grabmail.io

Privacy

A short page, because the honest version is short. The best way to protect data is not to hold it.

Last updated 4 August 2026

What we hold

Messages sent to your address
The whole message, including headers and attachments, for 5 days. Then it is deleted.
The address itself
Only for as long as it has a message. When the last one expires, nothing records that the address was ever used.
The sending server’s address
Kept with the message, because it is part of the message and because abuse reports are unanswerable without it. It goes when the message goes.
Custom domains
The domain, its key and its billing record, for as long as the subscription lasts.

What we do not hold

Not as a policy that could be relaxed later — these things are never collected, so there is nothing to hand over, leak or sell:

  • No accounts on public domains. No name, no password, no email address of yours.
  • No analytics. No Google Analytics, no Plausible, no pixel, no fingerprinting.
  • No third-party scripts. Every file this site loads comes from this site. Nothing else is contacted while you read it.
  • No advertising identifiers, and no data sold or shared with a broker. There is no second business model here.
  • No cookies — which is why there is no cookie banner. The address you picked is kept by your own browser for the tab’s lifetime and never sent to us as a cookie.

Public mailboxes are public

The most important sentence on this page: on a public domain, anyone who knows or guesses an address can read that mailbox. Through the website, through the API, from anywhere.

That is not a weakness to be fixed; it is what a shared, account-free service is. Treat a public address as a postcard on a noticeboard. If a message must be private, point your own domain here — those mailboxes answer to your key alone.

Server logs

Our servers keep operational logs — connections, errors, the ordinary record any mail server needs to work and to be debugged. They are used for keeping the service running and for handling abuse, and for nothing else.

Logs are short-lived and rotated. They are not joined to message content, not used to profile anyone, and not shared.

Who else is involved

A content delivery network
Sits in front of the website and sees requests for pages, as any CDN does. It never sees the mail path — messages reach us over SMTP directly.
Nobody else
No analytics provider, no advertising network, no support platform, no data processor with a copy of your mail.

Your rights, practically

Data-protection law gives you rights of access, correction and erasure. Here is what each means in practice, honestly:

Access
Open the mailbox. Everything we hold about a public address is on that page — there is no shadow record behind it.
Erasure
Delete the message, from the inbox or through the API. It is gone, and it was going anyway within 5 days.
Correction
Not applicable to received mail: we would be altering a message someone else sent you.
Identification
We cannot tell you who used an address, because we never knew. For the same reason nobody else can obtain that from us.