf, so deactivation is refused while you have one that is still running or has an unpaid invoice. Cancel it through Manage billing on the Pricing page, then come back and deactivate.
If you change your mind, email us within the 30 days and ask us to restore the account — there is no way to do it yourself, because signing in is exactly what a deactivated account cannot do. After the 30 days there is nothing left to restore.
To exercise any other right listed above — including correcting inaccurate data, restricting or objecting to processing, or asking what we hold if you have no account — please contact us at [email protected]. We will respond to your request within 48 business hours.
Security Measures
We implement reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit, secure server infrastructure, and access controls. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security of your data.
Children's Privacy
getrandom.email is intended for users who are at least 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information as promptly as possible. If you believe that a child under 18 has provided us with personal information, please contact us at [email protected].
Third-Party Links
Our service may contain links to third-party websites or services that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services. We encourage you to review the privacy policy of every site you visit.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this Privacy Policy periodically. Your continued use of getrandom.email after any modifications indicates your acceptance of the updated policy.
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Organization: Red Phoenix Team
- Email: [email protected]
- Response time: within 48 business hours