client-side encryption · zero tracking

End-to-end encrypted temporary email

A temporary inbox whose messages only you can read. Encryption happens in your browser, and the server stores ciphertext it can't open.

Create your inboxSee all use cases

Encrypted in your browser

Your key never leaves the client. The server only ever sees ciphertext.

Nothing to leak

We can't read your messages, so there's nothing readable to breach or hand over.

Temporary by default

Messages auto-purge every two hours; the address stays until you delete it.

What end-to-end encrypted means here

The encryption key is generated in your browser and never sent to us. Messages are encrypted client-side before they are stored, so what sits in the database is ciphertext the server has no way to open. When you read your mail, the decryption happens in the browser too.

This is a real constraint on us, not a policy we could quietly change: there is no key on our side to use, so "we could read it if we wanted to" is not available as an option.

What we can still see, said plainly

Encryption covers message contents. It does not erase the fact that a message arrived. We still handle the envelope: which of your addresses received mail, roughly when, and the sending server it came from, because that is what delivering mail requires.

One practical consequence: automatic one-time-code extraction cannot work on an encrypted inbox. The server would have to read the message to find the code, and it cannot. If you want a code pulled out for you automatically, use an inbox without encryption enabled.

You can turn it off, and back on

Encryption is a choice per account, not a one-way door. You can disable it with your password if you decide the tradeoff is not worth it, and enable it again later. Existing encrypted messages stay recoverable across that switch rather than being stranded.

It is available on the free plan, in full. Plenty of services treat encryption as the upsell that turns a free tier into a paid one; we did not, because an encrypted inbox you cannot afford protects nobody. What the paid plans buy is capacity and retention, not the right to keep your own mail private.

Read the details

How the encryption worksKey handling, what the server stores, and the OTP tradeoff.Privacy policyWhat we collect, what we do not, and how long any of it lives.Plans and retentionHow long encrypted messages are kept before they purge.

Frequently asked questions

What does end-to-end encrypted mean here?

Messages are encrypted in your browser with a key we never see. The server stores only ciphertext it can't decrypt.

Can MailFlat read my email?

No. Decryption happens client-side, so the contents are unreadable to us.

Is encryption free?

Yes. End-to-end encryption is available to free accounts.

Related

disposable emailemail for ai agentstemporary email api

Ready to try it?

Create your inbox

MailFlat for instant email inboxes for testing, automation & AI agents.