Skip to main content

License

Mailwoman is dual-licensed: AGPL-3.0-only, or LicenseRef-Commercial under a paid agreement. Both branches are offered for every release, and the branch that applies to an installation is the one it can show a key for. The offer reaches the code and model artifacts Sister Software authors, to the extent it holds or controls the rights in them. Third-party components distributed with Mailwoman, and reference data you download, stay under the terms of whoever published them, and neither branch of this offer changes those terms. The two sections below, on reference data and on what a pretrained package carries, say where to read them.

The open-source branch​

Under the AGPL, three obligations attach. You keep the copyright notices (attribution). A modified copy carries the same license (share-alike). And if people use your modified copy over a network, they are entitled to its corresponding source (the source offer, section 13). mailwoman doctor reports these three by name for the installation it runs on.

Without a license key, every mailwoman command ends with a two-line notice on stderr that says so, and every HTTP response from the native API and the drop-in servers carries a Server header naming the branch and a Link: rel="license" header pointing here. JSON responses carry the same in an engine object. The notice records which branch applies, and every command runs the same with or without a key. The AGPL grants those rights directly, so exercising them requires no key.

The commercial branch​

A commercial license releases you from the source offer and the share-alike condition on the code and model artifacts we author, so you can build closed products and services on Mailwoman. The agreement you accept at checkout is the commercial license agreement, published at its own address and never edited after publication. It is the agreement that binds, and it is the document to read for what you owe and what you are owed. This page and the site terms of service describe the website and the catalog, and neither replaces a term of the agreement you accepted. What each tier covers, and the enterprise and OEM tiers, are on the pricing page.

COMMERCIAL-LICENSE.md in the repository is a reference template, and its own opening notice says it is not self-executing and grants no rights on its own. It carries the same ten sections in the same order, and four of them read differently from commercial-2026-10: the template defines the licensee generically where the published agreement identifies the entity given at checkout, the template leaves fees and term open where the published agreement states the subscription price and the key-period mechanics, and the template's attribution section carries a paragraph limiting the waiver to Sister Software's own attribution that the published agreement states only in its grant section. Read the published version for a purchase made under it. The template is where a negotiated agreement starts.

What the commercial grant does not cover​

Section 2 of the agreement limits the grant to the code and model artifacts Sister Software authors. It does not extend to third-party components distributed with Mailwoman, which stay under their own licenses, and any attribution or share-alike obligation attaching to those components continues to apply. Buying a commercial license does not waive or relicense them. THIRD_PARTY_NOTICES.md lists the components we distribute and the terms each one carries. Reference data an operator downloads separately carries the terms of whoever published it, and the next section says what those terms are for each bundle we host.

Reference data you download​

The resolver needs a gazetteer, and no npm package carries one. Four bundles are published for download (candidate, poi, fr and us), and each one contains rows another party published. Taking a copy engages that publisher's terms:

bundlepublished byterms as the publisher names them
candidateWho's On First, GeoNamesCreative Commons Zero over Mapzen's own work; Creative Commons Attribution
poiOverture Maps FoundationCDLA-Permissive-2.0
frDINUM and IGN, for Base Adresse NationaleLicence Ouverte 2.0, the attribution-only half of a dual grant
usUnited States Census Bureau; OpenAddressesTIGER/Line carries no copyright; OpenAddresses is per-source terms that differ

No command downloads a bundle for you. mailwoman serve and mailwoman geocode with no gazetteer print the command to run and stop; the download happens when you run mailwoman data pull <bundle>. Both mailwoman data --list and mailwoman data pull print each bundle's publishers, its terms, what it obliges you to do, and what nobody has established about it, before any bytes move. Two paths do fetch without a prompt and are not this command: a page running the browser engine loads its model and database assets from public.mailwoman.ai as it starts, and a map surface loads fonts and sprites from the same origin.

A commercial key does not reach any of this. The publishers above are not parties to your agreement with us, and their attribution and share-alike conditions apply to you whichever branch you are on.

What a pretrained package already carries​

A model's inputs are fixed when it is trained. Installing @mailwoman/neural-weights-en-us without pulling a single bundle still gives you artifacts built from the sources that package records, and skipping a runtime download leaves them unchanged. To use different inputs, install a different package.

Every published weights package carries two generated files in its tarball. LICENSE.md states the terms above. PROVENANCE.json records each artifact it ships with its digest or unrecorded, the sources its model card attributes with the license each one names, the base package a data-only overlay decodes through together with that base's own sources, and the questions the record leaves open. Read it as a record of what the model card holds: a package recording no attribution is a package whose card records none, which is a different statement from a package with no attributable inputs. Neither file says an artifact is cleared for a particular use.

For the installation in front of you:

mailwoman license attribution

It reads the PROVENANCE.json of every weights package present in node_modules and prints the sources, the inherited lineage, and what each record leaves unresolved. It names what it does not cover: reference data you pulled separately, and whether a recorded entry is the whole of what that source requires.

Purchase a license​

Checkout asks for the licensee's legal name and your acceptance of the commercial agreement. After payment you land on a page that shows your key and a refresh secret, and the same key arrives by email. Change the card, the plan, or cancel at the billing portal.

For enterprise terms, seats, or a negotiated agreement, email us about a license.

Configuring and checking a key​

A key is a signed token verified offline against the public keys each release ships.

export MAILWOMAN_LICENSE_KEY="mwl1.…"
mailwoman license verify --online
mailwoman doctor

license verify reports valid, expired, unknown_key or invalid, and with --online also whether mailwoman.ai still lists the key id as active and, for a self-service license, whether the license still stands. doctor reports the branch that applies and the obligations it carries. With a valid key the notice is silent and engine.license reads LicenseRef-Commercial.

Keeping the key current​

A self-service license renews with its subscription, and each renewal issues a new key whose date is the paid period's end plus 14 days. The purchase page and the first email carry a refresh secret. Adopt the key once:

mailwoman license adopt "mwl1.…" --secret "<refresh secret>"

That writes the key to $MAILWOMAN_CONFIG_ROOT/license/key, which mailwoman reads when MAILWOMAN_LICENSE_KEY is unset, and the secret to refresh.json beside it with owner-only permissions. After a renewal, fetch the current key:

mailwoman license refresh

license verify --online and mailwoman doctor report the license's online status as one word: active, lapsed, revoked, unknown, or unreachable.

Refunds and disputes​

A full refund or a payment dispute marks the license revoked online at once. The key you hold keeps verifying offline until its date: it is a signed statement about a period that was paid for when it was signed, and revoking it early would break the installation of a customer whose dispute is later decided in their favour. A dispute decided in your favour returns the license to its subscription's state. Online checks are how a revocation reaches an installation before the key's date.