Privacy and security
You decide who holds your address.
What MailKey shares
Version 1 shares a name and a mailing address, nothing more. MailKey does not ask for a date of birth or a government ID. Later versions may add a primary email and a phone number, and you would choose what each business or friend receives.
Who can see it
- Nobody can look you up without your key.
- A lookup shows only a masked preview (first name, last initial, city and state) until the person looking it up claims the record.
- Business claims are approved automatically unless you turn on approval. You can require approval for every claim.
- A wrong or rotated key looks the same as a key that doesn't exist, so guessing teaches nothing.
What you can see
- Every business and person that holds your address.
- Businesses that released it and may still keep a copy. They are labeled that way. Business terms require them to delete it.
- Every lookup of your key and every read of your address.
How it is protected
- Names and addresses are encrypted in the database with keys held outside it, on top of the database provider's own encryption at rest.
- Logs never contain names, addresses or keys.
- Sign-in uses passkeys or email codes through WorkOS, a certified vendor, so MailKey never stores a password.
Limits
MailKey never sells data. It does not verify that you live at the address you enter. The yearly confirmation, returned-mail reports and the audit trail are the checks that make up for it.
Leaving
Export everything as JSON at any time. Delete a person or your whole account and every grant is revoked, businesses are told, and your personal data is removed within 30 days.