Legal
Privacy Policy
Last updated: April 2026
1. Introduction
2. Data controller
The data controller for the purposes of the GDPR is:
3. What data we collect
Ghostmails is designed with privacy at its core. We do not collect names, phone numbers, permanent email addresses, passwords, or payment information.
Data collected automatically:
| Data | Purpose | Retention |
|---|---|---|
| IP address | Abuse prevention, rate limiting | 48 hours max |
| Session cookie | Linking browser to inbox | 30 days |
| Temporary address | Core service | Until expiration |
| Received emails | Core service | Until address expiration |
Our advertising partner Google AdSense may collect your IP address, browser information, and device identifiers to serve and measure ads. This is governed by Google's own privacy policy and, for tracking cookies, requires your consent via our cookie banner.
4. How we use your data
- –Providing the Service — generating and managing temporary email addresses.
- –Abuse prevention — rate limiting and spam protection.
- –Service improvement — aggregated, anonymized usage patterns only.
- –Advertising — third-party ads (with your consent for tracking cookies).
- –Legal compliance — responding to lawful requests when required by law.
We do not sell or share your personal data for third-party marketing.
5. Cookies
One essential cookie is used:
| Cookie | Purpose | Duration |
|---|---|---|
| gm_session | Links browser to inbox | 30 days |
Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to Ghostmails and/or other sites on the Internet. Advertising cookies are only placed after you give consent via our cookie banner, and you can withdraw consent at any time from the cookie settings in the footer.
You may opt out of personalized advertising by visiting Google Ads Settings or opt out of third-party vendor cookies at aboutads.info. Analytics, if used, are privacy-friendly (no cookies, no personal data).
6. Data retention
| Data | Retention |
|---|---|
| Temporary email address & emails | Until expiration, then permanently deleted |
| IP address logs | Maximum 48 hours |
| Session cookies | 30 days |
7. Data sharing
- –Cloudflare — infrastructure, CDN, email routing (data processor on our behalf).
- –Google AdSense — advertising, only with your consent (see section 3).
- –Law enforcement — only when required by a valid legal order under French or EU law.
Data is not transferred outside the EEA without adequate safeguards (SCCs).
8. Your rights under the GDPR
As an EU/EEA user, you have the right to:
- –Access — request a copy of your personal data.
- –Rectification — request correction of inaccurate data.
- –Erasure — request deletion (note: data is auto-deleted on expiration).
- –Restriction — request limited processing.
- –Portability — request data in a machine-readable format.
- –Object — object to processing based on legitimate interest.
- –Withdraw consent — for advertising cookies, via cookie settings.
- –Lodge a complaint — with the CNIL (cnil.fr).
To exercise your rights: [email protected]. We respond within 30 days.
9. Security
10. Children's privacy
11. Changes to this policy
12. Contact
Questions or requests: [email protected]
Supervisory authority: CNIL — cnil.fr