How anonymity works here
Five steps, and then the part that usually gets left out: what this does not cover.
- 1
Verify your airline email
We send a code to your work address to confirm you actually work where you say you do.
- 2
Your browser creates a blinded credential
We sign something we cannot read. The signature proves you verified; it tells us nothing about who you are.
- 3
We delete your address
The moment your credential is issued, the address is gone. We keep a one-way fingerprint so the same address cannot claim a second credential.
- 4
You pick a handle and a password
Your account is created by spending that credential, so it is not connected to the address that earned it. We never learn your address, which is also why there is no password-reset email — you get a one-time recovery phrase instead, and it is the only way back in.
- 5
You write your reviews
Each one arrives with nothing tying it to any address we ever saw. You can attach your handle or post any individual review without it.
What the name check does and does not catch. Before a review is published, we run an automatic check for names and other identifying details. It is uneven, and it is worth knowing where. It is at its best when a name sits straight after a job title — “my manager Tom”, “the purser ANA”. In our own testing that shape was caught every time.
It is weaker everywhere else. A name simply doing something — “Tom shouted at me”, “Sam was rude” — gets past it somewhere between a third and a half of the time, depending on the sentence, when it is written in ordinary capitals. A full first and last name is usually caught but not always, and names that are not Anglo do clearly worse — in our own testing every Anglo full name we tried was caught, while several non-Anglo ones were missed in every sentence we tried them in. A name written only as a place, in capitals — “I was based at TOM” — is not caught at all. So please read your review once before you publish it. We keep working on this, but the check will never be airtight.
What “we cannot link it to you” covers. The cryptography is the strong part, and it is real: we sign your credential without being able to read it, and nothing we store pairs a review with a verification — no shared column, no shared key, no identifier in common. What we will not claim is that we ourselves could learn nothing at all. Our database writes rows in the order they arrive, and that physical order can be read by anyone able to query the database — which includes us. It is a hint, not a stored link: far weaker, and it names nobody by itself. But we have not erased it, and we would rather tell you than let you assume otherwise.
What having an account changes. Reviews you post under your handle are linked to each other, because they are all under the same handle. That is new — before accounts existed, each review stood alone. The link between your account and the address that created it is still destroyed, so this does not tell us who you are. But someone reading your handle’s history sees every base you have reviewed, and at a small base that pattern can be enough on its own. If that matters for a particular review, post that one without your handle attached — the option is on the review form, and using it still counts as your contribution.
Treat all of this as a backstop, not a shield. You are the last line of defence: do not name managers, colleagues, or anyone else, even though we try to catch it if you slip. More broadly, nothing stops someone recognising you from what you write — avoid details only a handful of people could know. In some countries, criticising an employer online carries legal risk regardless of how well we protect your identity — that risk is yours to weigh, and we would rather say so than let you find out later.
Read all of that and still want in? Verify and join free.