On this page
How long things are kept
Delivery metadata
A few days. Long enough for the activity timeline to be useful and for bounce-based auto-disabling to work, then deleted.
Stored messages
30 days by default, then deleted automatically.
Each message in your inbox shows how long it has left, so nothing disappears without warning.
Choosing your own window
In settings you can set a shorter one, and per alias on the alias page. A burner you will never read twice can be a day; something you need to look back at can be longer.
Shorter is free. It is strictly less of your data on our disk and there is no argument against it.
Longer is capped, and asks you to tick a box first. That is not bureaucracy. The cap is what lets us say "at most this much of anyone's mail exists here", which is a far stronger answer to a court order than "it depends on the account". And a longer window costs you three things worth knowing about:
- More of your mail exists to be handed over if we are ever compelled.
- The setting itself marks the account as one with mail worth keeping, which a uniform value does not.
- A setting can be pressured out of you by an employer or a partner. A fixed policy cannot.
If you want the longer window anyway, turn on the private inbox first. Then a year of held mail is a year of ciphertext, and only the metadata remains.
Keeping one past the clock
Mark a message keep and it is exempt from the schedule. It stays until you delete it.
This is the only content on the service that outlives the published retention period, and it only ever happens one message at a time because you asked. There is no setting that quietly keeps everything forever.
Deleted aliases
The alias goes to the trash for 30 days and can be restored. After that it is gone.
The address is remembered permanently, in a table that exists only to refuse it in future. Recycling an address would mean handing someone else your password resets.
Your account
Delete it and the aliases, mailboxes, contacts and stored messages go with it. The reserved addresses stay reserved, for the same reason.
What we cannot delete
Mail we already forwarded is in your mailbox provider's hands, and mail you sent is in the recipient's. Nothing here reaches either.
Backups
Backups exist, because a service that loses your mail to a disk failure is not a privacy service, it is a liability. They are encrypted and they age out on a fixed schedule, so a deleted message is gone from backups too within that window rather than lingering forever.
This is the awkward part of choosing a short retention, and we would rather say it than let you assume otherwise: if the backups include stored mail, then a message deleted by a one-day window can still exist in a nightly dump for as long as that dump is kept. The privacy page states which of the two applies here and for how long. Sealing your inbox makes those copies ciphertext as well.
Something here wrong or missing? Tell us. These pages live in the same repository as the code, so a correction is a one-line change.