My Mail Center

[DRAFT FOR LEGAL REVIEW. This is not final and has not been reviewed by an attorney. Do not publish until counsel has reviewed and approved it. Items marked [DECISION: ...] need a business decision from the owner. Items marked [VERIFY] need a check by counsel.]

My Mail Center Privacy Policy

Last updated: [DATE] Effective date: [DATE]

This Privacy Policy explains how [Legal entity name, e.g. My Mail Center LLC] ("My Mail Center," "MMC," "we," "us") collects, uses, shares, and protects personal information in our digital mailbox service. That includes mymailcenter.net, our web app, and our iOS and Android apps (the "Service").

We are a USPS-registered Commercial Mail Receiving Agency (CMRA) with locations at 332 S Michigan Ave, Chicago, IL 60604 and 5508 S Lake Park Ave, Chicago, IL 60637.

The short version:

  • We handle your mail. That means we see who sends you mail, and we see the contents of anything you ask us to scan.
  • We use trusted service providers, including an AI provider, to run the Service. They work for us and may only use your data to provide services to us.
  • We do not sell your personal information. We do not use it for targeted advertising.
  • We do not collect biometric identifiers like face scans or fingerprints.
  • You can access, correct, and delete your data, with some limits required by USPS and tax law.

1. Information we collect

Information you give us

  • Account and contact details: name, email, phone number, mailing and home address, business name (for Business plans), password.
  • USPS Form 1583 information: everything the form requires. This includes your name, home or business address, phone, the names of anyone authorized to receive mail, business details, and details of your ID documents.
  • Identification documents: photos or copies of the two IDs USPS requires (one with a photo), such as a driver's license, passport, or state ID.
  • Notarization details: if you use an online notary, the notary provider collects information to complete the notarization (see Section 4).
  • Payment information: handled by Stripe. We do not store your full card number. We receive limited details from Stripe, such as card brand, last four digits, expiration date, and billing ZIP code.
  • Your requests and settings: scan, forward, shred, pickup, and archive requests; mail rules; forwarding addresses; notification preferences.
  • Support messages: anything you send us by email, chat, or phone.

Information created when we handle your mail

  • Envelope and package images: we photograph the outside of every item we receive for you. These images show the sender, the addressee, postmarks, and anything printed on the outside.
  • Mail log data: date received, sender, carrier, tracking numbers, size and weight, and the actions taken.
  • Scanned contents: full scans of items you ask us (or your mail rules tell us) to open and scan. These may contain sensitive information, such as bank statements, tax forms, medical bills, or legal notices.
  • AI-generated data: AI-produced text read from envelopes, summaries of scanned contents, detected due dates, and suggested categories.

Information collected automatically

  • Usage data: pages and screens viewed, features used, log-in times, and actions taken.
  • Device data: device type, operating system, app version, IP address, browser type, and crash reports.
  • Push notification tokens: identifiers from Apple or Google that let us send app notifications.
  • Cookies and similar technology: used to keep you signed in and to make the website work. [DECISION: Will you use any analytics tools (e.g. Google Analytics, PostHog)? If so, list them and add a cookie section.]

Text message consent

If you opt in to text messages, we record your phone number, the date, time, and method of your consent, and the wording you agreed to. We also keep records of opt-outs (STOP) so we stop texting you.

2. Biometric information (Illinois BIPA)

Illinois has a law called the Biometric Information Privacy Act (BIPA). It covers things like fingerprints, face geometry scans, voiceprints, and retina or iris scans.

We do not collect, capture, store, or use biometric identifiers or biometric information in the mailbox Service.

  • ID photos are pictures of documents. We store them as images. We do not scan them to create face geometry templates or use facial recognition on them. [VERIFY: confirm neither MMC nor the online notary / ID-verification provider performs facial matching or face-geometry analysis on IDs or selfies. If the notary provider does, a BIPA notice and written release are required.]
  • Face ID and fingerprint login are handled by your device. If you use Face ID, Touch ID, or Android fingerprint or face unlock to sign in to our app, that check happens on your phone, by Apple or Google. We never receive your face or fingerprint data. We only receive a yes/no result from your device.

Separate service: My Mail Center also offers biometric health screening services. Those services are not part of this mailbox Service. They have their own privacy notice and consent process, and this Privacy Policy does not cover them.

3. How we use your information

We use your information to:

  • Provide the Service: receive, log, photograph, scan, forward, shred, store, and release your mail and packages.
  • Meet USPS requirements: verify your identity, keep Form 1583 records, and report to USPS's CMRA system.
  • Match mail to you: including with AI (see Section 5).
  • Run your mail rules and send you alerts.
  • Bill you and prevent payment fraud.
  • Communicate with you: service messages, alerts, receipts, renewal reminders, and support.
  • Keep things secure: detect fraud, abuse, and unauthorized access; keep audit logs.
  • Improve the Service: fix bugs and understand which features are used. We use your data for this only within our own systems or our providers acting for us.
  • Follow the law: respond to legal requests and keep records the law requires.

[DECISION: Will you send marketing emails or texts? If yes, add an opt-in/opt-out description. Default draft assumption: service messages only.]

4. Who we share information with

We share personal information only as described here.

Service providers

These companies process data on our behalf to run the Service. They may only use it to provide services to us.

Provider What they do Data involved
Supabase Database, file storage, and authentication All account data, mail images, scans, IDs, Form 1583 data
Vercel Web hosting Usage and device data; data passing through the web app
Stripe Payment processing Name, email, billing details, card data (collected by Stripe directly)
Twilio Text messages Phone number, message content
[Email provider name] Email delivery Email address, message content
Anthropic (Claude API) AI for mail matching, summaries, and due-date detection Envelope images, scanned contents, account names for matching
[Online notary provider name] Remote notarization of Form 1583 Name, ID documents, video session, signature, as needed for notarization
Apple / Google App distribution and push notifications Push tokens, notification content
[DECISION: any others, e.g. analytics, error monitoring (Sentry), customer support tool]

Online notaries are themselves regulated and may be required by law to keep their own records of the notarization, including a recording of the session. Those records are kept under the notary's own legal duties. [VERIFY]

USPS and government

  • We provide Form 1583 information to USPS as CMRA rules require.
  • We may share information when required by law, subpoena, court order, or a valid request from law enforcement or a government agency. Where allowed, we will try to notify you first.

People on your account

People you list on your Form 1583 or add as authorized users may see mail addressed to them and other account information you allow.

Business transfers

If we sell or reorganize our business, your information may transfer to the new owner. They must honor this policy, and USPS rules on Form 1583 still apply.

What we don't do

  • We do not sell your personal information.
  • We do not share it for cross-context behavioral advertising.
  • We do not give your mail contents to anyone except as described above.

5. How AI is used

We use AI from Anthropic (Claude), accessed through its commercial API, to:

  1. Read envelope images to help match each item to the right mailbox.
  2. Read scanned contents to create a short summary and detect due dates.

What you should know:

  • AI providers act as our service providers (processors). They process your mail data only to give the results back to us.
  • Not used to train AI models. Under the provider's commercial terms as we understand them, data sent through the API is not used to train its models. [DECISION/VERIFY: Confirm current Anthropic Commercial Terms and data processing addendum, including data retention period on the provider side and any zero-data-retention arrangement. Update this statement to match.]
  • The provider may keep data for a short time for safety and abuse monitoring, as set out in its terms. [VERIFY: retention period, e.g. up to 30 days by default.]
  • Summaries may be wrong. Always read the full scan. See our Terms of Service.
  • [DECISION: Will customers be able to turn off AI summaries for their account? If yes, describe the setting here.]

6. How we protect your information

We use reasonable security measures, including:

  • Encryption in transit (HTTPS/TLS) for all connections to the Service.
  • Encryption at rest for our database and file storage.
  • Access controls: staff only access what they need for their job. Access to ID documents and Form 1583 data is further restricted. [DECISION: which roles can view ID images.]
  • Audit logs: we record who viewed or acted on mail, scans, and IDs.
  • Physical security at our locations for mail and packages. Mail is shredded with [DECISION: shredding method or vendor, e.g. cross-cut shredder or certified shredding service].
  • Secure login options, including device-based Face ID or fingerprint login. [DECISION: Will you offer or require two-factor authentication?]

No system is perfectly secure. Please use a strong password and keep your devices secure.

7. Data breaches

If a breach of security affects your personal information, we will notify you as required by the Illinois Personal Information Protection Act (815 ILCS 530). That law requires notice in the most expedient time possible and without unreasonable delay. If a breach affects more than 500 Illinois residents, we will also notify the Illinois Attorney General as the law requires. We will also follow the notice laws of other states where they apply.

8. How long we keep information

We keep information only as long as we need it for the Service, for USPS rules, for tax and legal reasons, and for security. See our Data Retention & Deletion Policy for details.

9. Your privacy rights

We give all users these rights, wherever you live:

  • Access: ask what personal information we have about you and get a copy.
  • Correction: ask us to fix information that is wrong.
  • Deletion: ask us to delete your information. (Some records must be kept. See below.)
  • Portability: download your scans and mail log in a common format. [DECISION: confirm export format and whether it is self-serve in the app.]
  • Opt out of texts: reply STOP at any time.
  • Opt out of marketing: use the unsubscribe link or app settings.
  • No discrimination: we won't treat you differently for using these rights.

How to make a request: in the app under [Account > Privacy], or email [privacy email]. We will verify your identity before acting. We aim to respond within [DECISION: e.g. 30 or 45] days.

What we can't delete right away: we must keep some records even after you ask us to delete your account. These include your Form 1583 and ID copies (as required by USPS), billing and tax records, and records needed for security, fraud prevention, or legal claims. Our Data Retention & Deletion Policy explains each one.

10. Deleting your account

You can delete your account in the app under [Account > Delete Account]. You can also email [support email].

When you delete your account:

  • Your account closes and you can no longer sign in.
  • Any remaining paid term ends. [DECISION: refund on deletion? Tie to Terms refund policy.]
  • We will delete or de-identify your mail images, scans, and AI summaries, as described in our Data Retention & Deletion Policy.
  • We keep what USPS, tax law, and other laws require, then delete it when the retention period ends.
  • Mail and packages we are still holding must be picked up, forwarded, or shredded first. Mail that arrives after closing is handled as USPS regulations require. See Section 12 of our Terms of Service.

11. Children

The Service is not for anyone under 18. We do not knowingly collect information from children. If we learn that a person under 18 has opened an account, we will close it and delete their information, except for records the law requires us to keep.

12. Text messaging (SMS) terms

By opting in, you agree to receive recurring automated text messages from My Mail Center about your mail, packages, and account at the number you provide. Consent is not a condition of purchase. Message frequency varies. Message and data rates may apply. Reply STOP to cancel. Reply HELP for help, or contact [support email].

We do not share your mobile number or text message opt-in consent with third parties for their marketing purposes.

13. Other state laws

Some states give residents more privacy rights. We extend the rights in Section 9 to everyone. If a law in your state gives you more rights, contact us and we will honor them as that law requires.

14. Changes to this policy

We may update this policy. If we make a material change, we will notify you by email or in the app before it takes effect. The "Last updated" date at the top shows the latest version.

15. Contact us

[Legal entity name, e.g. My Mail Center LLC] 332 S Michigan Ave, Chicago, IL 60604 Privacy requests: [privacy email] Support: [support email] Phone: [support phone]


Notes for counsel

  • BIPA (740 ILCS 14). The draft states no biometric identifiers are collected. BIPA's definition of "biometric identifier" excludes photographs, but courts have treated face-geometry scans derived from photos as covered. Please confirm (a) no facial matching is done on ID images by MMC, Anthropic, or the online notary / identity-verification provider (many RON platforms use ID-to-selfie face matching or KBA), and (b) device-based Face ID/Touch ID login results in no biometric data reaching MMC. Note the 2024 amendment (P.A. 103-0769) on per-person damages and electronic signature for releases. Sources: 740 ILCS 14/10 definitions; Public Act 103-0769.
  • Separate biometric screening business. Confirm that the health screening business has its own BIPA-compliant written policy and releases, and whether HIPAA applies to it. Keep data systems separate from the mailbox platform. [VERIFY]
  • Illinois PIPA (815 ILCS 530). Confirm breach-notice timing, content requirements, Attorney General notice when more than 500 Illinois residents are affected, the reasonable-security duty (530/45), and secure disposal duty (530/40). Sources: 815 ILCS 530; Public Act 101-0343 (AG notice amendment).
  • USPS Form 1583 data sharing. Confirm CMRA reporting obligations and USPS access to 1583 data under DMM 508.1.8. Sources: USPS DMM 508; 88 FR 32117 (May 19, 2023).
  • CCPA and other state laws. MMC may fall below CCPA thresholds, but rights are offered voluntarily. Confirm the "no sale/no sharing" statement is accurate given any analytics or advertising pixels used on the website.
  • AI provider terms. Confirm current Anthropic Commercial Terms of Service and Data Processing Addendum regarding no training on API inputs/outputs, provider-side retention period, and subprocessors. Consider a zero-data-retention arrangement given sensitive mail contents. Source: Anthropic Commercial Terms; Anthropic Privacy Center.
  • Supabase, Vercel, Stripe, Twilio, email provider DPAs. Confirm DPAs are in place and data region (US) is configured.
  • TCPA and 10DLC. Confirm SMS opt-in wording matches the registered campaign. The "no sharing of mobile opt-in data" sentence is commonly required by carriers for 10DLC approval.
  • Apple and Google requirements. Apple App Store Review Guideline 5.1.1(v) requires in-app account deletion; Apple's App Privacy "nutrition label" and Google Play's Data Safety form must match this policy. Source: Apple App Review Guidelines.
  • Sensitive mail contents. Scans may include health, financial, and government ID information belonging to the client or third parties. Consider whether any additional obligations are triggered by handling third parties' sensitive data in scans (e.g. Social Security and account numbers that appear in scans are "personal information" under 815 ILCS 530). [VERIFY]