Privacy Policy

Boom Mail is a temporary email forwarding service. This policy describes what data we handle and how.

What we collect

When you create a temporary alias, we store your real email address in memory for the duration of the alias lifetime (10, 30, or 60 minutes). It is never written to disk, never logged, and never shared with any third party.

We store a one-way hash (SHA-256 with a secret pepper) of email addresses on our ban-list. We cannot reverse this hash to recover the original address.

Anonymous usage metrics

We collect anonymous aggregate counters — for example, the number of aliases created per day or emails forwarded — to monitor service health and operational status. These counters contain no personal data. No email addresses, IP addresses, or any other identifying information are intentionally captured or stored.

What we do not collect

We do not collect IP addresses. Our web server access log records only the timestamp, request path, and response code — no client IP addresses. Error logging is configured at a level that captures genuine infrastructure failures only, not connection-level events. We do not use cookies. We do not create accounts. We do not retain email content. Email addresses are never written to disk: they exist only in process memory during routing and are discarded when the alias expires. Redis persistence has been explicitly disabled to enforce this guarantee.

Email forwarding

Emails received by your temporary alias are forwarded directly to your real address and immediately discarded from our systems. We do not store, index, or analyse email content.

Opt-out

Each alias creation response includes a deactivation link. Clicking it immediately removes the alias. You can also simply wait for the alias to expire.

If you opt out, we store a one-way hash of your email address permanently so that we can honour your preference in future. This hash cannot be reversed to recover your address without knowledge of our secret key.

Infrastructure

The service runs on a dedicated server in France. Configuration data is stored on AWS S3 (private bucket, EU region). Secret keys are held in AWS Secrets Manager and loaded into process memory at startup only.

Contact

Questions about this policy can be sent to [email protected].

Last updated: June 2026.