Last updated: March 8, 2026

PRIVACY POLICY

1. Overview

Specter ("we", "our", "us") operates the disposable email service available at specter.email. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. We are committed to minimizing data collection and protecting your privacy.

2. Data We Collect

2.1 Anonymous Users

Anonymous users can generate temporary email addresses without creating an account. We do not require any personal information. We store a session token in your browser's localStorage to associate you with your temporary mailbox. This token expires after 48 hours along with the associated mailbox.

2.2 Registered Users

When you create an account, we collect:

  • Email address (used for authentication and account recovery)
  • Name and profile picture (if you sign in via Google OAuth)
  • Hashed password (if you register with email and password — never stored in plain text)

2.3 Email Content

Emails received in your mailboxes are stored in our database (Cloudflare D1) to enable you to read them. Emails are associated with your account and are visible only to you. We do not read, analyze, or share the content of your emails.

2.4 Billing Information

If you subscribe to a paid plan, payments are processed in cryptocurrency via NOWPayments. We do not store your payment credentials. We receive and store your subscription status, plan type, and payment confirmation from NOWPayments to manage your account access.

2.5 Technical Data

We may collect basic request metadata (such as HTTP headers) through our infrastructure provider Cloudflare for security and abuse prevention. We do not log or store individual IP addresses in our own database.

3. How We Use Your Data

  • To provide and operate the Specter service
  • To authenticate you and secure your account
  • To process payments and manage your subscription
  • To deliver emails to your temporary mailboxes
  • To enforce usage limits and prevent abuse
  • To send transactional emails (e.g., password reset)

We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Data Retention

  • Anonymous mailboxes: Deleted automatically after 48 hours.
  • Registered user mailboxes: Retained until you delete them or close your account. Pro and Enterprise mailboxes are permanent.
  • Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
  • Billing records: Retained for up to 7 years as required by financial regulations.

5. Third-Party Services

We use the following third-party services:

  • Cloudflare — infrastructure, CDN, DNS, edge compute, and database (D1). Subject to Cloudflare's privacy policy.
  • NOWPayments — cryptocurrency payment processing. Your payment data is governed by NOWPayments' privacy policy.
  • Resend — outbound email delivery for Pro/Enterprise users. Email content is transmitted through Resend's infrastructure.
  • Google OAuth — optional sign-in method. If used, Google's privacy policy applies to the authentication process.

6. Cookies & Local Storage

We use session cookies for authentication (set by NextAuth). We use localStorage to store temporary session tokens for anonymous users. We do not use third-party tracking cookies or advertising cookies.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your data (emails, account info)
  • Withdraw consent at any time

To exercise these rights, contact us at privacy@specter.email.

8. Security

We take reasonable measures to protect your data: passwords are hashed using bcrypt, data is transmitted over HTTPS, and our infrastructure is hosted on Cloudflare's secure edge network. No system is completely secure, and we cannot guarantee absolute security.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of significant changes by email or in-app notification. Continued use of the service after changes constitutes acceptance of the updated policy.

10. Contact

If you have questions about this Privacy Policy, contact us at:
privacy@specter.email