Privacy
MailWhen retains a copy of your email, because returning that email to you later is the entire service. That is a significant amount of trust to ask for, so this page sets out exactly what is kept, how long it is held, and who can read it.
Summary
- Your message is retained so that it can be returned to you, and for no other purpose.
- It is stored privately and encrypted, and is never transferred elsewhere.
- No one other than the operator can read it. It is never sold, shared, or used to train anything.
- It is deleted automatically once nothing needs it — never while a reminder still does, however far off that reminder is. The one exception is mail that failed to process, which is kept until a person has looked at it.
- Write to MailWhen without an account and you get one reply, asking you to confirm. Ignore it and that is the end of it — no account, and nothing else sent.
- This website sets no cookies and keeps no record of who visits.
What is retained
The rule first, because it is what actually binds: nothing is kept unless something still needs it, and it is deleted once nothing does. What the service needs, when you send mail to a MailWhen address, is this:
- The message itself — complete and unaltered, including attachments. It must be complete, because the message returned to you later is this one.
- The reminder — which address you used, the subject line of your message, when it is due, when it was delivered, and whether anything went wrong. This record is kept indefinitely and outlives the message it refers to, so a subject line survives after the message itself has been deleted. It is what makes it possible to answer later questions about a reminder that has already been sent.
- A record of its handling, so that a reminder which fails can be traced and corrected. Kept for a limited period and then discarded automatically.
- A note that an address asked to begin, if you write to MailWhen without an account. It records the address and that a confirmation was sent to it — not your message, and nothing from inside it. It is what matches your reply to your request, and what stops the same address being mailed about this again. Ignore the confirmation and it expires by itself; no account is created and you hear nothing further.
Anything else held exists only to make one of those work, and is held the same way. That sentence is deliberate: a list of items can fall out of date as the service grows, and the rule above cannot.
Your mail is never indexed, profiled, advertised against, or used to train anything, and nothing reads its contents but the component that assembles your reminder.
One automated check does examine every message as it arrives. It is scanned for viruses and for spam, and checked for proof that the sender is who they say they are. That is a security measure and its result decides one thing only — whether the message is accepted at all. A message that will be stored for months and then sent back to you is exactly the one worth checking before any of that begins; what happens to one that fails is described under Messages that are refused below.
Retention periods
Messages you send
Retained for as long as a reminder requires them, and no longer. A repeating reminder’s copy is held for the life of the series, because each future reminder sends that same message again; ending the series releases it. A one-time reminder’s copy is released once it has been delivered.
Released is not the same as gone, and the gap is worth being exact about. A copy that nothing needs any more is marked as released on the next scheduled pass — within a day — and is deleted once it is both released and past a minimum age counted from the day it arrived. Whichever of those two happens later is when it goes.
That has two consequences, and the second matters more. A copy needed only briefly is not removed the moment it is released: it waits out the minimum age, so a reminder due in an hour and one due in a month have their copies deleted at about the same age. And a copy needed for longer than that minimum is never removed while it is still needed — a reminder years away keeps its copy for years. Age alone deletes nothing; being finished with is what does.
So being released is what makes deletion certain rather than what makes it immediate. Nothing reads a released copy — no reminder refers to it, and the service holds no way to open one that is not attached to a reminder it is assembling — but it is still on disk until it goes. See below for why it works that way.
Messages that could not be processed
A message that arrives and produces nothing — no reminder, and no reply explaining why not — is kept until a person has looked at it, with no period attached. This is rare and it is deliberate: it means something went wrong on our side, and the message is the only evidence of what. Deleting it on a schedule would destroy the thing needed to find out why your reminder never happened.
The operator is alerted when one appears, so this is a state that gets resolved rather than one that accumulates quietly.
Messages that are refused
Anything failing verification never enters the service. It is set aside briefly — long enough to identify a pattern of abuse, and no longer — and then deleted.
Mail to our contact address
Writing to the address published on this website is not the same as using the service, and that mail is kept separately from it. It is stored when it arrives and then forwarded to the operator, who replies by hand. Storing it is what makes the forwarding safe to rely on: a note asking for an account, lost because the forwarding quietly failed, would leave the sender waiting for an answer that was never coming — which is the exact failure this service exists to prevent.
It is kept on age alone. It expires on a fixed schedule counted from the day it arrived, whether or not it has been answered — nothing about a message written to us is ever still needed later in the way a reminder's message is, so there is no condition that could hold it longer. Nothing automated acts on it: it never enters the reminder service, and it cannot create an account by arriving — only a person reading it can do that.
How deletion occurs
Automatically, on a fixed schedule, and by no other means. No part of the running service can delete a stored message itself — not as a safeguard that could be bypassed, but because the permission to do so was never granted to any of it. What the service can do is mark a message as finished with, and the storage deletes marked messages on its schedule, so no one has to remember to do it.
That mark is the one way an error could remove your mail early. A message marked by mistake, once it is older than the schedule allows, is deleted on the storage's next pass, and that cannot be undone. The service checks every stored message once a day and takes the mark off any that a reminder still needs, which narrows that window without closing it.
The exact periods are not published here, because a number on this page would be a promise the service could quietly stop keeping. What is promised is the rule: held for as long as a reminder needs it, for however long that is, and deleted once nothing does — with a minimum age that stops a short-lived copy being removed the instant it is released.
Who can read it
The operator, and no one else. Not advertisers, and not commercial partners; MailWhen has neither.
Other people hear from MailWhen only where you put it in front of them. A MailWhen address in To or Cc is visible to everyone on the message, so the reminder goes to those of them who already hold a MailWhen account — they can already see what you sent and what you asked for. Nobody without an account is written to on your behalf, and you are told who was left out. Anywhere else, it is yours alone: blind-copy the address, or forward a thread to it, and nobody else on that mail is contacted or learns that a reminder exists.
That is one rule rather than a list of situations, which is the point. A list would need a new line every time there is a new way to address a message, and the line would be missing for a while first.
Your mail is never sold, rented, shared, published, or used as training data. The service has no commercial model that would give it any reason to.
Verification on arrival
Every message is verified as genuinely originating from the account it claims to come from before anything is scheduled. Knowledge of a MailWhen address alone confers no access to the service.
The routine delivery metadata that accompanies any email is retained alongside it, and expires with it.
This website
These pages are exactly as simple as they appear:
- No cookies are set, by this site or by any other party.
- No analytics, tracking pixels, or third-party resources. Every element of this page is served from this domain alone.
- No record is kept of who visited or what was read.
- A single preference is stored, and only by your own browser: whether you selected the light or dark theme. It never leaves your device.
The address preview on the front page runs entirely within your browser and transmits nothing.
Access and deletion
On request, you may receive a list of what is held for you, a copy of it, or have all of it deleted. There is no self-service control for this; it is handled individually, which also means a person will confirm exactly what was removed.
Whether or not you have an account. If you wrote to MailWhen once, were sent a confirmation and never replied, something is still briefly held for you — and the same request reaches it. Not having become a user is not a reason to have fewer rights over what is kept.
Closing an account cancels its reminders outright, rather than merely stopping them from arriving. That distinction is the one that matters here: a reminder that is stopped but still on file goes on holding the message it would have sent, and a cancelled one lets it go. So closing an account is what releases your stored mail, and it then expires on the ordinary schedule described above.
Change log
If what is kept, or how long it is held, ever changes, this page changes with it and account holders are told directly. It will not change silently.
- 28 September 2026 — Corrected how deletion is described. This page said no error or defect could remove mail early. The service still cannot delete a message itself, but it marks the ones it has finished with, and a message marked by mistake would be deleted early. Nothing about the practice changed; the description promised more than the service does.
- 12 September 2026 — Corrected who is copied on a reminder. A MailWhen address in To or Cc copies only the people on that message who already hold a MailWhen account; this page said everyone. Nothing about the practice changed; the description was wider than the service.
- 12 September 2026 — Anyone can now start an account by writing to MailWhen. The note recording that an address asked to begin, described under What is retained, is therefore held in practice from today rather than only described. This is a change in what is kept.
- 4 September 2026 — Corrected a line saying mail is not scanned. Every message has always been checked for viruses, spam and sender authenticity as it arrives, because one that will be stored and sent back later is worth checking. Nothing about the practice changed; the page described it wrongly, and in the direction that flattered us.
- 4 September 2026 — Closing an account now cancels its reminders, which is what releases the messages they were holding. Until today it stopped them without ending them, and a stopped reminder went on holding its message indefinitely — so this section described what closing an account was meant to do rather than what it did. The description was already right; the service now matches it.
- 4 September 2026 — Mail sent to our contact address is now stored when it arrives, rather than only forwarded, so that a request cannot be lost if the forwarding fails. It expires on a fixed schedule. This is a change in what is kept, not a correction to how it was described.
- 3 September 2026 — Corrected the retention section, which described what is kept less fully than the service keeps it.
- 30 August 2026 — Replaced the specific retention periods with the rule they follow.
- 27 August 2026 — First published.