Home / Privacy Policy

Privacy Policy

Last updated: March 27, 2026

Thrro generates disposable @thrro.com email addresses so you can sign up for things without using your real inbox. Your credentials and settings live on your device. Emails you receive pass through our servers briefly and are deleted automatically after 24 hours. We don't run ads, we don't sell data, and we don't track you outside the extension.

What stays on your device

The following is stored locally using Chrome's chrome.storage.local API and never sent to us:

  • Your generated email addresses and encrypted account credentials
  • Identity fields you generate (name, address, phone, etc.) for auto-fill
  • Generated test card numbers — these are fake, Luhn-valid numbers used for form testing only
  • Daily stats: emails created, messages received, trackers blocked — stored locally and purged after 90 days
  • Your settings and preferences
  • Your Pro license key (stored encrypted)

All locally stored data is encrypted with AES-256-GCM. Keys never leave your device.

What goes to our servers

When you create an account or receive email, limited data passes through our infrastructure:

  • Account creation — your chosen email address and your account credentials are stored on our servers. We cannot recover your password.
  • Inbound emails — emails sent to your @thrro.com address are received and stored temporarily. They are automatically deleted after 24 hours and capped at 50 messages per account.
  • Pro license verification — when you activate Pro, your license key is verified against our licensing server to confirm it's valid. Nothing else is sent.

Third-party services

Stripe

Pro payments are handled entirely by Stripe. We never see or store your card details. Stripe's privacy policy is at stripe.com/privacy.

Permissions

PermissionWhy we need it
storageSave your accounts, settings, and cached data locally
alarmsPoll for new emails in the background and run the auto-delete timer
notificationsShow a desktop alert when a new email arrives
activeTabRead form fields on the current page when you click "Fill Page" — only runs on your action
scriptingInject your generated identity or email into form fields — only runs on your action
host_permissions (api.thrro.com)Fetch and manage your disposable email accounts and messages

Deleting your data

  • Delete an account — removes it from both your device and our servers immediately
  • Auto-delete timer — automatically removes emails from our servers after a set period
  • Uninstall the extension — removes all locally stored data. Accounts on our servers are deleted when their 24-hour TTL expires.

What we don't do

  • We don't sell or share your data with any third party for advertising or marketing
  • We don't use any analytics or tracking SDKs
  • We don't track what websites you visit
  • We don't serve ads
  • We don't read your emails — they pass through our infrastructure but we have no interface or process to view them

Children

Thrro is not intended for anyone under 13. We don't knowingly collect data from children.

Changes

If this policy changes, the updated version will be posted here with a new date. We can't notify you directly since we don't collect contact information.

Contact

Questions? Send us a message or email support@thrro.com.