Temporary sessions
Addresses, access tokens, and expiry times are kept mainly in your current browser; the service processes incoming mail during the active window.
Effective date: September 1, 2026
This policy explains how ForwardEasy handles information when providing three-hour temporary email and long-term receiving addresses. We describe each feature separately rather than mixing short-lived sessions with account management data.
Addresses, access tokens, and expiry times are kept mainly in your current browser; the service processes incoming mail during the active window.
Your login email is used for code verification and forwarded mail, while each independent address is linked to your management identity.
To troubleshoot delivery, forwarding records are typically kept for up to about 30 days, then cleared on the system’s regular schedule.
You can change a temporary address, delete an independent address, leave the management area, and contact us about privacy requests.
| Data category | Purpose | Typical retention | Your controls |
|---|---|---|---|
| Temporary address, token, expiry time | Create, restore, refresh, and extend a session | Active period and necessary cleanup window | Change the address, wait for expiry, or clear browser storage |
| Temporary email content | Display genuine incoming messages in the inbox | For the life of the temporary mailbox | Delete individual messages or stop using the session |
| Login email and independent addresses | Passwordless authentication, forwarding, and address management | While the identity exists | Delete the address or submit an account request |
| Delivery records and message content | Check forwarding, spam, and failure status | Typically about 30 days | View and delete them in the management area |
| Security and request logs | Rate limiting, abuse prevention, and troubleshooting | Only as long as needed for security purposes | Rotated on expiry, except where retention is required by law |
This policy applies to temporary receiving, independent-address forwarding, delivery records, and identity verification features provided at forwardeasy.com. Third-party senders, websites you visit, and external links in emails have their own privacy practices and are not controlled by this policy.
If you use the service on behalf of an organization, make sure you have the right to provide us with the relevant receiving addresses and email data. This policy does not replace your agreements with third parties.
You do not need to submit a name or primary email address to use a temporary mailbox, but our servers must process the random address, access token, email headers, and message content. When you enter the long-term management area, we receive the email address and verification result you provide, along with the address prefix you create.
When authenticator protection is enabled, the system generates a key and verifies one-time codes. We do not ask you to provide contacts, your real name, or payment card information.
To provide network services and prevent abuse, the system may record IP addresses, timestamps, request paths, response statuses, browser types, and rate-limit events. These logs help detect attacks, troubleshoot failures, and maintain service capacity.
We do not use necessary security logs to build cross-site advertising profiles. Local browser storage helps restore temporary mailboxes and login sessions; it is not the same as a third-party advertising cookie.
When you create a temporary mailbox, the service generates an address, token, and expiry time. The token is the credential for reading that mailbox, and anyone who obtains it may see messages in the session. Do not share complete session details publicly.
When you refresh the page, your browser attempts to restore a session that has not expired. Clearing local storage, closing a private window, or accessing the mailbox from another device may remove the information needed for recovery.
Long-term access uses an email verification code instead of a password. Your login email is both the verification destination and the default forwarding recipient. Codes expire, and repeated requests may trigger cooldowns and rate limits.
Each independent address is linked to the management identity. After an address is paused, new messages may be silently discarded; after deletion, you should not rely on the original address to restore contact.
We process information to provide the services you request, including creating addresses, receiving email, forwarding messages, displaying records, providing security verification, and offering customer support. Necessary security processing is based on maintaining service integrity, preventing abuse, and protecting legitimate user interests.
Where required by law, we may process or disclose limited information to meet legal obligations. If local law requires consent, we will obtain the appropriate choice for the applicable feature.
Temporary mailboxes are designed for short-term use, and messages and sessions are not kept as permanent archives. Forwarding records support recent troubleshooting and are typically cleared in a rolling window of about 30 days; actual deletion may pass through backup rotation and security queues.
Login emails and independent addresses may be retained until the identity is deleted or deactivated for an extended period. Security incidents, disputes, or legal obligations may require related records to be preserved for a limited time.
We may use hosting, network, email delivery, and security providers to process information required to deliver the service. These providers may process information only for the agreed purposes and are bound by confidentiality and security obligations.
We do not sell temporary email content or login emails. We may disclose limited information as required by law in response to valid legal process, urgent security risks, corporate restructuring, or the need to protect rights.
Network traffic and email may cross borders, and service providers’ infrastructure may be located in other jurisdictions. We use applicable contractual and organizational measures to address the risks of international transfers.
We use access controls, transmission protection, token isolation, rate limiting, and log reviews, but no internet service can promise absolute security. Do not use temporary email to store information related to assets, health care, government services, or long-term account recovery.
You can avoid long-term access and use only the temporary features, which do not require a primary email address. You can also clear local records, delete individual messages, pause or delete independent addresses. Applicable law may give you rights to access, correct, delete, restrict, object to processing, or port your data.
When you submit a request, we may need to reasonably verify your identity to avoid disclosing information to someone without authorization. Some requests may be limited by security logs, the rights of others, and legal retention requirements.
The service is intended for users who have the capacity to provide digital consent required by local law and is not directed at children. We do not knowingly ask minors to provide their names, schools, or guardian information.
If a guardian believes a child provided personal information inappropriately, please contact us. After confirmation, we will take steps to restrict or delete it as required by applicable law.
We will update this policy and adjust its effective date when there are significant changes to features, laws, or service providers. Material changes will receive reasonable notice in a prominent place on the site; we will not present an earlier version as permanently unchanged.
For privacy questions or rights requests, email support@forwardeasy.com. Please specify whether your request concerns a temporary session or long-term access. Do not include complete verification codes, authenticator keys, or sensitive email content in your message.