GUEST RECEIVING
No account, incoming only, a visible expiration.
A guest can request one unique temporary fax number and a private inbox without providing a name, email address, mailing address, or personal telephone number. Fax Me Maybe creates no authentication user or persistent personal profile. The number receives faxes for seven days by default and the exact expiration is displayed whenever the inbox is open. It is not a permanent line.
Temporary number and routing
We process the provisioned number, an immutable random callback-routing identifier, provider identifiers, activation and expiration times, and release state. Each active guest receives a unique number. At expiration the number stops delivering to that guest, remains isolated in a safety quarantine that exceeds documented callback retries, discards late incoming faxes, and is then released to the provider. Fax Me Maybe does not route a previously assigned number directly to another guest.
Private browser key
The browser creates a high-entropy access key. Only a purpose-bound cryptographic hash is stored on our server. The key is kept in the guest's browser and can be saved in a locally generated recovery file; the private URL carries it after the # fragment so it is not sent in ordinary page requests. It mints a short-lived, HttpOnly, SameSite=Strict inbox session. Because no account or contact information is collected, Fax Me Maybe cannot recover the inbox if the browser key and recovery file are both lost.
Received fax and document
A sender—not necessarily the guest—provides the document, destination number, and possibly a caller number. Caller ID may be missing or spoofed. We authenticate the provider callback, download the original into bounded private processing memory, validate its true PDF type, scan it for malware, and rasterize every page into a new metadata-stripped PDF. Only that sanitized copy is stored in the private guest-inbox bucket. Scanning reduces risk but cannot guarantee that every downloaded file is harmless.
Downloads and deletion
The inbox exposes sanitized documents only after private session authorization and through bearer signed URLs valid for at most 60 seconds. Documents, caller information, fax status metadata, browser-key hashes, and inbox sessions become inaccessible and are deleted or scrubbed when the inbox expires. Recovery files, clipboard copies, and documents already downloaded to a guest's device are outside server-side deletion. Minimal random routing tombstones and the quarantined number may remain longer solely to discard late callbacks and release the provider resource safely.
GUEST SENDING
No account, outgoing only, temporary processing.
A guest provides a destination fax number, a confirmation email, and a supported document. Fax Me Maybe does not ask for a name, mailing address, or personal telephone number, and does not create an authentication user, profile, dedicated fax number, inbox, or permanent history.
Destination number
The complete number exists in request memory long enough to validate and transmit the fax, and the fax provider receives it. The application database stores a keyed destination fingerprint for short-lived rate limits and a separate keyed repeat-submission fingerprint derived from the destination and document digest. The destination fingerprint is cleared at confirmed delivery or failure; the repeat-submission fingerprint is scrubbed at expiry.
Uploaded document
The original bytes are processed temporarily in request memory, a private malware scanner, and a renderer-specific security sandbox while the upload is type-checked, malware-scanned, and rebuilt as a generic PDF; the browser replaces the local filename before sending. Scanner work files, if any, are confined to isolated non-swapping ephemeral storage, deleted when scanning completes, and covered by the same 24-hour outer deletion deadline. The renderer cannot access the network or application secrets and receives only a minimal read-only runtime plus bounded ephemeral workspace that cannot swap or spill to persistent storage. Images and every PDF page are rendered into fresh pixels, so source metadata, attachments, hidden resources, and interactive content do not enter the transmitted copy. Only the prepared copy and its integrity digest are stored in a private guest-only bucket, and the provider receives it as a direct private upload—never through a public document URL.
Abuse-prevention signals
The network address is used in memory for bot protection and converted into a keyed hash that rotates daily for rate limits; IPv6 addresses are grouped at the /64 network level to prevent address rotation from bypassing those limits. Only minimal outcome and lease data is kept. These security records automatically expire within 24 hours and are not joined into a visitor profile.
Delivery status
A random one-time token grants a temporary, purpose-limited status session. The confirmation address is envelope-encrypted until we send the final delivered or failed result, then it is scrubbed; it is always scrubbed at fax expiry. Delivery is reported only after provider confirmation, while a definitive local or provider rejection may produce a failed result. The transactional email processor receives only that address and terminal result, never the fax document, destination, or private status link. Short-lived idempotency, provider, callback, email-job, and deletion-lease records prevent duplicate transmission or duplicate notices and track cleanup. The status view exposes only queued, sending, delivered, or failed. It never reveals the destination, filename, document, provider identifier, or failure detail.
DELETION SCHEDULE
Terminal deletion first. Sensitive state expires by the deadline.
For guest sending, the local document and the fax provider's transmitted file are queued for deletion as soon as delivery or failure is confirmed. A cleanup job runs every 15 minutes and retries failures. Guest status credentials, destination and repeat-submission fingerprints, encrypted confirmation address, document digests, and status access are irreversibly scrubbed by expiry. In normal operation the document metadata, callback records, and guest row are then hard-deleted. If a deletion call fails, status access and identifying fingerprints still expire, while service-only cleanup metadata and the inaccessible private object remain only long enough to retry deletion; they cannot create a profile or restore the status link. Live guest sending must remain disabled unless the configured provider's destination-data retention is contractually limited to the 24-hour window and independently enforced storage, replica, backup, and log lifecycles guarantee the same deadline. Guest receive content and inbox access are revoked at the displayed seven-day deadline. Local sanitized documents and fax metadata are then deleted, while the number remains provider-controlled and isolated only through its safety quarantine. Provider file deletion is requested promptly after a safe sanitized copy is stored. Because some fax providers do not expose an API to erase every live-fax metadata field, live guest receiving remains disabled unless provider retention is contractually confirmed and accurately disclosed; the site does not promise deletion that its provider contract cannot enforce.
PROCESSORS AND PURPOSES
Who processes a guest fax.
- Hosting and private storagereceive requests and hold temporary sanitized documents for transmission, guest-inbox access, and deletion retries. Guest objects are never exposed through permanent public URLs.
- Cloudflare Turnstileprocesses bot-protection signals such as the network address, TLS fingerprint, User-Agent, and site key/origin. Fax Me Maybe does not send Turnstile the destination, document, or application retry key. These signals are separate from the guest fax records covered by our 24-hour schedule and instead follow Cloudflare's purpose-based retention practices described in the Cloudflare Turnstile Privacy Policy.
- The malware scanner and isolated rendererrun in private infrastructure and check/rebuild the upload before it can reach the fax provider. Scanner work storage is private, ephemeral, non-swapping, and deletion-bounded; samples are not submitted for vendor analysis and document content is not logged. The renderer runs under a dedicated unprivileged identity with no network or application-secret access, a minimal read-only runtime, restricted system-call and process namespaces, whole-process resource ceilings, and bounded ephemeral no-spill workspace.
- The fax providerreceives the prepared document, destination, and platform-controlled caller ID to send a fax; for receiving, it provisions the temporary number, routes inbound faxes to the unique signed callback, supplies the received file, and processes file deletion and number release.
- The transactional email processorreceives the required confirmation address and only the final delivered or failed result. It does not receive the fax document, destination number, private guest status link, or account history. The delivered email itself may remain in the recipient's mailbox and follows the processor and mailbox provider's retention practices.
Guest fax content, numbers, and security signals are not used for advertising, AI training, marketing audiences, cross-site tracking, or behavioral/product-analytics profiles.
REGISTERED SERVICE
Account-based fax and messaging.
Registered customers create an account and may receive a dedicated fax number, an incoming inbox, sent history, account settings, stored documents, contacts, and one-to-one SMS/MMS conversations. Messaging is never available in guest mode and activates only after number capability, carrier registration, and abuse controls are approved. Consent records, recipient opt-outs, STOP/START/HELP policy events, message status, provider identifiers, and private sanitized MMS attachments are processed to operate that service. Marketing messaging is disabled; registered message data is not used for advertising, training, or behavioral profiles. Those records are linked to the authenticated account and follow the registered-service retention and deletion controls—not the guest 24-hour schedule. Every registered number, inbound fax, outbound fax, and document remains isolated by authenticated ownership. Outbound fax confirmation is sent only to the verified email address already attached to the signed-in account. Guest submissions and temporary inboxes are never copied into a registered account automatically.
Windows and macOS sign-in uses a separate revocable desktop credential stored in the operating system credential vault. The server retains only a cryptographic digest, device label, app/platform version, last-use time, expiry, and revocation state. Desktop content is requested from the authenticated server API and is not kept as an unencrypted local archive. Users can review and revoke these sessions in account settings.
PAYMENTS
No card fields on Fax Me Maybe.
The current guest form does not collect payment details. If guest payment is introduced, checkout must use Stripe-hosted Checkout. Stripe—not Fax Me Maybe—would collect and store card details. Payment fulfillment would be driven by verified, idempotent Stripe webhooks and would not create a Fax Me Maybe user profile.
Choose a temporary workflow.
Guest sending asks for a destination, temporary confirmation email, and document. Guest receiving creates a private seven-day number and inbox key.