Back home

Privacy guide

Useful privacy starts with honesty.

YOQMail is designed to keep low-value email away from your real address. It is not designed for confidential communication.

Public by design

YOQMail inboxes are not accounts. Anyone who knows or guesses an address may be able to read its mail.

Short-lived by default

Messages and stored attachments are automatically deleted after the configured retention window.

Tracking limited

Remote images are blocked until you choose to load them, and email HTML is sanitized before it reaches the reader.

No false promises

Never use temporary email for identity verification, financial information, password recovery, or sensitive documents.

What the service stores

To deliver the service, YOQMail stores received message headers, sanitized message bodies, basic delivery timestamps, and accepted attachments until they expire or are deleted. Operational logs may temporarily record delivery errors and abuse signals.

Inbox pages are marked so search engines should not index them. That is a crawler instruction, not an access control mechanism. Treat every temporary address as publicly discoverable.

This project includes the technical controls described here, but operators should publish their final retention period, legal entity, contact channel, and jurisdiction before launching the service publicly.

Advertising and privacy choices

YOQMail includes clearly labeled advertising locations that can help cover infrastructure costs. Development placeholders are first-party layout previews and do not contact an advertising network.

A configured third-party advertising provider is blocked until advertising consent is available through the consent layer. Optional analytics and personalization are separate choices. Necessary storage, such as remembering privacy and theme preferences, continues to work when optional choices are rejected.

The built-in development consent panel is for local design and integration testing only; it is not represented as a certified production CMP. Before enabling AdSense for applicable European traffic, the operator must configure an appropriate certified consent solution and update this notice with the provider and data-processing details.