Privacy Policy
Last updated: September 21, 2026.
Sister Software is currently operated by Nirrus LLC, a Delaware limited liability company.
Mailwoman is self-hosted software. We do not operate a hosted geocoding service, and ordinary use of Mailwoman does not send your addresses, coordinates, queries, customer records, or other workload data to us.
Your workload stays on your infrastructure
Mailwoman runs on infrastructure you control.
The published libraries, CLI, browser engine, and self-hosted API servers contain no usage telemetry, behavioral analytics, crash reporting, or query harvesting, and none of them transmits the content of a parse or geocode request to Sister Software.
When you parse or geocode an address with Mailwoman, that operation occurs locally on your computer, browser, server, or other infrastructure.
We therefore do not receive or maintain:
- addresses you geocode;
- coordinates returned by Mailwoman;
- customer or subscriber records processed through Mailwoman;
- geocoding query histories;
- usage volumes; or
- datasets you process locally.
If information never leaves your infrastructure, Sister Software is neither receiving nor processing that information.
Requests that do leave your infrastructure
Four activities send a request to a server. Each one carries the request metadata any web request carries, such as an IP address, a request time, and a requested URL. None of them carries the content of a parse or geocode request.
- Installing from a package registry. npm, or whichever registry you configure, receives the request. Its operator's policy governs it.
- Downloading a reference-data bundle.
mailwoman data pullrequests the bundle's objects frompublic.mailwoman.ai, which is served through Cloudflare R2. Only that command downloads a bundle. A Mailwoman server started without a gazetteer prints the command and stops. - Running the browser engine or a map surface. A page that loads the browser engine requests its model and database assets from
public.mailwoman.aias it starts, and a map surface requests fonts and sprites from the same origin. These requests happen without a prompt, and they identify which assets a visitor's page loaded. - Optional online license actions.
mailwoman license verify --onlineandmailwoman license refreshcontact Sister Software infrastructure and send the license information the request needs. A key verifies offline without them.
A third-party network provider or content-delivery network in front of any of these endpoints may keep its own request records under its own policy.
Where our training data comes from
The records Mailwoman is trained on are separate from anything you send us, and this section is about the former.
We obtain address records from public and third-party sources to build training corpora and the pretrained models we publish. Those records are not customer queries. Ordinary self-hosted use transmits no query to us, so no customer query can reach a corpus. That fact does not establish that a corpus contains no personal data, so this section states the two claims separately.
The register of candidate sources is public, at packages/corpus/data/address-source-register.json. It holds 389 sources. As of this update, the register records a license decision for none of them and marks none of the 389 as eligible for ingest, so no source in that register has contributed to a published model.
The assessment of personal data in training sources is incomplete. Some candidate registers, such as the French SIRENE enterprise register, carry records about sole traders that identify a natural person at a business address. We have not completed a purpose, category, role, lawful-basis, retention, and individual-rights analysis for that class of source, and this Policy does not assert one.
The ingest process enforces that incompleteness. Each source in the register carries a personal-data review with one of three outcomes: a review that found no record about an identifiable person, a review that found such records, or a completed analysis that states where it is recorded. The first and third outcomes admit a source for ingest. The second refuses it, and so does a missing review, because an unexamined publication has not been found clear. All 389 sources are refused on that ground today. This rule keeps such a source out of any corpus built from now on. It makes no statement about a model already published.
Where a published model was trained on address records, we cannot at present recover an individual record from the trained weights, and we do not claim that the weights are anonymous within the meaning of any particular law.
Information you provide directly to us
We may receive limited personal information when you choose to interact with us directly.
This may include:
- your name and email address;
- company or organisation information;
- correspondence with us;
- support requests;
- information submitted during a commercial inquiry or pilot; and
- billing or licensing information associated with a commercial license.
We use this information only as reasonably necessary to respond to you, provide requested services, administer commercial relationships, comply with legal obligations, and maintain business records.
Commercial licensing
Mailwoman's commercial licensing system is separate from the geocoding engine.
If you purchase a commercial license, we may maintain records such as:
- licensee name;
- email address;
- company name;
- subscription and plan information;
- license identifiers and status;
- invoice and transaction identifiers; and
- records necessary to issue, renew, verify, or support a commercial license.
Payment processing is handled by third-party payment providers such as Stripe.
These systems do not receive your Mailwoman geocoding queries or datasets.
Mailwoman license keys verify locally. Optional online license-management actions, such as checking license status or refreshing a license, may contact Sister Software infrastructure and transmit the license information necessary to perform that request.
Website and infrastructure
Our websites and supporting infrastructure may process ordinary technical information required to deliver and secure a web service, such as IP address, request time, requested URL, and similar network metadata.
We do not use Mailwoman websites to create advertising profiles or track users across unrelated services.
We do not use tracking cookies or behavioral advertising cookies.
Customer projects and pilots
If you participate in a design-partner program, support engagement, evaluation, or other commercial project, you may choose to provide data to us directly.
That is separate from ordinary Mailwoman operation.
Any customer data provided for such an engagement remains subject to the applicable agreement. We do not acquire ownership of customer address lists, subscriber records, network data, or other business information merely because it is supplied to us for a project.
For engagements involving substantial personal data, we may enter into additional confidentiality, security, retention, or data-processing terms.
How we use information
We may use information provided directly to us to:
- respond to inquiries;
- provide support;
- administer commercial licenses;
- process purchases and subscriptions;
- conduct agreed evaluations or commercial work;
- maintain accounting and business records;
- prevent fraud or abuse;
- comply with legal obligations; and
- enforce our agreements.
We do not sell personal information.
We do not sell Mailwoman query data.
We do not use customer geocoding queries for advertising or model training because ordinary Mailwoman queries are not transmitted to us. That statement is about customer queries. What our training corpora are built from is described under "Where our training data comes from".
Service providers
We use third-party providers where necessary to operate our business and infrastructure.
These may include providers for:
- payment processing;
- website and network infrastructure;
- email delivery; and
- commercial license management.
Those providers receive only the information necessary to provide the relevant service.
Data retention
We retain information provided directly to us only for as long as reasonably necessary for the purpose for which it was collected or as required for legal, accounting, security, or contractual reasons.
Mailwoman workload data processed entirely on your infrastructure is not subject to our retention practices because we never receive it.
Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to our processing of personal information about you.
These rights apply only to information we hold.
Because Mailwoman normally processes your workload locally, we cannot access, export, correct, or delete addresses or queries that were never transmitted to us. Data held inside an installation you operate is yours to act on. We have no access to it and cannot act on it for you.
For a record in a public source we used to build a corpus, write to the address under "Contact". We will identify what we hold, what we can remove from a corpus we still hold, and what a published model retains. We do not claim an ability to delete a record from weights that are already published.
International processing
Sister Software is currently operated by Nirrus LLC in the United States.
Information you provide directly to us may be processed in the United States or other locations where our service providers operate.
Where applicable law requires safeguards for international transfers, we will use an appropriate legal mechanism.
Changes to this Policy
We may update this Policy as our services, providers, or legal obligations change.
If responsibility for the services covered by this Policy moves from Nirrus LLC to another legal entity, we will update this Policy accordingly.
Contact
For privacy questions or requests:
Sister Software currently operated by Nirrus LLC, a Delaware limited liability company
support [at] sister [dot] software