Privacy Policy
Last updated: 6 August 2026.
Most privacy pages describe intentions. This one answers the questions people actually ask when they are deciding whether to trust a free inbox, and every answer was checked against the running system rather than against a template.
Do you know who I am?
No, and there is nowhere to put the answer if we did.
We hold no name, no phone number, no billing detail and no verified identity of any kind. A guest gives the service nothing at all: you arrive, an address appears, mail lands in it. The only thing tying today's visit to yesterday's is a random string in your browser, generated here, meaningless to every other site on the internet.
Do you have my IP address?
Not in any lasting form.
Nowhere in the database is there a column to hold one: not against inboxes, not against messages, not against accounts. Access logging is switched off in the web server sitting ahead of the application, so no file on disk records that a particular page went to a particular address at a particular second. Worth saying out loud, because retaining those logs for months is what the rest of the industry does by default.
Abuse throttling works the same way. What stops one visitor claiming a thousand addresses inside a minute is a counter held in the memory of the running process. It never touches disk, and every restart of the application wipes it back to nothing.
What that does not mean is that you are invisible. Read the next answer before you conclude otherwise, and then read what a throwaway address really hides, which is a longer treatment of the same question.
Then who does see me?
Four companies, and they see different slices.
Cloudflare sits ahead of this site, terminating the connection, screening out attacks and returning cached files. Every visitor's address passes through it as a consequence, and it keeps traffic statistics that reach us as counts and graphs rather than as records of individuals. Cloudflare's own privacy terms govern that, not this page.
Cloudflare Turnstile guards the registration and password forms by watching for signs of automation in the browser. It does not ask you to identify traffic lights and its verdict is not fed into any advertising profile.
Amazon SES carries password reset messages, and only those, from a separate sending domain.
Google supplies the advertising through AdSense and the visitor counts through Analytics.
What do you keep while I use it?
Four things, and each has a reason attached.
The address, because mail arriving somewhere needs a somewhere. The browser identifier described above, so the inbox is still waiting when you come back. The messages, meaning the sending address and display name, the subject, the text and HTML bodies, the size, the time of arrival and any attachments, all of it held for the single purpose of showing it to you. And on an account, an email address and a password hash: your actual password is never recorded anywhere, and the hash it leaves behind cannot be turned back into it.
None of the mail is mined for advertising, offered for sale, or passed to anybody outside.
What do the visitor counts contain?
Events, never content.
What the counter receives is five facts: an address got issued, an address got copied, mail turned up, somebody registered, somebody signed in. Each one leaves a tally mark with a time against it and nothing else. Analytics never learns the address, and no fragment of a message ever reaches it either. Not who sent it. Not what it was called. Not one line of the body, and not the name of a single attached file.
How long does any of it live?
Twenty four hours after you last touched a guest inbox, it and its entire contents are deleted. Request a fresh address and its predecessor goes at that instant instead, with no grace period in between.
Hold a free account and an inbox stretches to a week past your most recent sign in, with any single message capped at thirty days inside that, and an attachment living precisely as long as the message that carried it.
Deleted here means the row has gone. No archive, no backup, no copy set aside for later analysis. After the sweeper has passed, there is no version of that message left to hand to you, to an advertiser, or to anyone turning up with a demand for it.
That arrangement suits both sides. You get a service that cannot leak what it does not hold. We get to run a mail system without accumulating a warehouse of other people's correspondence, which is the single largest liability anyone in this position can carry.
Can somebody else read my mail?
If it is a guest inbox: yes, anyone who types the address into this site.
Guest inboxes carry no password, and adding one would simply make them accounts, which is the point of accounts. This was decided deliberately rather than overlooked, and what follows from it is straightforward. Assume a stranger could be reading guest mail, and move anything you would rather they did not see behind a sign in, where an inbox answers to its owner and to nobody else.
What about cookies?
AdSense and Analytics both set them. Google and its partners may use them to show advertising based on your earlier visits here and elsewhere.
Personalised advertising can be turned off from Google Ads Settings, and the cookies themselves can be blocked in your browser. The inbox behaves identically in either case. No page here holds a message or an article hostage behind a consent click before it will show you anything.
I am in the EU. What are my rights?
The ones the GDPR gives you: to ask what personal data is held about you, to have it corrected or erased, and to complain to your national supervisory authority.
For guest use the honest answer is that the subject matter barely exists: one address, its mail, and a random browser identifier, every piece of which erases itself on a timer with nobody lifting a finger. Account holders have a delete button in their own settings, and pressing it takes out the registered address, the stored hash, and every inbox and message hanging off the account, in a single operation. No letter, no intermediary, and no waiting on us.
Do children use this?
Not with our knowledge, and the service is neither built nor advertised for them. We hold no information about anyone under 13 knowingly. If you believe a child has registered, write and the account goes.
Will this page change?
Whenever it does, the date at the head of the page moves to match. If what we collect ever changes, that change gets written out here in plain sentences rather than slipped quietly into the middle of a list.
Questions: hello@crazymailing.com or the contact page.
Read next
What Is a Disposable Email Address?
Five names, three different technologies. What a disposable address really is, who controls it, and how long each kind survives.
Burner Email Addresses
People want four different things when they ask for a burner email. Which one fits your situation, and where a burner is the wrong answer.
Email Masking and Relay Services
Apple, Firefox, DuckDuckGo and password managers all hide your address differently. What each one covers, what forwarding does to authentication, and where each one breaks.