In the browser's local extension storage, which is not synced to other devices:
You can delete the history at any time with Clear in the extension's History tab. Removing the extension deletes everything it stored.
BurnerFill sends requests to exactly one service, api.tempmail.lol:
These requests contain no information about you: not your real email address, not the website you're signing up to, not the password, and not the content of any page. The emails in a temporary inbox are held by tempmail.lol and are subject to tempmail.lol's own terms. Temporary inboxes are not private, so don't use them for anything sensitive.
No data is sold, shared with anyone else, or used for advertising, and nothing is collected by the developer.
To recognise signup forms, BurnerFill's content script runs on the pages you visit. It only acts on pages that look like a signup or verification-code form, where it fills in the temporary address, password and code. Page content is never stored beyond the debug log described above, and never sent anywhere.
If Copy OTP to clipboard is on (the default), BurnerFill writes each verification code to your clipboard when it arrives. It never reads your clipboard.
A new install starts switched off. While the power button in the popup is off, BurnerFill detects nothing, fills nothing, and makes no requests to tempmail.lol.
This page and the BurnerFill website are static files. They load fonts from Google Fonts and browser logos from jsDelivr, which receive the usual request information from your browser (such as your IP address) when you visit. The extension itself does neither.
If this policy changes, the new version will be published on this page with a new date.
← Back to BurnerFill