Privacy Policy
5 Minute Mail is built around short-lived, receive-only inboxes. It does not require an account, but operating an email service still involves message data, access tokens, network logs, and third-party infrastructure.
Data used to run an inbox
When you create a mailbox, the service generates a random address, an access token, a creation time, and an expiration time. Incoming messages can contain sender and recipient addresses, subject lines, text or HTML content, delivery time, and spam-scoring information.
The browser sends the address and token when it checks or extends the inbox. Anyone with both values may be able to read the active mailbox, so do not share them or place them in screenshots. The token is not a permanent account password.
Storage and expiration
Mailbox records and received messages are stored while the inbox is active. The default session lasts five minutes and may be extended before expiration, subject to the service limit. After expiration, the inbox and its messages are no longer available through this tool.
Do not use this service as proof of deletion from every system that handled an email. Senders, email delivery providers, security logs, and infrastructure providers may keep their own records under their policies. An expired inbox cannot erase a sender's copy.
Security and service logs
The service and its hosting, storage, and inbound email providers may process IP addresses, request times, delivery status, and error details. These records help enforce rate limits, diagnose failed delivery, prevent abuse, and keep the service available.
The website uses HTTPS between your browser and 5 Minute Mail. Email delivery before it reaches the service involves other networks and is not guaranteed to use end-to-end encryption. Treat every temporary inbox as disposable, not confidential.
Analytics
When a compatible analytics collector is configured, mailbox creation records ttl_seconds, the configured inbox lifetime in seconds at creation. When new mail is observed, a delivery event recordsmessage_count, the total messages visible in that inbox, and new_message_count, the messages newly observed in that check. The event contract intentionally excludes mailbox addresses, access tokens, sender and recipient fields, subject lines, and message bodies.
Advertising and cookies
The site includes Google AdSense code. Third-party vendors, including Google, use cookies to serve ads based on a visitor's earlier visits to this website or other websites. Google's use of advertising cookies enables Google and its partners to serve ads based on those visits.
The vendors available for ad serving depend on the site's Google ad settings, your region, and your consent choices. Google publishes an ad technology partner list with links to those providers' data-use information.
You can opt out of personalized advertising through Google Ads Settings. You can also manage participating third-party advertising vendors through YourAdChoices. See the cookie notice for more detail.
Your choices
You can avoid entering personal information in a temporary inbox, close the browser page, allow the mailbox to expire, block third-party cookies, and adjust personalized ad settings. If you need a durable address with account controls, use a permanent inbox or forwarding alias instead.
Because the service has no user accounts, it cannot locate an inbox by your name or restore an expired session. Active mailbox access requires the address and token held by the browser session.
Important limit
Do not receive passwords, financial records, medical details, identity documents, legal notices, or permanent account recovery links in a temporary inbox. Use a mailbox you control long term for any message you may need later.
Last updated August 5, 2026.