Privacy

Privacy Notice

susmail.dev is designed for short-lived, receive-only inboxes. Message content is treated as untrusted data and stored only for the retention period shown in the product unless a shorter manual deletion happens first.

What We Store

We store inbox identifiers, message metadata, parsed message content, and raw MIME objects needed to provide the service. We also retain limited operational and abuse-prevention data such as IP-derived source keys, rate-limit events, and abuse reports.

Retention

Free inboxes are deleted automatically on expiry. Expired inboxes, parsed messages, and raw MIME objects are removed by scheduled cleanup jobs. Manual delete removes the current inbox earlier than the standard TTL.

Analytics and consent

susmail.dev uses a first-party analytics endpoint for optional public-page and product-flow measurement. Optional Google Analytics can also be enabled on eligible public pages. Outside regions managed by Google's consent tooling, these signals are gated behind the in-product data-settings controls and can be denied separately from advertising consent.

We do not send email bodies, full sender addresses, full subject lines, raw MIME keys, or inbox local parts in analytics payloads. The public traffic layer is meant to measure route families and product interactions, not to profile message contents.

Advertising on public pages

If susmail.dev shows advertising, it is intended for eligible public pages only. Sensitive product surfaces such as the message reader, HTML email preview, abuse/reporting flows, and internal operator routes are intentionally excluded from advertising placements.

Advertising signals, when present, are limited to eligible public pages. In the EEA, UK, and Switzerland, Google advertising consent is expected to be handled by Google's certified CMP flow when Google ads are active; Susmail keeps its own first-party analytics conservative in those regions unless a separate bridge is added. Outside those regions, the Susmail data-settings panel remains available for optional analytics and advertising preferences.

What We Do Not Promise

This is not permanent mailbox hosting. Do not use the service for long-term storage, sensitive regulated data, or business-critical communication.