Addresses and emails are kept for up to 24 hours, then enter the deletion process when they expire or are deleted manually.
Privacy Policy · Updated September 4, 2026
What data passes through Fwdzy—and how you stay in control
This policy covers one-time email on the website, persistent forwarding identities, recent delivery records, and passwordless sign-in. If you do not agree with these practices, do not submit a long-term receiving address or create a forwarding identity.
Delivery metadata and message bodies are kept for up to 30 days to support verification and redelivery.
Your receiving address is used to send verification codes and forwarded messages; it is never sold to advertisers.
You can pause or delete addresses, clear records, and contact us to exercise your rights.
Retention periods and limits
| Data category | Purpose | Typical retention | How it ends |
|---|---|---|---|
| Temporary addresses and incoming mail | Receive and read online | Up to 24 hours | Expiration, address replacement, or manual deletion |
| Receiving address and verification-code records | Identity confirmation and forwarding | While the account exists; security logs for as long as necessary | Account deletion or request fulfillment |
| Forwarded-mail records | Verification, spam filtering, and failed-delivery retries | Up to 30 days | Expiration or user-initiated deletion |
| Security and access logs | Abuse prevention, troubleshooting, and service protection | Limited period needed for risk management | End of the retention period or de-identification |
1. Scope
This policy applies to the temporary inbox and email forwarding services provided by Fwdzy on fwdzy.com. Third-party senders, your receiving-email provider, and websites you visit from messages handle data under their own policies.
The service is intended for people who may lawfully use email tools. It must not be used to bypass third-party rules or handle high-risk identity matters. If a workflow requires a permanent credential, use a recoverable email account that you control long term.
2. What we collect
The temporary inbox feature processes random addresses, access tokens, expiration times, and the messages and attachments delivered to those addresses. Forwarding also processes the receiving address you submit, identities you create, delivery status, and necessary anti-spam signals.
Servers may record IP addresses, timestamps, browser type, request paths, and error results to limit abuse and diagnose failures. We do not require your name, government ID number, or payment card to create a temporary inbox.
3. Why we process this data
We use relevant data to create addresses, display incoming mail, complete forwarding, verify sign-ins, provide redelivery, and carry out your deletion choices. Processing also helps maintain quotas, detect automated attacks, block malicious attachments, and protect other users.
We do not use message bodies for advertising profiles or sell receiving addresses. When we need aggregated service-reliability insights, we prefer statistics that cannot directly identify individuals.
4. Temporary email lifecycle
Temporary addresses have a clear countdown and remain available for up to 24 hours. After an address expires, is deleted, or is replaced, its old token should no longer be used to read mail.
Deletion may need to run across primary storage, caches, and backup rotations, so data may not disappear from every copy instantly. We restrict access during the waiting period and overwrite residual copies through our scheduled rotation.
5. Forwarding and recent delivery records
Messages received at a forwarding address are sent to your confirmed receiving address, while limited records are retained to verify delivery results. Records may include the subject, sender, body, attachment names, spam verdicts, and delivery errors.
The default maximum retention of 30 days does not mean we guarantee permanent archiving. Save important content in your receiving inbox and delete records you no longer need promptly.
6. Verification codes and dynamic confirmation
Passwordless sign-in uses a one-time verification code to confirm that you can access the target inbox. If you enable an authenticator, the system also processes derived verification data from the TOTP setup secret, but it does not request access to other accounts in your authenticator.
Verification codes expire and are subject to sending-rate limits. Security logs help detect replay and brute-force attempts. Never forward a verification code or one-time code to anyone.
7. Cookies and local storage
Browser local storage keeps temporary-inbox tokens, sign-in tokens, and necessary interface state so you can continue the current task after refreshing. It is not a cross-site advertising tracker and is not used to build marketing preferences.
Clearing browser data removes the corresponding tokens from this device and may prevent you from reading temporary mailboxes that have not yet expired. On shared devices, sign out and clear your data when you are finished.
8. Sharing and processors
Email delivery naturally involves the sender’s servers, network operators, and your receiving-email provider. We may also use vetted infrastructure providers for hosting, logs, backups, and security protection.
Processors may access data only as needed to provide their services and are bound by confidentiality and security obligations. We may disclose necessary information when required by law, in response to an urgent security risk, or to protect the service’s rights.
9. International transfers and security
Infrastructure may be located outside your region, so data may be transferred across borders. We combine contractual safeguards, access controls, and least-privilege measures to reduce transfer and storage risks.
No internet service can promise absolute security. We use encryption in transit, rate limiting, short-lived tokens, and isolation measures, but you should not use a temporary address for medical, banking, or government accounts.
10. Your choices and rights
The interface lets you destroy temporary inboxes, pause or delete forwarding identities, delete delivery records, and sign out. Where permitted by applicable law, you may also request access, correction, deletion, restriction, or objection to the processing of relevant personal data.
Send requests from the receiving address concerned to support@fwdzy.com so we can reasonably verify your identity. We will respond within the applicable period and may request additional information to protect others.
11. Children and abuse
The service is not directed at children and does not knowingly collect age information. If a guardian believes a child has submitted personal information improperly, they can contact us for review and deletion.
Do not use the service to harass, defraud, distribute malware, or evade law enforcement. To stop ongoing abuse, we may restrict requests and retain necessary evidence.
12. Changes and contact
We will update this policy when features, legal requirements, or providers change and will show the date at the top of the page. We will give reasonable notice of material changes, while past activity remains governed by the commitments in effect when it occurred.
Send privacy questions and rights requests to support@fwdzy.com. State whether your request concerns a temporary inbox or forwarding identity, but do not include verification codes, one-time secrets, or sensitive message content.