discard.dev log in get credentials →
legal / privacy

Privacy Policy

What we collect, why we hold it, how long for, and what you can ask us to do about it.

Last updated 18 August 2026 · Version 1.0

The short version. We collect the least we can: an email address, a password hash, and the messages your own applications send us. There is no analytics, no advertising, no tracking cookie and no third-party script anywhere except the payment overlay on the checkout page. We do not sell data. Captured mail is developer test data — please keep real personal data out of it.
1 Who is responsible 2 What we collect 3 Captured email 4 Why, and on what basis 5 Cookies 6 Who else sees it 7 How long we keep it 8 Your rights 9 Security 10 Changes 11 Contact

01Who is responsible

discard.dev is an independently operated developer tool. For the account data described in clause 2 we are the data controller under the EU General Data Protection Regulation (GDPR).

For the contents of the email your applications submit, we are a processor: you decide what to send and why, and we store and display it on your instructions. Clause 3 covers that separately.

Privacy questions go to support@discard.dev.

02What we collect about you

Only what the service needs to work. We do not buy data, and we do not enrich or profile what we hold.

Data Where it comes from
Email address You, at sign-up. Your login identity and the only channel we use to reach you.
Password You. Stored only as a salted hash — we never hold the password itself and cannot recover it.
Account name You, optionally. A label for your own benefit.
Plan and subscription state Read from our payment provider on demand: whether Pro is active, the current period end, and a customer reference. No card details ever reach us.
SMTP credentials Generated by us. The name you give a credential, plus a digest of the secret. The secret itself is shown once and never stored.
Usage counters A daily message count per account, used to apply your plan's quota. It resets each UTC day.
Server logs Automatic. Request and connection records that may include IP address, timestamp and user agent, kept for security and diagnostics.

03Captured email

When your application submits a message, we store it in full — sender and recipients, headers, subject, HTML and plain-text bodies, and attachments — so you can read it back in the portal or download it as .eml. We stop it there. Nothing is ever delivered to the addresses it names.

That content is yours, and what it contains is your choice. Please do not send real personal data through discard.dev. It is a testing tool; use synthetic fixtures. If you do submit personal data belonging to other people, you are its controller and we process it solely on your instructions to provide the service. We do not read captured messages, mine them, or use them to train anything — we access them only where strictly necessary to keep the service running, to investigate abuse, or where the law requires it.

One deliberate consequence of how the portal renders mail: it blocks all remote content, so tracking pixels and remote images inside captured email never load and never fire. Reading a message here does not tell its sender anything.

04Why we process it, and on what legal basis

Purpose Basis under Article 6
Running your account, authenticating you, capturing and showing your mail Performance of a contract
Billing and subscription management Performance of a contract
Enforcing quotas, preventing abuse, keeping the service secure Legitimate interests — protecting the service and its users
Service notices about outages, security or changes to terms Legitimate interests, and legal obligation where the change requires notice
Keeping accounting records Legal obligation

We send no marketing email and run no advertising, so we ask for no consent for either. There is no automated decision-making producing legal effects, and no profiling.

05Cookies

We use strictly necessary cookies only. There is no consent banner because there is nothing to consent to — nothing we set is used for analytics, advertising or tracking, and nothing follows you off this site.

06Who else sees it

We do not sell personal data, and we do not share it for anyone else's marketing. We rely on two kinds of supplier, both bound by data processing terms:

We will name the current suppliers on request — write to support@discard.dev. Beyond those, we disclose data only where we are legally compelled to, where it is necessary to establish or defend legal claims, or to a successor if the service is transferred — in which case this policy travels with it and we will tell you first.

The service is operated from within the European Union. Where payment processing or support involves a transfer outside the EEA, that transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision, as applicable.

07How long we keep it

08Your rights

Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to you in a portable format. You may also object to processing we base on legitimate interests.

Much of this you can do yourself: the portal shows your account data, lets you delete messages, and lets you revoke credentials. For anything else — including closing the account and erasing everything with it — email support@discard.dev from the registered address. We answer within 30 days, free of charge.

If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the data protection authority in your EU or EEA country of residence, work, or where the issue occurred.

09Security

No system is perfectly secure. If a breach is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay. If you have found a vulnerability, please report it to support@discard.dev rather than testing it against live infrastructure.

10Changes to this policy

We will update this policy as the service changes. The date and version at the top always identify the current text. For material changes to how we use your data we will email the account address before they take effect.

11Contact

Privacy questions, access and erasure requests, and breach reports all go to support@discard.dev. Our Terms of Service govern everything else.