The address, token, and emails expire when the validity period ends or you switch inboxes.
Privacy boundaries · Updated September 5, 2026
We process only the data needed to deliver your email
This policy explains what data OnceFwd processes when providing disposable inboxes and long-term forwarding aliases, how long we keep it, and how you can request access or deletion.
Used to show delivery status, subject lines, senders, and retry failures.
Control is confirmed with a six-digit code sent to your receiving email address.
We do not base our business model on selling personal data or creating cross-site advertising profiles.
| Data category | Purpose | Typical retention | After expiry |
|---|---|---|---|
| Disposable addresses and emails | Create, refresh, and read short-lived inboxes | While the mailbox is valid | Deleted after expiry or when you switch inboxes |
| Receiving email and aliases | Verify identity and provide long-term forwarding | While the account is in use | Cleared when the account or entry point is deleted |
| Delivery metadata and message content | Display records, troubleshoot, and retry delivery | Up to 30 days | Deleted on a rolling basis |
| Security and rate-limit logs | Prevent abuse and diagnose unusual requests | The necessary short-term window | Aggregated or deleted |
1. Scope
This policy applies to disposable email, alias forwarding, delivery archives, and account security features on oncefwd.com. Emails sent from third-party websites and their links are the responsibility of those third parties; their privacy practices are not controlled by this policy.
When you submit a OnceFwd address to another website, that website may independently record the address, device, or signup activity. Please also read the destination website's privacy notice and avoid submitting sensitive information on untrusted pages.
2. Data we process
Disposable email requires us to process random addresses, access tokens, expiration times, and the contents of emails sent to the address. Long-term features also process your receiving email address, created public entry points, delivery status, and authenticator status.
To keep the service stable, we may briefly record IP addresses, request times, browser types, and error events. Logs are used for rate limiting, security investigations, and troubleshooting—not to build cross-site advertising profiles.
3. Purposes and legal bases
Core data is used to carry out the receiving, forwarding, viewing, and deletion actions you request. Security logs are processed on the legitimate interest of protecting the service, users, and network from abuse.
If the law requires a different legal basis, we will obtain consent or meet our legal obligations when necessary. You can stop using a disposable address or delete a long-term entry point to end the related processing.
4. Disposable email
Disposable addresses are available for three hours by default, and you can extend their validity using the page's extension feature. Switching addresses creates a new mailbox; the old mailbox's token and emails do not carry over to the new task.
Disposable email is suitable for short-term signups and verification codes, but not for medical, financial, employment, or account-recovery use. After expiration, we cannot guarantee recovery of the address, emails, or access.
5. Long-term entry points and delivery
Entry points created after login forward incoming messages to your verified receiving email address. When you pause an entry point, new messages are discarded and will not be forwarded or generate a bounce guarantee.
You can copy, pause, or delete each entry point. Deletion cannot be undone; whether the same prefix can be used again depends on system security and retention rules.
6. Email records and message content
Long-term delivery records are retained for up to 30 days so you can check subjects, senders, processing status, and failure reasons. Records may include message content and attachment details because these are required for reading and retry features.
Records are deleted on a rolling basis after the retention window ends. We may also remove malicious content, oversized attachments, or data that threatens system security earlier.
7. Verification codes and authenticators
Login codes are used only to confirm that you control the receiving email address and are given a short validity period. We do not require an account password, and verification emails will never ask for payment or an existing password.
When two-step verification is enabled, the service stores the key material needed for verification. Before recovering or replacing a device, make sure you can still access your account; otherwise, you may be unable to complete the second verification step.
8. Cookies and local storage
The page may use your browser's local storage to save disposable email tokens, login tokens, interface settings, and the read status of demo emails. This keeps your session active and prevents your current task from being lost on every refresh.
You can clear this data in your browser settings, but doing so immediately removes the local credentials for the associated mailbox or login session. The deployment environment may automatically add aggregate visit analytics; check what the page actually loads for the current setup.
9. Sharing and processors
We allow service providers to process data only when necessary for hosting, network delivery, security protection, or legal compliance. Processors may act only under our contract and instructions and must meet corresponding confidentiality and security obligations.
We do not sell personal data. If there is a reorganization, merger, or asset transfer, data may be transferred with the service, but it will remain subject to the privacy commitments in effect at that time.
10. Security measures
We use access tokens, least-privilege controls, transmission protection, rate limiting, and dynamic authenticator codes to reduce the risk of unauthorized access. No internet system can guarantee absolute security, so important accounts should not rely on disposable email.
If you discover unusual access, suspicious email, or a potential vulnerability, do not disclose sensitive details publicly; contact support directly. We will assess the impact and take any required notification steps under applicable law.
11. Your choices and rights
You can delete emails, entry points, and delivery records in the interface, and you can request access to, correction of, or deletion of data associated with your receiving email address. We may first verify control of the address to avoid giving data to the wrong person.
Some logs may be retained for a limited period for security, dispute handling, or legal obligations. After verification, we will explain what we did or the specific reason why something cannot be deleted immediately.
12. Contact and policy updates
Please send privacy requests to support@oncefwd.com, including the associated email address and type of request. Do not send verification codes or account tokens by email. We will respond within a reasonable period.
We will update the date on this page when features, regulations, or processing practices change. Significant changes will be explained through page notices or other appropriate means; please review the latest version before continuing to use the service.