Overview
MailDrop provides a public temporary-mail service and an account-based Developer Cloud. The data required for each surface is different.
Public inbox data
Public mailbox addresses, access tokens, messages, OTP metadata, and attachment metadata may be processed to deliver the service and apply retention rules. Public inboxes are not customer workspaces.
Customer account data
MailDrop stores account email, display name, password hash and salt, sessions, organization membership, subscription state, activation requests, usage, API-key metadata, webhook endpoint configuration, and audit events.
API keys and secrets
The complete API key and webhook signing secret are displayed once. MailDrop stores a hash or encrypted secret where required. Keep credentials in a secret manager.
Service providers
Cloudflare infrastructure is used for Workers, D1, Pages, Email Routing, and Durable Objects. WhatsApp is used only when a customer chooses to contact MailDrop for manual plan activation.
Retention and deletion
Temporary mail follows configured retention and plan limits. Account records and audit history may be retained for security and operational purposes. Contact MailDrop to request account review or deletion.
No sale of data
MailDrop does not sell customer conversation, mailbox, or API data to advertisers.
Last updated: 24 July 2026
