Back to homeLegal

Privacy

What Tempy stores, how long it keeps it, and what it never holds at all.

Last updated September 5, 2026

What we hold about you

Your email address, a hash of your password, the language you chose, your webhook URL and your signing secret. That is the entire account.

Email content is temporary

The text, HTML and headers of an inbound email exist only until its delivery finishes. Content is purged 60 minutes after a successful delivery, or 24 hours after the retry schedule ends. There is no inbox and nothing left to browse.

Delivery metadata is kept 90 days

Status, timings, the response code, the request headers we sent and a truncated response snippet stay in your log for 90 days, then are deleted. They are what lets you prove a delivery happened.

The request body is never stored

The JSON we POST to you is built, signed, sent and dropped. Only its SHA-256 is recorded — enough to prove what was signed, useless for reconstructing the email.

Attachments sit in private storage

Attachment files go to a private bucket that no URL can read directly. Every download runs through a signed link valid for 24 hours from the moment the email arrived, and the files are deleted with the rest of the content.

We never sign in to your mailbox

Tempy holds no OAuth token and no mailbox password, and makes no connection to Gmail, Outlook or any other provider. You forward mail to us; we cannot reach in.

Who else handles your data

Cloudflare receives the mail, Vercel runs the application, Supabase hosts the database and the file storage, and Stripe processes payments if you upgrade. We never see your card number, and nobody at Tempy reads email content in the course of running the service.

Cookies

Two kinds: the cookies that keep you signed in, and one that remembers the language you picked. No analytics scripts, no advertising pixels, no third-party trackers.