PGP is the encryption layer between you and a vendor. It is the channel that is private, in a place where the rest of the conversation is visible to the platform. This is what it does, how to use it, and where people break it.

What it does

When you message a vendor without PGP, the platform can read the message. That is normal, and it is the price of the convenience. When you message with PGP, the message is encrypted with the vendor's public key, and only the vendor's private key can read it. The platform stores the ciphertext, not the content. The same applies in reverse, when the vendor writes to you.

The practical use is the delivery details. An address, a delivery instruction, a note about the package, all of it belongs in the encrypted message, because it is the part of the order that identifies you to a courier, and it is the part you do not want in the open.

Generating a key

The market generates a key pair for you in the security settings, if you do not have one. The public half is what you share, and it appears on your profile. The private half is what you keep, and it is what reads the messages. Export the private key and store it somewhere safe, because losing it means losing the ability to read the messages that were encrypted to it. The recovery words for the account cover the account, but the PGP key has its own backup, and it is the one people forget.

Messaging a vendor

Open the vendor's profile, take their public key, and compose a message in the encrypted field. The market handles the encryption. Paste the delivery details, send, and attach the message to the order. When the vendor replies, the reply is encrypted to your key, and you read it in the same field. The whole exchange is private, as long as the private key stays yours.

The mistake that undoes it

The mistake is sharing the private key, or storing it where the public key is stored. The public key is meant to be seen. The private key is meant to be kept. A private key in a screenshot, in a chat, or in a password manager that is also where you store your exchange login, is a private key that is no longer private, and the encryption it provides is the encryption of a message that someone else can also read.

The 2FA guide covers the account side, and the security basics covers the rest of the stack.