Privacy Policy
Last updated: July 15, 2026
Who we are
QaviMail (“we”, “us”) operates the disposable email service at qavimail.eu.cc. Contact: support@qavimail.eu.cc.
What we collect
- Account data — email address (when you sign up) and a hashed recovery key. We never store your recovery key in plain text.
- Mailbox data — the temporary addresses you create and messages inbound providers deliver to them.
- Technical logs — IP address, user agent, and timestamps, retained for up to 30 days for abuse prevention.
- Billing data — for paid plans, handled by our payment processor (Paddle). We store only order metadata, never card numbers.
What we do not collect
No advertising cookies, no third-party analytics that profile individuals, no cross-site tracking pixels.
Retention
- Guest mailboxes expire and are permanently deleted within their stated TTL (typically 24 hours).
- Messages older than the mailbox lifetime are purged automatically.
- Deleted accounts and their mailboxes are removed within 30 days.
Your rights (GDPR / UK GDPR)
You can access, export, correct, or delete your data at any time from your dashboard, or by emailing privacy@qavimail.eu.cc. You may also lodge a complaint with your local supervisory authority.
Sub-processors
- Supabase (managed Postgres, auth, storage) — EU region.
- Cloudflare (CDN, email routing).
- Paddle (billing, only for paid plans).
Cookies
We use a single first-party session cookie required for authentication, plus localStorage for UI preferences (theme, sound). No consent is required for strictly necessary storage under ePrivacy. See our Terms.
Changes
Material changes are announced on this page and dated above.