Privacy Policy
What we collect, why we hold it, how long for, and what you can ask us to do about it.
Last updated 18 August 2026 · Version 1.0
01Who is responsible
discard.dev is an independently operated developer tool. For the account data described in clause 2 we are the data controller under the EU General Data Protection Regulation (GDPR).
For the contents of the email your applications submit, we are a processor: you decide what to send and why, and we store and display it on your instructions. Clause 3 covers that separately.
Privacy questions go to support@discard.dev.
02What we collect about you
Only what the service needs to work. We do not buy data, and we do not enrich or profile what we hold.
| Data | Where it comes from |
|---|---|
| Email address | You, at sign-up. Your login identity and the only channel we use to reach you. |
| Password | You. Stored only as a salted hash — we never hold the password itself and cannot recover it. |
| Account name | You, optionally. A label for your own benefit. |
| Plan and subscription state | Read from our payment provider on demand: whether Pro is active, the current period end, and a customer reference. No card details ever reach us. |
| SMTP credentials | Generated by us. The name you give a credential, plus a digest of the secret. The secret itself is shown once and never stored. |
| Usage counters | A daily message count per account, used to apply your plan's quota. It resets each UTC day. |
| Server logs | Automatic. Request and connection records that may include IP address, timestamp and user agent, kept for security and diagnostics. |
03Captured email
When your application submits a message, we store it in full — sender and recipients,
headers, subject, HTML and plain-text bodies, and attachments — so you can read it back
in the portal or download it as .eml. We stop it there.
Nothing is ever delivered to the addresses it names.
That content is yours, and what it contains is your choice. Please do not send real personal data through discard.dev. It is a testing tool; use synthetic fixtures. If you do submit personal data belonging to other people, you are its controller and we process it solely on your instructions to provide the service. We do not read captured messages, mine them, or use them to train anything — we access them only where strictly necessary to keep the service running, to investigate abuse, or where the law requires it.
One deliberate consequence of how the portal renders mail: it blocks all remote content, so tracking pixels and remote images inside captured email never load and never fire. Reading a message here does not tell its sender anything.
04Why we process it, and on what legal basis
| Purpose | Basis under Article 6 |
|---|---|
| Running your account, authenticating you, capturing and showing your mail | Performance of a contract |
| Billing and subscription management | Performance of a contract |
| Enforcing quotas, preventing abuse, keeping the service secure | Legitimate interests — protecting the service and its users |
| Service notices about outages, security or changes to terms | Legitimate interests, and legal obligation where the change requires notice |
| Keeping accounting records | Legal obligation |
We send no marketing email and run no advertising, so we ask for no consent for either. There is no automated decision-making producing legal effects, and no profiling.
07How long we keep it
- Captured messages and attachments — for your plan's retention window: 7 days on Free, 30 days on Pro. After that a message may be deleted at any time. You can delete any message yourself from the portal immediately.
- Account record — for as long as the account exists, and then deleted when you close it.
- SMTP credential records — until you revoke them; revoking takes effect at once.
- Usage counters — one day.
- Server logs — a short rolling period for security and diagnostics, not longer than 90 days.
- Billing and accounting records — as long as tax law requires, typically up to 7 years, held largely by our payment provider.
08Your rights
Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to you in a portable format. You may also object to processing we base on legitimate interests.
Much of this you can do yourself: the portal shows your account data, lets you delete messages, and lets you revoke credentials. For anything else — including closing the account and erasing everything with it — email support@discard.dev from the registered address. We answer within 30 days, free of charge.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the data protection authority in your EU or EEA country of residence, work, or where the issue occurred.
09Security
- SMTP requires TLS before it will accept a login. Unauthenticated delivery and cleartext authentication are refused outright.
- The portal is HTTPS-only, and data is encrypted in transit and at rest.
- Passwords are salted and hashed. SMTP secrets are generated with 256 bits of entropy, shown once, and stored only as a digest.
- Every query for a message, attachment or credential is scoped to the requesting account, so one account's data is never loaded for another.
- HTML in captured mail is sanitised on the server and rendered inside a fully sandboxed frame that cannot load remote content.
No system is perfectly secure. If a breach is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay. If you have found a vulnerability, please report it to support@discard.dev rather than testing it against live infrastructure.
10Changes to this policy
We will update this policy as the service changes. The date and version at the top always identify the current text. For material changes to how we use your data we will email the account address before they take effect.
11Contact
Privacy questions, access and erasure requests, and breach reports all go to support@discard.dev. Our Terms of Service govern everything else.