MailDropMailDropInbox + Developer Cloud
AR Developer login
Trust and policy

Privacy

How MailDrop handles public inbox, customer, API, webhook, and operational data.

Overview

MailDrop provides a public temporary-mail service and an account-based Developer Cloud. The data required for each surface is different.

Public inbox data

Public mailbox addresses, access tokens, messages, OTP metadata, and attachment metadata may be processed to deliver the service and apply retention rules. Public inboxes are not customer workspaces.

Customer account data

MailDrop stores account email, display name, password hash and salt, sessions, organization membership, subscription state, activation requests, usage, API-key metadata, webhook endpoint configuration, and audit events.

API keys and secrets

The complete API key and webhook signing secret are displayed once. MailDrop stores a hash or encrypted secret where required. Keep credentials in a secret manager.

Service providers

Cloudflare infrastructure is used for Workers, D1, Pages, Email Routing, and Durable Objects. WhatsApp is used only when a customer chooses to contact MailDrop for manual plan activation.

Retention and deletion

Temporary mail follows configured retention and plan limits. Account records and audit history may be retained for security and operational purposes. Contact MailDrop to request account review or deletion.

No sale of data

MailDrop does not sell customer conversation, mailbox, or API data to advertisers.

Last updated: 24 July 2026

MailDrop can be installed as an app. When the browser prompt is unavailable, use the permanent install guide.

A new MailDrop version is available.