Burner Boxx lets you use core temporary privacy tools without exposing your everyday contact information. Account-based features such as Squads, LIVE, creator tools, messaging, settings, purchases, and age-safety controls require only the information needed to operate those features. Temporary data is designed to expire according to its configured lifespan.
01Introduction
Burner Boxx Corp ("Burner Boxx," "we," "us," or "our") is committed to protecting your privacy. This policy explains how we collect, use, retain, and safeguard information when you use our app, website, and services, including temporary email addresses and phone numbers. It is intended to describe our actual practices and support compliance with applicable privacy and platform requirements.
02What We Collect
We collect the minimum data necessary to provide our services:
- ▸Account Email: If you create an account, we use your email for authentication, security, account recovery, and account-based features. Checkout email may also be used for subscription management and purchase restoration.
- ▸Temporary Email Addresses: Randomly generated disposable addresses and all messages received at them. Destroyed when the timer expires.
- ▸Temporary Phone Numbers: Randomly generated disposable numbers and SMS messages received. Destroyed upon expiration.
- ▸Payment Confirmation: We receive confirmation of successful payments from Stripe. We do not receive or store your card number, CVV, or full payment details.
- ▸Preferences: Language selection, premium status, forwarding destinations, and inbox PIN — stored locally on your device, not on our servers.
- ▸Usage History: A local record of previously used temporary addresses, stored on your device only and never transmitted to our servers.
- ▸Analytics (Website Only): Aggregated, anonymized page view counts via first-party, cookieless analytics. No cookies, no IP addresses, no device IDs. No tracking SDKs in the mobile app.
- ▸Crash Data: Anonymous crash reports if the app unexpectedly terminates, used solely to fix bugs. No personal data included.
- ▸Legal Consent Records: For account-based features, we may store the policy versions you accepted, acceptance timestamp, account identifier, consent method, source, age band, and locale so we can demonstrate which terms applied when you agreed.
- ▸Device Identifiers: We do not collect device IDs, IDFA, or advertising identifiers. We do not engage in cross-app or cross-website tracking. For abuse prevention only, we generate a privacy-safe device fingerprint hash (not a raw device ID) to rate-limit automated abuse — see Section 2A below.
- ▸IP Addresses: We do not log IP addresses linked to your identity or browsing activity. For abuse prevention and security only, we may temporarily retain IP addresses in hashed form to block malicious actors, rate-limit abuse, and comply with telecom carrier requirements — see Section 2A below. These are not linked to your email address, subscription, or inbox content.
- ▸Server Logs: We do not retain server access logs or request logs that could identify you. Security-related logs (abuse flags, blocked IPs) are retained solely for abuse prevention and are not linked to user identity.
03Abuse Prevention Data (IP & Device Fingerprint)
To protect the service from automated abuse, fraud, and spam — and to comply with telecom carrier requirements — we collect limited security data. This data is not linked to your email address, subscription, or inbox content:
- ▸IP Reputation: We track IP addresses that exhibit abusive behavior (rapid inbox creation, login flooding, chargeback patterns) and may block them. IP addresses associated with normal use are not retained long-term.
- ▸Device Fingerprint Hash: A one-way hash derived from limited device characteristics may be used to detect automated or excessive abuse. It is designed to reduce direct identifiability and is not used as an advertising identifier. No raw advertising device ID is stored for this purpose.
- ▸Velocity Tracking: We count the number of inboxes, logins, and forwards created from a given IP or device hash in a 24-hour window. The counts are stored, not the content of your emails or messages.
- ▸Retention: Abuse prevention data is retained for up to 90 days after the last abusive action, then automatically purged. Non-abusive IP data is not retained.
- ▸Legal Compliance: IP and device data may be disclosed to law enforcement only in response to valid legal process. Due to our hashing approach, we typically cannot link an IP to a specific user or inbox.
This data is never sold, shared with advertisers, or used for marketing. It exists solely to keep the service available and fast for legitimate users.
04How We Use Your Data
- ▸Account Email: Authentication, account security, account recovery, subscription management, purchase restoration, and customer support where applicable.
- ▸Temporary Email/Phone Data: To deliver the core service — receiving and displaying messages. Destroyed upon expiration; no secondary use.
- ▸Payment Confirmation: To verify subscription status, grant premium features, and manage billing. Handled entirely by Stripe.
- ▸Preferences: To remember your settings between sessions. Stored on-device only.
- ▸Analytics: To understand website traffic patterns and improve blog content. Not used for tracking or profiling individuals.
- ▸Crash Data: To identify and fix bugs and improve app stability.
We never sell, rent, or share your personal data with third parties for marketing or advertising.
05Tracking Transparency
The Burner Boxx mobile app does not track you. No IDFA, no cross-app tracking, no advertising networks, no tracking SDKs, no third-party analytics SDKs.
Our public website uses first-party, cookieless analytics to count page views for blog content optimization. No cookies, no IP addresses, no cross-site tracking, no Google Analytics. This applies only to website visitors and does not extend to the mobile app.
We do not participate in data broker sharing and do not sell personal data as defined by CCPA.
5.5SMS Opt-In & Text Messaging Consent
SMS opt-in is voluntary and separate from our core service. If you choose to opt in to receive text messages from Burner Boxx, that consent is collected through a distinct opt-in mechanism — a checkbox that is unchecked by default — and is not a condition of using any Burner Boxx service.
- ▸Voluntary Consent: Providing your mobile number and checking the consent box is a distinct, optional action. You are not required to opt in to SMS messaging to use our temporary email or temporary phone number services.
- ▸No Data Sharing: We do not share or sell mobile phone numbers, SMS opt-in data, or text messaging originator consent with third parties or affiliates for marketing or promotional purposes. The above excludes text messaging originator opt-in data and consent; this information will not be shared with any third parties.
- ▸Service Providers Only: Mobile information may be shared only with service providers (such as Twilio) that assist us in delivering our SMS services, and solely for that purpose.
- ▸Opt Out: You may opt out of SMS messaging at any time by replying STOP to any message. Reply HELP for help. Message and data rates may apply.
- ▸Consent Is Non-Transferable: Opt-in consent cannot be transferred or sold. It remains a direct 1:1 agreement between you and Burner Boxx.
06Third-Party Services
We use the following third-party services to operate our platform. Each has its own privacy policy:
- ▸Stripe — Payment processing and subscription management. Handles all card data securely. We receive only transaction confirmation. Stripe Privacy Policy
- ▸Twilio — Provisioning temporary phone numbers and receiving SMS messages. Twilio Privacy Policy
- ▸Mailgun — Receiving inbound email on our temporary email domains. Mailgun Privacy Policy
- ▸Base44 —Backend infrastructure and database hosting. Base44 Privacy Policy
We do not share your personal data with any other third parties except as required by valid legal process.
07Data Security
- ▸Encryption in Transit: Burner Boxx uses HTTPS/TLS for supported network communications between your device and our services.
- ▸Encryption at Rest: Stored data is protected using the security controls provided by our hosting and storage infrastructure, with additional application-level encryption used for features that explicitly state it.
- ▸Encrypted Forwarding: Forwarded emails are encrypted with AES-256 and delivered as one-time secure links that self-destruct after viewing or 24 hours.
- ▸Secure Storage: Payment data is handled exclusively by Stripe (PCI DSS Level 1). We never touch raw card data.
- ▸Data Minimization: Burner Boxx is designed to minimize persistent logging and retain only operational, billing, security, safety, legal, and abuse-prevention records reasonably needed to operate and protect the service. Temporary content follows its configured expiry rules.
- ▸User-Controlled Deletion: Temporary privacy content follows its expiry controls, and users/creators can use supported deletion tools to remove content and account data they control. Limited records may remain only where required for billing, disputes, safety, abuse prevention, legal consent, or other legal obligations.
- ▸Access Controls: Administrative access is restricted, authenticated, and audited.
08Data Retention
- ▸Temporary Email/SMS Data: Removed when the configured timer expires or when the supported destroy control is used, subject only to limited operational, safety, billing, abuse-prevention, consent, or legal records that must be retained separately.
- ▸Subscription Data: Retained while your subscription is active. Deleted within 30 days of a deletion request.
- ▸Legal Consent Records: Retained as reasonably necessary to document agreements, resolve disputes, meet legal obligations, and enforce applicable terms, subject to applicable retention requirements.
- ▸Payment Records: Retained by Stripe per their policy. We retain only subscription status.
- ▸Operational Logs: Burner Boxx minimizes persistent logging. Limited operational, security, safety, billing, consent, and abuse-prevention records may be retained where necessary and are kept separate from user-facing content.
- ▸On-Device Preferences: Stored locally. Clearing your browser or app data removes these.
09Your Rights (GDPR & CCPA)
Under GDPR, CCPA, and similar laws, you have the right to:
- ▸Access — Request a copy of the personal data we hold about you.
- ▸Rectification — Request correction of inaccurate data.
- ▸Deletion — Request permanent deletion of your personal data.
- ▸Opt-Out of Sale — We do not sell personal data. You can opt out of any future sale (none currently occurs) by contacting us.
- ▸Restriction — Request that we restrict processing of your data.
- ▸Data Portability — Receive your data in a structured, machine-readable format.
- ▸Withdraw Consent — Withdraw consent to data processing at any time.
To exercise any of these rights, email support@burnerboxx.com with the subject "Privacy Rights Request."
10Deleting Your Data
You have the right to request deletion of personal data associated with your account or subscription. Account data and subscription data are managed separately from temporary inbox/SMS content, which follows its own configured expiry lifecycle.
- ▸Email support@burnerboxx.com with the subject "Delete My Data" from your checkout email address.
- ▸We will delete supported account and subscription data within 30 days, except records we must retain for billing, disputes, fraud prevention, safety, consent, tax, or other legal obligations.
- ▸Deletion is permanent and irreversible. You will lose access to any active subscriptions and premium features.
Temporary email and SMS content follows its configured expiry and destroy controls. Creators and users can also use supported deletion and Burn Everything controls for content and profile data they control.
On-device data (preferences, usage history, PIN) can be cleared by clearing your browser or app storage, or by uninstalling the app.
11Privacy Manifest Alignment
Our app includes an Apple Privacy Manifest (PrivacyInfo.xcprivacy) declaring our data practices. This policy is aligned with that manifest:
- ▸NSPrivacyTracking:
false— We do not track as defined by Apple. - ▸NSPrivacyTrackingDomains: Empty — No tracking domains used.
- ▸Email Address: Collected for app functionality, including authentication, account security, subscription management, and recovery where applicable.
- ▸Phone Number: Collected for app functionality (temporary number service).
- ▸Crash Data: Collected for app functionality (stability). Not linked to identity.
- ▸Required-Reason APIs: UserDefaults (CA92.1), FileTimestamp (C617.1), SystemBootTime (35F9.1) — all for app functionality.
12Age Requirements
Burner Boxx accounts are not available to children under 13. Users ages 13–17 use protected Teen accounts with stricter privacy, messaging, LIVE, and monetization controls. If you believe a child under 13 has provided us with personal data through an account, contact us and we will investigate and remove it as appropriate.
13Law Enforcement
We comply with valid legal requests when required by law. User-facing temporary content and creator-controlled content can be removed through the product's expiry, delete, or Burn Everything controls, while limited billing, dispute, safety, abuse-prevention, consent, or other legally required records may remain when we are required to retain them. We require properly served legal process directed to our registered agent.
14Changes to This Policy
We may update this Privacy Policy periodically. We'll notify you of significant changes via our website and app. Your continued use of Burner Boxx after changes constitutes acceptance of the updated policy. The "Last updated" date at the top reflects the most recent revision.
15Contact
- ▸General Support: support@burnerboxx.com
- ▸Privacy Requests: support@burnerboxx.com (subject: "Privacy Rights Request")
- ▸Data Deletion: support@burnerboxx.com (subject: "Delete My Data")
- ▸Abuse Reports: abuse@burnerboxx.com
- ▸DMCA: dmca@burnerboxx.com
- ▸Contact Form: burnerboxx.com/contact
We aim to respond to privacy-related inquiries promptly and within any timeframe required by applicable law.