Legal
Privacidad
Esta política explica los límites y responsabilidades que mantienen el servicio seguro.
What Free Domain Mail does
Free Domain Mail only receives email; it never sends or forwards mail on your behalf except account mail (verification, password resets) and support replies, both sent through Resend.
What we store
We store your account email address and password hash, the domains you connect, messages received during their retention period, hashes of any API keys you create, and IP-based rate-limit counters and security logs used to keep the service safe.
What we do not store
We never store the content of attachments — only their file name, size and type. We do not sell your data to third parties.
Service providers we use
We use a VPS host to run the application and receive mail, Resend to deliver account emails, Cloudflare Turnstile to filter automated abuse, and Google Analytics, when it is enabled, to understand traffic to public pages.
Paid plans are sold through Paddle.com, which is the Merchant of Record and payment processor for our orders. Paddle collects your payment details directly; we never receive or store card numbers.
To set up a purchase, we send Paddle your account email address and an internal account ID, so that Paddle can identify you as a customer and the resulting subscription can be linked back to your account.
From Paddle we receive and store your Paddle customer ID and subscription ID, the plan status, billing interval, number of domains, price, the end of the current billing period, any scheduled changes (such as a cancellation), and the payment amounts and totals reported in Paddle's notifications, so that we can provide the service you paid for.
Error and usage diagnostics
To find and fix errors and the places where people get stuck, we record limited diagnostics when you use our app, including its sign-in and registration pages, and when you use the temporary inbox on our homepage. If you open other pages from the temporary inbox during the same visit, those pages may also send diagnostics until you reload or leave the site. Other public pages, such as guides and tools, do not send them when you open them directly.
We record: the page path (without query string or fragment, with IDs and email addresses replaced by placeholders); the names of steps and actions, such as opening an inbox or copying a code; error messages and the place in our code where they happened, with personal data removed (email addresses are masked, long numbers and anything that looks like a code or token are replaced); the method, path, status and how long it took for requests that fail or are very slow; repeated rapid clicks on the same button or link (the element type and a short label); your browser's user-agent; and a random session ID created for each browser tab and kept in sessionStorage. Errors on our servers are recorded with the route, status and error type.
When you are signed in to the app, these events are linked to your account on our servers through your existing sign-in session. Events sent before you sign in, for example from the sign-in or registration page, are not linked to an account. Diagnostics from the temporary inbox are not linked to any account, even if you are also signed in.
We never record the content or subject of messages, anything you type into forms, passwords, API keys, one-time codes, verification, password-reset or magic-link URLs and tokens, cookies, or Authorization headers.
These diagnostics are first-party: they are sent only to our own servers and are not shared with analytics or advertising companies. No cookies are set for them, and we do not fingerprint your device or browser.
Raw diagnostic events are deleted after 30 days. Error summaries and daily totals are kept for up to 1 year, and internal alerts for 90 days. Alerts go to the operator (for example through Telegram) and contain error summaries, page paths and counts; any email address in them is masked.
To check that public temporary inboxes keep working, our servers regularly send test messages to random fdm-sentinel-… addresses on our own public temporary domains. These messages contain no user data.
Public mailboxes
Messages sent to a public temporary address on freedomainmail.info or freedomainmail.link can be read by anyone who knows that address; treat them as public, not private.
Deletion
Public mail is deleted automatically 10 minutes after it arrives. Custom-domain mail is deleted automatically after 30 days. Deleting a domain or your account deletes the associated mail, API keys and settings.
Retención y límites
Free Domain Mail solo recibe correo: nunca lo envía ni lo reenvía en tu nombre. Las direcciones temporales públicas se eliminan a los 10 minutos; el correo de dominio propio se conserva 30 días. Los adjuntos nunca se almacenan, solo su nombre, tamaño y tipo.
Contacto y abuso
Security reports: security@freedomainmail.com
Abuse reports: abuse@freedomainmail.com
Support: support@freedomainmail.com