Privacy Policy · Updated September 4, 2026

Clear data boundaries for email testing

This policy applies to the disposable inboxes, forwarding dashboard, and support services at forwardtop.com. It explains what we process, why we process it, how long we retain it, and how you can control your data.

Data retention at a glance

The retention period starts when the relevant data is stored in the service. Security incidents, disputes, or legal obligations may require us to retain it longer when necessary.

Data category Primary use Typical retention Your controls
Temporary address and incoming email Receive, display, and delete test email While the address is active, up to 24 hours Replace the address or destroy the inbox
Forwarding delivery records Troubleshooting, retries, and spam classification Rolling 30-day retention Delete an individual record or clear all
Authentication and security logs Abuse prevention, rate limiting, and session security Usually no more than 90 days Request access or deletion
Support correspondence Answer questions and retain relevant context Up to 12 months after the issue is closed Ask support to delete it

1. Scope and roles

ForwardTop is the data controller for this website's services. Contact us at support@forwardtop.com. This policy does not cover the sender's website, email provider, or third-party pages you access through email.

Before sending third-party test data to this site, make sure you have the right to do so. If you use the service on behalf of an organization, that organization may also have independent responsibility for personal data in the email.

2. Data we collect

The temporary service processes random email addresses, access tokens, email headers, message content, attachments, arrival times, and deletion status. The forwarding feature also processes your receiving address, alias prefix, delivery results, and security settings.

We also receive the IP address, time, User-Agent, and necessary error logs provided by your browser. This technical information helps with rate limiting, security investigations, and service stability.

3. Purposes and legal bases

We create inboxes, display incoming messages, forward email, and verify logins to provide the requested service. To prevent spam delivery, attacks, and automated abuse, we process limited logs based on our legitimate interest in protecting the service and its users.

We may retain relevant records when required by law or while handling a dispute. Unless we obtain separate, explicit consent, we do not use email content for marketing or cross-site behavioral profiling.

4. Disposable inboxes

Temporary addresses are active for 3 hours by default and can be extended up to a maximum of 24 hours. The access token is the key to the inbox; anyone who obtains it may be able to read its messages, so do not share it publicly.

After expiration, normal access stops and the inbox enters the cleanup process. Do not use a temporary address for financial, medical, work, or any account that requires long-term recovery.

5. Login, aliases, and delivery records

The dashboard uses email-code login instead of traditional passwords. The code verifies that you can receive messages at the target address, while the active session token is stored in your current browser.

Messages sent to an alias are forwarded to a verified receiving address, with delivery records kept for up to 30 days. After an alias is paused, new messages are discarded and not forwarded.

6. Two-step verification

When you enable two-step verification, we generate a secret key and QR code for use with an authenticator app. Keep the key secure; anyone who obtains it may generate valid one-time codes.

The service stores the encrypted configuration and enabled status needed for verification. Before turning off two-step verification, you must submit the current one-time code again to reduce the risk of session hijacking.

7. Cookies and local storage

This site uses browser local storage to save temporary email tokens, login sessions, and essential interface state. This lets you restore the inbox or login status after refreshing the page.

We do not rely on third-party advertising cookies. Clearing site data logs you out of the dashboard and may prevent an unexpired temporary inbox from being restored.

8. Sharing and service providers

We disclose only the data needed to perform their tasks to providers of hosting, network protection, email transmission, and incident monitoring. Providers are bound by contractual, confidentiality, and security obligations and may not use email content independently.

We may also disclose limited information as required by law when valid legal process applies, to protect user safety, or when necessary to investigate serious abuse. We do not sell personal data.

9. International data transfers

Our service infrastructure may be located outside your country or region, so data may be transferred across borders. We use contractual clauses, access restrictions, and other appropriate safeguards in accordance with applicable law.

Data protection rules may differ between jurisdictions. Contact support to learn about the primary processing locations and safeguards relevant to your request.

10. Security measures

We use encryption in transit, access controls, rate limiting, short-lived tokens, and log reviews to reduce risk. No internet service can guarantee absolute security, so avoid sending production keys, identity documents, or highly sensitive information.

If we discover a security incident that may affect you, we will assess its impact and notify affected users or supervisory authorities as required by applicable law. You can send suspected activity to our support email.

11. Your rights

Where applicable law allows, you may request access to, correction or deletion of, restriction of processing of, or a copy of data about you. We may need to verify your identity through the receiving email address or another reasonable method.

Some requests may be limited by security, anti-fraud measures, legal retention requirements, or other people's rights. If we cannot fully comply, we will explain why and identify available complaint channels.

12. Children, changes, and contact

This service is not intended for children below the applicable legal age and must not be used to collect children's sensitive information. If you believe a child's data was mistakenly sent to this site, contact us immediately.

When this policy changes materially, we will update the date at the top of the page and provide notice in a reasonable location. Send privacy questions, rights requests, and complaints to support@forwardtop.com.

If a translated version of this policy differs in interpretation from the Chinese version, we will resolve the difference in light of applicable law and users' reasonable expectations, without using language differences to limit statutory rights.