Privacy Policy
Last updated: February 3, 2026
1. Introduction
Buun Group ("Company", "we", "us", or "our") operates destroy.network (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We are committed to protecting your privacy. Our Service is designed specifically to help you protect your personal email address from spam, tracking, and unwanted communications.
2. Information We Collect
2.1 Information You Provide
- Account Information: When you create an account, we collect your email address for authentication purposes.
- Payment Information: For paid plans, payment is processed by Stripe. We do not store your credit card details.
- Custom Domains: If you configure custom domains, we store domain configuration data.
2.2 Automatically Collected Information
- Log Data: We may collect information that your browser sends whenever you visit our Service, including IP address, browser type, pages visited, and access times.
- Device Information: We may collect information about the device you use to access the Service.
2.3 Email Content
Emails received at temporary inbox addresses are stored only for the duration of the inbox's lifetime. Once an inbox expires, all associated email content is permanently deleted. We do not read, analyze, or process email content for advertising or profiling purposes.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Service
- Process transactions and send related information
- Send technical notices, updates, and support messages
- Respond to your comments, questions, and requests
- Monitor and analyze trends, usage, and activities
- Detect, investigate, and prevent fraudulent transactions and abuse
- Comply with legal obligations
4. Data Retention
Our data retention practices reflect our commitment to privacy:
- Temporary Inboxes: Email content is automatically and permanently deleted when the inbox expires (between 10 minutes and 1 hour depending on plan).
- Account Data: Account information is retained while your account is active. You may request deletion at any time.
- Log Data: Server logs are retained for a maximum of 30 days for security and debugging purposes.
- Payment Records: Transaction records are retained as required by law for accounting and tax purposes.
5. Information Sharing
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
- Service Providers: We use third-party services (Cloudflare, Stripe) that may process data on our behalf under strict confidentiality agreements.
- Legal Requirements: We may disclose information if required by law, court order, or governmental request.
- Protection of Rights: We may disclose information to protect our rights, privacy, safety, or property, or that of our users or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
6. Data Security
We implement appropriate technical and organizational measures to protect your information:
- All data is transmitted over HTTPS/TLS encryption
- Data at rest is encrypted using industry-standard encryption
- Access to user data is restricted to authorized personnel only
- We conduct regular security assessments and monitoring
- Our infrastructure is hosted on Cloudflare's secure global network
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee its absolute security.
7. Cookies and Tracking
We use minimal cookies necessary for the Service to function:
- Session Cookies: Used to maintain your login session.
- Preference Cookies: Used to remember your settings and preferences.
We do NOT use:
- Third-party advertising cookies
- Cross-site tracking
- Analytics that identify individual users
- Social media tracking pixels
8. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate personal data.
- Erasure: Request deletion of your personal data.
- Portability: Request a copy of your data in a portable format.
- Objection: Object to certain processing of your personal data.
- Restriction: Request restriction of processing of your personal data.
To exercise any of these rights, please contact us at legal@destroy.network.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our Service, you consent to the transfer of information to countries outside your country of residence.
We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses and other legally recognized transfer mechanisms.
10. Children's Privacy
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information.
11. Browser Extension
The DESTROY.NETWORK browser extension provides quick access to our Service. The extension operates with the following privacy practices:
11.1 Data Collection
- No Personal Data Collection: The extension does not collect, track, or transmit any personal information.
- No Browsing History: The extension does not access or store your browsing history.
- No Analytics: The extension contains no analytics, telemetry, or tracking code.
11.2 Local Storage
- Inbox Data: Active inbox information is cached locally in your browser's extension storage for quick access.
- API Key: If you configure an API key (Pro/Business), it is stored locally in your browser's encrypted sync storage. It is never transmitted except to authenticate with our servers.
- Preferences: Your notification and display preferences are stored locally.
11.3 Network Requests
The extension only communicates with destroy.network servers to:
- Create and manage temporary inboxes
- Retrieve inbox messages
- Verify API key validity (if configured)
All network requests are made over HTTPS. The extension does not make requests to any third-party servers.
11.4 Permissions
The extension requests only the minimum permissions necessary:
- contextMenus: To add "Create temp inbox" to the right-click menu
- storage: To save your preferences and cached inbox data locally
- notifications: To alert you when new emails arrive
- alarms: To periodically check for new emails
- host_permissions (destroy.network): To communicate with our API
11.5 Content Script Behavior
The extension includes a content script that runs on web pages you visit. This script:
- Email Field Detection: Scans the page for email input fields to display a convenient "fill" button. This detection is done entirely locally in your browser.
- DOM Observation: Monitors for dynamically added form fields (e.g., on single-page applications) to provide the fill button feature. No page content is collected or transmitted.
- Toast Notifications: Displays on-page notifications when an inbox is created. This is purely visual feedback.
Important: The content script does NOT read, collect, store, or transmit any information from the pages you visit. It does not access your browsing history, form data, passwords, or any other personal information on websites.
11.6 Clipboard Access
When you create a temporary inbox, the extension automatically copies the email address to your clipboard for convenience. The extension only writes to your clipboard-it never reads from it. Clipboard access is limited to the moment of inbox creation.
12. Third-Party Services
Our Service integrates with the following third-party services (subprocessors):
- Cloudflare: Infrastructure and security services. Privacy Policy
- Stripe: Payment processing. Privacy Policy
We encourage you to review the privacy policies of these third parties. This list of subprocessors may be updated from time to time; material changes will be reflected in this Privacy Policy.
13. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do NOT sell or share your personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
Do Not Sell or Share My Personal Information: We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising purposes.
To exercise your California privacy rights, contact us at privacy@destroy.network. We will verify your identity before processing your request.
14. Australian Privacy Principles
As an Australian company, we comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). In addition to the rights described above:
- Open and Transparent Management: This Privacy Policy describes how we handle your personal information.
- Anonymity and Pseudonymity: Where practicable, you may use our Service without identifying yourself (temporary inboxes can be created anonymously).
- Collection: We only collect personal information that is reasonably necessary for our functions and activities.
- Dealing with Unsolicited Information: If we receive unsolicited personal information, we will determine whether we could have lawfully collected it, and if not, we will destroy or de-identify it.
- Use and Disclosure: We only use or disclose personal information for the purpose for which it was collected, or for related purposes you would reasonably expect.
- Cross-border Disclosure: When we disclose personal information overseas (e.g., to cloud service providers), we take reasonable steps to ensure recipients comply with the APPs.
- Quality: We take reasonable steps to ensure personal information is accurate, up-to-date, and complete.
- Security: We take reasonable steps to protect personal information from misuse, interference, and loss, as well as unauthorized access, modification, or disclosure.
You may lodge a complaint about a breach of the APPs with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
15. Data Breach Notification
In the event of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- Notify the Office of the Australian Information Commissioner (OAIC) as required by law
- Notify affected individuals as soon as practicable
- Take immediate steps to contain the breach and mitigate harm
- Conduct an investigation to prevent future breaches
For users in the European Economic Area, we will notify relevant supervisory authorities within 72 hours as required by GDPR.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
17. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
- Email: legal@destroy.network
- Website: https://destroy.network
For privacy-related concerns, you may also have the right to lodge a complaint with your local data protection authority.
