Privacy Policy
Last updated: 6 August 2026.
Most privacy pages describe intentions. This one answers the questions people actually ask when they are deciding whether to trust a free inbox, and every answer was checked against the running system rather than against a template.
Do you know who I am?
No, and there is nowhere to put the answer if we did.
We hold no name, no phone number, no billing detail and no verified identity of any kind. A guest gives the service nothing at all: you arrive, an address appears, mail lands in it. The only thing tying today's visit to yesterday's is a random string in your browser, generated here, meaningless to every other site on the internet.
Do you have my IP address?
Not in any lasting form.
There is no column for one anywhere in the database: not on inboxes, not on messages, not on accounts. The web server in front of the application has no logging turned on, so no file records which page was fetched from which address at which second. That is unusual, and worth saying out loud, because keeping those logs for months is the industry default rather than the exception.
The rate limiter, the thing that stops one visitor demanding a thousand addresses a minute, counts in memory and writes nothing to disk. Restarting the application wipes it.
What that does not mean is that you are invisible. Read the next answer before you conclude otherwise, and then read what a throwaway address really hides, which is a longer treatment of the same question.
Then who does see me?
Four companies, and they see different slices.
Cloudflare stands in front of this site: it accepts the connection, filters attacks and serves cached files. It therefore sees the address of every visitor and holds traffic statistics we can look at as counts and graphs. That handling runs under Cloudflare's own privacy terms, not ours.
Cloudflare Turnstile guards the registration and password forms by watching for signs of automation in the browser. It does not ask you to identify traffic lights and its verdict is not fed into any advertising profile.
Amazon SES carries password reset messages, and only those, from a separate sending domain.
Google supplies the advertising through AdSense and the visitor counts through Analytics.
What do you keep while I use it?
Four things, and each has a reason attached.
The address, because mail arriving somewhere needs a somewhere. The browser identifier described above, so the inbox is still there when you return. The messages themselves, with their sender, subject, headers, body and attachments, held so they can be shown to you. And for an account, an email address and a password hash, where the password itself is never written down and cannot be reconstructed from the hash.
Message content is not read to target advertising, not sold and not handed to anyone.
What do the visitor counts contain?
Events, never content.
The counter is told that an address was issued, that an address was copied, that a message arrived, that somebody registered or signed in. Every one of those is a number with a timestamp. The address itself never goes to analytics, and neither does any part of a message: not the sender, not the subject, not a line of the body, not a filename.
How long does any of it live?
A guest inbox and everything in it are deleted twenty four hours after you last touched it, and immediately when you ask for a new address.
With a free account an inbox survives seven days from your last sign in, an individual message is kept up to thirty days inside that, and an attachment lives exactly as long as the message it arrived with.
Deletion here means the row is gone. Nothing is archived, nothing is backed up, no copy is set aside for analysis. Once the cleanup has run, that message cannot be produced for you, for an advertiser, or for anybody arriving with a demand.
That arrangement suits both sides. You get a service that cannot leak what it does not hold. We get to run a mail system without accumulating a warehouse of other people's correspondence, which is the single largest liability anyone in this position can carry.
Can somebody else read my mail?
If it is a guest inbox: yes, anyone who types the address into this site.
There is no password on a guest inbox and there cannot be one without turning it into an account. That is a design decision, not an oversight, and the practical consequence is simple. Treat guest mail as readable by strangers, and put anything you would mind a stranger reading behind an account, where the inbox belongs to you alone.
What about cookies?
AdSense and Analytics both set them. Google and its partners may use them to show advertising based on your earlier visits here and elsewhere.
You can switch personalised advertising off at Google Ads Settings, or block the cookies in your browser, and the inbox works exactly the same either way. Nothing on this site asks you to accept a cookie before you can read a page or receive a message.
I am in the EU. What are my rights?
The ones the GDPR gives you: to ask what personal data is held about you, to have it corrected or erased, and to complain to your national supervisory authority.
For guest use the honest answer is that there is almost nothing to ask about: an address, its messages and a random browser identifier, all of which delete themselves without anyone doing anything. If you hold an account, deleting it from your settings removes the email address, the password hash and every inbox and message attached to it in one action. That is faster than any letter and needs no intermediary.
Do children use this?
Not with our knowledge, and the service is neither built nor advertised for them. We hold no information about anyone under 13 knowingly. If you believe a child has registered, write and the account goes.
Will this page change?
When it does, the date at the top changes with it, and a change in what is collected is described here in sentences rather than absorbed quietly into a list.
Questions: hello@crazymailing.com or the contact page.
Read next
What Is a Disposable Email Address?
Five names, three different technologies. What a disposable address really is, who controls it, and how long each kind survives.
Burner Email Addresses
People want four different things when they ask for a burner email. Which one fits your situation, and where a burner is the wrong answer.
Temporary Email and Permanent Email Are Not Rivals
A permanent address collects senders for years and cannot be taken back. A temporary one ends the same day. The difference is not privacy talk, it is who holds the string afterwards.