What we hold about you
Your email address, a hash of your password, the language you chose, your webhook URL and your signing secret. That is the entire account.
What Tempy stores, how long it keeps it, and what it never holds at all.
Last updated September 5, 2026
Your email address, a hash of your password, the language you chose, your webhook URL and your signing secret. That is the entire account.
The text, HTML and headers of an inbound email exist only until its delivery finishes. Content is purged 60 minutes after a successful delivery, or 24 hours after the retry schedule ends. There is no inbox and nothing left to browse.
Status, timings, the response code, the request headers we sent and a truncated response snippet stay in your log for 90 days, then are deleted. They are what lets you prove a delivery happened.
The JSON we POST to you is built, signed, sent and dropped. Only its SHA-256 is recorded — enough to prove what was signed, useless for reconstructing the email.
Attachment files go to a private bucket that no URL can read directly. Every download runs through a signed link valid for 24 hours from the moment the email arrived, and the files are deleted with the rest of the content.
Tempy holds no OAuth token and no mailbox password, and makes no connection to Gmail, Outlook or any other provider. You forward mail to us; we cannot reach in.
Cloudflare receives the mail, Vercel runs the application, Supabase hosts the database and the file storage, and Stripe processes payments if you upgrade. We never see your card number, and nobody at Tempy reads email content in the course of running the service.
Two kinds: the cookies that keep you signed in, and one that remembers the language you picked. No analytics scripts, no advertising pixels, no third-party trackers.