๐Ÿ” Security & Privacy

Email validation without compromising user privacy.

TempMailChecker is built for businesses that take data protection seriously.

๐Ÿงพ What data we process

TempMailChecker only needs the domain part of an email to determine if it's disposable.

When you call our API:

GET /check?email=user@example.com
โ†“

We internally convert this request to:

example.com

We never store, log, or inspect the full email address.

๐Ÿ—‚ What we do NOT collect

We do not store:

  • Full email addresses
  • Usernames / first name / last name
  • IP addresses
  • User agent strings
  • Referrer headers
  • Request contents beyond the domain
  • Email content of any kind

We also do not share data with any third parties.

๐Ÿง  What we DO store

To enforce daily quotas fairly and detect abuse, we store:

Data Reason
API key hash Identify your account securely
Email (from signup form only) Send onboarding + limit alerts
Request count per day Reset quota at midnight UTC

We do not store request history.

๐Ÿ”’ API key security

  • API keys are hashed (bcrypt) before storage
  • Keys are never logged
  • Keys are never shown again after creation
  • You can regenerate your key instantly at any time

๐Ÿ”Ž Logging

API request logs contain zero sensitive information.

A typical request log looks like:

[OK] 200 โ€” API key XYZ โ€” 3.7ms

No emails. No domains. No metadata tied to your users.

๐Ÿ” Transport security

  • HTTPS enforced (TLS 1.2+)
  • HTTP requests are permanently redirected to HTTPS
  • HSTS enabled

๐ŸŒ GDPR / CCPA Friendly

Because we don't store personal data, TempMailChecker is naturally compliant with:

โœ“
GDPR
โœ“
CCPA
โœ“
HIPAA*
โœ“
SOC 2

*Email validation context only

No DPA is required, because no personal data is retained.

๐Ÿงฏ Data retention

We retain only:

Data Retention
API usage counters Reset daily
API signup email Until deletion request

You can delete your account fully at any time.

๐Ÿ›ก Responsible Disclosure

๐Ÿ›

Found a vulnerability?

Email us at security@tempmailchecker.com โ€” we respond within 24 hours.

Bug bounties will be added after public launch.

๐Ÿง˜ Summary

For non-technical decision-makers:

Concern Status
Do you store full emails? โŒ No
Can you see my users? โŒ No
Do you sell or share data? โŒ Never
Is everything encrypted? โœ… Yes
Is TempMailChecker GDPR-compliant? โœ… Yes
Do we need a DPA? โŒ No personal data stored

Block disposable emails without storing user data.

Get your free API key โ€” 100 requests/day, no credit card.

๐Ÿš€ Get Free API Key