Privacy Policy

Last updated: August 2, 2026

Burner Mail is an email-alias and forwarding service operated from Romania. This Privacy Policy explains what personal data we process when you visit burnermail.io or use our websites, applications, browser extensions, aliases, forwarding features, APIs, and support channels (collectively, the “Service”). Burner Mail is the controller of that personal data unless stated otherwise.

Our privacy principles

  • We do not sell or rent personal data.
  • We collect and retain only data needed to operate, secure, support, and improve the Service or meet legal obligations.
  • We do not ordinarily store the content of successfully forwarded email after delivery.
  • An alias hides your forwarding address from correspondents, but it is not a guarantee of anonymity from Burner Mail or lawful authorities.
  • Abuse reports and government demands are reviewed separately; an abuse report alone does not authorize disclosure of user data.

Data we process

Account and identity data

We process the information you provide when creating or managing an account, which may include your name, account email address, verified forwarding addresses, password hash, authentication tokens, two-factor-authentication configuration, API credentials, and account preferences.

Alias and routing data

To route mail, we process your burner addresses, custom domains, alias descriptions and status, forwarding destinations, reply/send address mappings, message counters, and related configuration. These mappings are necessary for the Service to know where a message should be forwarded and how a reply should be presented to the recipient.

Email content and metadata

The Service necessarily receives and processes message content and SMTP metadata while forwarding email. Metadata can include sender and recipient addresses, message identifiers, originating mail server information, timestamps, subject lines, and delivery status. Successfully forwarded email content is not intentionally retained as a mailbox or archive after delivery. Messages may remain temporarily in operational mail queues while delivery is attempted or an error is handled.

Ordinary internet email is not end-to-end encrypted by Burner Mail. Transport encryption may be used when supported by both mail servers, but messages can be available in plaintext while the Service processes them.

Account activity and technical data

We process account creation and update times, current and previous sign-in times, sign-in counts, subscription status, feature usage, forwarding and blocking counters, and security or abuse signals. Web, application, and mail-server logs may include IP addresses, user-agent information, request identifiers, timestamps, sender or recipient metadata, and delivery or error information.

Billing data

We process subscription status, plan information, payment-provider identifiers, billing events, cancellation information, and related records. Payment processors and app stores process payment instruments under their own privacy policies; full card details do not need to be stored by Burner Mail when the payment provider handles them directly.

Support and communications

If you contact us, report abuse, respond to a survey, or request support, we process the address, message, attachments, and other information you provide so we can respond and keep an appropriate record of the interaction.

Website analytics and cookies

We use Umami Cloud to understand website and product usage. It may process page views, referrer URLs, browser, operating system, device type, approximate country, and visit timing. When you are signed in, Burner Mail sends an internal user ID to Umami so activity can be associated with your account. We do not send your email address to Umami through this identification feature. We also use essential cookies for sessions, security, preferences, and account functionality. Our consent tooling describes additional optional cookies in use.

Service providers

Providers used by the Service currently include:

  • Akamai Cloud (formerly Linode) for United States-based production server hosting and related cloud infrastructure;
  • Umami Cloud for website and product analytics;
  • Amplitude for account-linked product events and feature analytics;
  • Rollbar for application error monitoring and diagnostic context;
  • Paddle as merchant of record for web subscriptions;
  • Apple and Google for subscriptions purchased through their app stores;
  • Cookiebot by Usercentrics for cookie-consent management; and
  • network, email-infrastructure, storage, and security providers needed to operate the Service.

These providers process only the data needed for their role and are governed by their own privacy notices as well as our agreements with them where applicable. The providers we use may change as the Service evolves; material changes will be reflected in this Policy.

Why we process data

  • Contract: to create and administer accounts, route messages, provide paid features, and provide support.
  • Legitimate interests: to secure the Service, prevent abuse and fraud, maintain deliverability, troubleshoot failures, and improve reliability.
  • Legal obligations: to comply with tax, accounting, consumer-protection, data-protection, and valid legal-process requirements.
  • Consent: where required for optional marketing, non-essential cookies, or another optional feature. You may withdraw consent at any time.

When we access or disclose data

We limit access and disclosure to the following circumstances:

  • staff and contractors who need access to operate, secure, or support the Service;
  • service providers acting for us, such as hosting, email infrastructure, payment, analytics, error monitoring, and support providers;
  • investigation and prevention of suspected abuse, fraud, security incidents, or violations of our Terms;
  • a binding request from a competent authority, or another disclosure permitted or required by applicable law; and
  • a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality and notice where required.

We review government requests for authenticity, legal validity, scope, and jurisdiction. We seek to disclose only the data legally required and may narrow or challenge requests where appropriate. More information is available in our Law-Enforcement Guidelines.

Retention

Account, subscription, alias, domain, and routing data is generally retained while needed to provide the Service. Deactivating an alias or account does not necessarily erase every record. When data is deleted, residual copies may remain for a limited period in backups or records needed for security, fraud prevention, dispute resolution, accounting, or legal compliance.

Successfully forwarded message content is not ordinarily retained after delivery. Undelivered messages and related metadata may remain temporarily in mail queues while delivery is attempted. Security, web, application, and mail logs are retained for limited operational periods and may be retained longer when associated with detected abuse, a security incident, a preservation request, or a legal obligation. Support correspondence and legally required billing records may be retained for as long as reasonably necessary for those purposes.

Aggregated or de-identified information that no longer identifies a person may be retained for analytics, security, and service-improvement purposes.

International processing

The Service’s production server is hosted in the United States on Akamai Cloud infrastructure (formerly Linode). Account, alias and routing data, technical logs, and email content and metadata handled while messages are forwarded may therefore be processed in or transferred to the United States. Other providers that support the Service may also process data outside Romania or the European Economic Area.

Where required, we use contractual and other safeguards recognized by applicable data-protection law for restricted international transfers, including standard contractual clauses where applicable. Akamai may be subject to valid United States legal process and could be required to provide data it controls independently of a request made to Burner Mail. We may not receive notice of, or be able to challenge, legal process served directly on a service provider.

Security

We use technical and organizational safeguards intended to protect data in transit and at rest, restrict administrative access, authenticate users, and detect misuse. No internet service is completely secure, and we cannot guarantee that unauthorized access, loss, or interception will never occur.

Your rights

Subject to applicable law, you may request access to, correction of, deletion of, or restriction of your personal data; object to certain processing; request data portability; or withdraw consent. You may also lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing or the competent authority where you live.

We may need to verify your identity before completing a request. Some rights are limited where we must retain data to meet a legal obligation, protect other people, prevent fraud, establish legal claims, or preserve the integrity of the Service.

Changes to this Policy

We may update this Policy to reflect changes to the Service, law, or our practices. We will provide reasonable notice of material changes through the Service or by email.

Contact

Privacy questions and rights requests may be sent to contact@burnermail.io. Please use the subject “Privacy request” and do not send passwords, authentication tokens, or unnecessary sensitive information.