Privacy Policy
Effective date: 27 July 2026
1. Who We Are
Batuhan Torun, an individual developer located in Antalya, Türkiye, is the data controller for Temp Mail – Test Email (the “App”, “we”, “us”, or “our”).
Contact: novidoc.support@gmail.com
This city-level location and email address are provided as our public contact details. You may contact us by email for privacy requests or legal notices.
2. Scope and Important Information About Temporary Email
This Privacy Policy explains how personal data is handled when you use the App, including its temporary-mail service, advertising, subscriptions, diagnostics, and support features.
The App does not require you to create a user account with us. It generates temporary email addresses and lets you retrieve messages sent to those addresses. Email messages may contain personal data about you, the sender, or other people. Do not use a temporary mailbox for confidential, financial, medical, government, legal, account-recovery, or other sensitive communications. Temporary addresses may expire, be recycled, guessed, or become accessible to someone else.
If you provide another person's personal data through the App, you are responsible for having a lawful reason to do so.
3. Data We Process
3.1 Temporary mailboxes and messages
To provide the temporary-mail service, the App processes:
• the generated mailbox login, domain, full temporary email address, creation time, active or archived status, and any mailbox label you add;
• message identifiers and dates, sender information, subject lines, message bodies in text or HTML form, read or deleted status, and one-time passwords or verification codes extracted on your device.
Mailbox labels, App preferences, and downloaded mailbox data are stored in the App's private storage on your device. To generate mailboxes and retrieve mail, the App sends the relevant mailbox login, domain, message identifier, and message request to the temporary-mail API at api.novidoc.com. We operate this API on Contabo infrastructure located in the European Union. The API and its hosting infrastructure necessarily process ordinary network information, such as an IP address, while handling a live connection. We do not use Netdata to store visitor IP addresses, request paths, mailbox addresses, or other request-level personal data. Our completely self-hosted Netdata installation stores only aggregate infrastructure measurements such as CPU usage, memory usage, and traffic volume. Netdata does not receive information as a separate cloud provider.
We do not create or retain permanent mailbox accounts or a separate database of generated email addresses on the server. During a message's one-hour server lifetime, however, its recipient temporary address is necessarily processed as part of SMTP delivery, message routing, and the API search used to retrieve that message. The recipient address is deleted from the server together with the message.
The current Service does not support email attachments. We will update this Policy before enabling attachment retrieval or storage.
We use this data to generate temporary addresses, retrieve and display messages, prevent abuse, protect the service, diagnose failures, and maintain service reliability. The legal bases are performance of the service you request and our legitimate interests in operating and securing it, or the corresponding legal grounds under applicable Turkish law.
3.2 App preferences and technical information stored on the device
The App stores settings such as language, region, theme, first-launch status, and App version/build information in its private on-device database. We use this information to remember your choices, display the correct interface, manage updates, and troubleshoot compatibility. This data is normally not sent to us unless it appears in a diagnostic event or you include it in a support message.
3.3 Crash reports and performance monitoring
We use Sentry, configured with its European data region in Germany, to identify crashes, errors, slow operations, and performance problems. Depending on the event and SDK configuration, Sentry may process:
• error messages, exception details, stack traces, and breadcrumbs describing technical actions before an error;
• App version, build, environment, operating-system and device information;
• performance transactions, spans, and timing information; and
• network connection information, such as an IP address, processed by Sentry's infrastructure.
We do not intentionally assign your name or personal email address as your Sentry user identity. Error details can nevertheless contain request URLs, temporary mailbox identifiers, or other values present in the failing operation. We use data-scrubbing controls designed to prevent message bodies, attachment contents, full mailbox addresses, and authentication secrets from being stored in diagnostic events.
We use this information for our legitimate interests in maintaining security, stability, and performance, subject to your rights and any consent required by local law.
Sentry retains these diagnostic events for 30 days under our Developer plan.
3.4 Advertising
The free version of the App may display ads using Google Mobile Ads (AdMob). Depending on your location, consent choices, device settings, and our ad configuration, Google and its advertising partners may process:
• IP address and approximate location derived from it;
• device, advertising, or App-specific identifiers;
• advertisements displayed and your interactions with them;
• App interactions and diagnostic, crash, or performance information; and
• information used to prevent fraud and measure or deliver ads.
We use advertising to support the free version of the App. We intend to use personalized advertising only when a user is eligible and has provided the consent required by applicable law. If consent is refused, unavailable, or not legally valid, we may request non-personalized, contextual, or limited ads instead. Where applicable law permits contextual or limited ads without consent, we rely on our legitimate interests in funding and protecting the service. Withdrawing consent does not affect processing that occurred lawfully before withdrawal.
The App uses Google's User Messaging Platform to refresh consent information at launch and show a consent form where required. The Google Mobile Ads SDK is initialized, and ads are requested, only after Google indicates that ads may be requested under the current consent state. If the consent process cannot be completed and no valid previous consent state permits ad requests, the App does not request ads. If we later track users across other companies' apps or websites, we will also request Apple's App Tracking Transparency permission and update the App Store privacy label before enabling that behavior.
3.5 Subscriptions and purchase status
The App uses RevenueCat to offer and manage subscriptions. RevenueCat assigns an automatically generated, pseudonymous App User ID because the App does not provide an account sign-in. RevenueCat and the applicable app store may process:
• the pseudonymous App User ID;
• product, purchase, receipt, renewal, expiration, cancellation, and entitlement information;
• device type, operating system, App version, country or store region, and last activity information; and
• technical logs needed to complete, restore, and validate purchases.
Apple processes payment credentials and store-account information under its own terms and privacy policy. We do not receive your full payment-card details. We use purchase data to perform the subscription agreement, restore purchases, prevent fraud, provide customer support, and meet accounting or legal duties.
3.6 Support and feedback
If you contact us, we process your email address, name if included, message, attachments, and any App version or technical information you provide. We use it to answer your request, provide support, investigate problems, protect our legal rights, and comply with law. Please do not include mailbox contents or other sensitive information unless it is necessary for us to resolve the issue. Our support inbox is provided by Google Gmail, which processes the email and its metadata to deliver and host the communication.
3.7 Clipboard, exports, and sharing
You may copy temporary addresses, message text, or verification codes to the device clipboard. Other apps or operating-system features may be able to read clipboard contents depending on your device settings and platform rules.
When you export a message, the App creates a text file in operating-system temporary storage. When you use a share feature, the operating-system share sheet sends the selected address, message, export, or attachment only to the destination you choose. That destination processes the data under its own privacy terms.
3.8 Viewing this policy
The in-App privacy-policy page is hosted by Telegra.ph. When the page is loaded, Telegra.ph may process the IP address and other request information needed to provide and secure the page.
4. Service Providers and Other Recipients
We disclose data only as described in this Policy and as necessary for the relevant purpose. Recipients may include:
• Contabo, which hosts our temporary-mail API at api.novidoc.com in the European Union, for message delivery and retrieval;
• Google AdMob (https://policies.google.com/privacy) and its advertising partners for advertising, measurement, and fraud prevention;
• Google Gmail (https://policies.google.com/privacy) for receiving and storing support and privacy-request emails;
• Sentry (https://sentry.io/privacy/) for error reporting and performance monitoring;
• RevenueCat (https://www.revenuecat.com/privacy/) for subscription and entitlement management;
• Apple (https://www.apple.com/legal/privacy/) for App Store distribution, purchase processing, and subscription management;
• Telegra.ph (https://telegra.ph/) for hosting this Privacy Policy;
• the apps or services you select through the system share sheet; and
• public authorities, courts, professional advisers, or other recipients when disclosure is required by law or reasonably necessary to protect rights, safety, users, or the Service.
These providers may act as our processors, independent controllers, or both, depending on the activity. Their own policies explain how they handle data for their purposes.
We do not sell personal data for money. Depending on advertising configuration and applicable law, sharing identifiers or activity with advertising partners may be treated as a “sale,” “sharing,” or targeted advertising. Where required, we provide a consent or opt-out mechanism before that activity.
5. International Data Transfers
We are located in Türkiye. Our providers may process data in Türkiye, the European Economic Area, the United States, or other countries where they or their subprocessors operate. Those countries may have privacy laws different from the laws where you live.
Where required, transfers are made using an adequacy decision, standard contractual clauses, approved contractual safeguards, explicit consent for an identified transfer, or another lawful transfer mechanism under the GDPR, Türkiye's Law No. 6698 on the Protection of Personal Data (KVKK), or other applicable law.
6. Retention and Deletion
We retain personal data only as long as needed for the purposes described above, including legal, accounting, security, and dispute-resolution requirements.
• On-device mailboxes and messages: retained until you delete them, use Clear All Data, or uninstall the App, subject to operating-system backup, cache, and deletion behavior.
• Exported files: stored in operating-system temporary storage until the App or operating system deletes them, or until the App is uninstalled. The current Clear All Data function clears database records but may not immediately remove every temporary export file.
• Temporary-mail server messages: message metadata and content are deleted from the live server one hour after receipt. We do not keep message backups. A message already downloaded to the device remains in the App's local database until the user deletes it, uses Clear All Data, or uninstalls the App.
• Temporary mailbox identifiers: we do not keep permanent mailbox accounts or store generated addresses in a separate server database. A recipient address is processed within its SMTP message and retrieval index during the message's one-hour lifetime and is deleted with that message.
• Infrastructure monitoring: self-hosted Netdata retains aggregate CPU, memory, and traffic-volume measurements. These measurements do not contain visitor IP addresses, request paths, mailbox addresses, or message content.
• Sentry diagnostics: stored for 30 days in Sentry's European region in Germany under our Developer plan.
• Subscription records: kept for as long as needed to provide and verify the subscription and then for any period required for accounting, fraud prevention, disputes, or law. Apple and RevenueCat apply their own retention rules to data for which they are independent controllers.
• Support messages: normally retained for up to 24 months after the request is resolved, unless a longer period is required for security, legal claims, or law. This retention period concerns copies of individual support conversations; it does not limit how long our published support email address remains active.
• Consent records: retained for as long as needed to demonstrate your choice and compliance with law.
When a retention period ends, data is deleted or anonymized unless continued retention is required or permitted by law.
7. Your Choices and Rights
Depending on where you live, you may have the right to:
• learn whether we process your personal data and receive information or a copy;
• correct incomplete or inaccurate data;
• request deletion or destruction of data;
• restrict or object to processing, including direct marketing or processing based on legitimate interests;
• withdraw consent at any time;
• receive certain data in a portable format;
• learn the recipients and international-transfer safeguards that apply;
• object to certain decisions based solely on automated processing; and
• complain to a competent data-protection authority or seek other remedies.
You can delete local database records using Settings → Clear All Data and can remove App cache or all App data using the controls provided by your operating system. Uninstalling the App removes its local container subject to device backup and operating-system behavior. Because no account is required, we may be unable to identify server or diagnostic data as relating to you unless you provide a temporary address, transaction identifier, diagnostic-event identifier, and other information reasonably needed to locate it.
You can change advertising consent through the privacy-options control provided in the App where required, and may also limit tracking or reset advertising settings through your device.
To exercise a right, email novidoc.support@gmail.com with the subject “Privacy Request.” We may request limited information to verify the request. We will respond within the period required by applicable law; under the GDPR this is generally one month, and under the KVKK requests are handled as soon as possible and no later than 30 days.
You may complain to the Turkish Personal Data Protection Authority (https://www.kvkk.gov.tr/) or, if the GDPR applies, to the supervisory authority in the EEA country where you live, work, or believe an infringement occurred.
8. Children
The App is a general-audience utility and is not designed or directed specifically to children. Its App Store 4+ rating is a content-suitability rating. The App does not participate in Apple's Made for Kids category. We do not knowingly use children's data for personalized advertising. If you are under the age at which you may consent to data processing in your country, use the App only with the authorization of a parent or guardian. If you believe a child provided personal data contrary to this section, contact us so we can investigate and delete it where required.
Our AdMob account is configured consistently with the App's general-audience, not-child-directed status and its selected maximum ad-content rating. If the App becomes intended for children, personalized advertising will not be used and this Policy will be revised.
9. Security
We use reasonable technical and organizational measures designed to protect personal data. No network transmission or storage system is completely secure. Temporary mail is inherently unsuitable for confidential or sensitive material, and we cannot guarantee that a temporary address or message will remain private, available, or exclusively accessible by you.
10. Changes to This Policy
We may update this Policy when the App, our providers, or legal requirements change. We will post the revised version, update its effective date, and provide additional notice or request new consent where required. Material changes apply prospectively unless law permits otherwise.
11. Contact
Batuhan Torun
Individual developer
Antalya, Türkiye