Cookie Policy
Last updated 5 September 2026
This site sets one kind of cookie, and only for a function you have asked for.
Inbox session cookie
When an inbox is generated, we set a cookie containing that inbox’s session token. It is what proves the inbox is yours: without it, knowing the address gives no access to the messages.
- Type: strictly necessary / functional.
- Flags: HttpOnly, Secure, SameSite=Lax — not readable by scripts, restricted on cross-site requests.
- Lifetime: expires with the inbox; check the countdown for its lifetime.
What we do not set
No advertising cookies, no cross-site tracking cookies, and no third-party marketing pixels.
Local storage
Your browser also remembers the id of your current inbox in local storage, so a page reload reconnects you to it. It contains no message content and never leaves your device except as part of a normal request to us.