Korppi Mail ("we", "the service") is a temporary email service. We are committed to protecting user privacy.
Data We Collect
We collect no personal data. No registration is required. We do not ask for your name, permanent email, phone number, or any identifying information.
Data in Memory
Email messages and mailbox data exist exclusively in volatile server memory (RAM). This data is never written to disk, databases, or permanent storage of any kind. When a mailbox expires or the server restarts, all associated data is permanently and irrecoverably destroyed.
Access Tokens
When you create a mailbox, a 512-bit cryptographic access token is generated. This token is stored on our server only as a SHA3-512 hash — we never store the raw token. The raw token is shown to you once and optionally saved in your browser's localStorage. Token comparisons use constant-time algorithms (secrets.compare_digest) to prevent timing attacks.
Logging
We do not log email content, sender addresses, recipient addresses, or message metadata to disk. Minimal operational logs (error messages, rate limit hits) may exist temporarily in server memory and do not contain email content.
IP Addresses
IP addresses are used transiently for rate limiting (stored in memory only) and are never written to disk or associated with mailboxes.
Cookies & Local Storage
We do not use cookies. Your browser's localStorage is used to save session data (email address and access token) for convenience. This data stays entirely on your device and is never transmitted to third parties. You can clear it at any time via your browser settings.
Third Parties
We do not share, sell, or transmit any data to third parties. We do not use analytics services, advertising networks, or tracking pixels. The only third-party origins our pages contact are fonts.googleapis.com and fonts.gstatic.com for typography — no tracking pixels or analytics scripts are loaded.
Data Retention
All data is destroyed when: the mailbox's configured TTL expires; the mailbox is manually deleted; or the server is restarted. There is no recovery mechanism.
Children's Privacy
This service is not intended for children under 13 years of age. We do not knowingly collect data from children. If you believe we have inadvertently received data from a child, please contact us so we can ensure the corresponding mailbox is destroyed at the next TTL expiry.
Changes to This Policy
We may update this policy. Material changes will be reflected by an updated "Effective date" at the top of this page. Continued use of the service after a change constitutes acceptance.
Contact
For questions about this policy, contact us at [email protected]. To report abuse, contact [email protected].