This Privacy Policy explains how MeshChat AI ("MeshChat", "we", "us") collects, uses, shares, and protects personal data when you use our website and web application (together, the "Service"). Where required by law, we obtain consent before processing.
Overview
- Controller. MeshChat AI acts as the data controller for personal data processed via the Service. Contact: [email protected]. Registered address: Nikou Parttihi 105, Office 1-2, 3070, Limassol, Cyprus.
- EU/UK Representative & DPO. If appointed, we will publish details here: [email protected].
- DSA Single Point of Contact (EU). [email protected] (or [email protected]).
- Scope. This Policy covers properties we control. It does not apply to third-party websites/services we do not control.
- AI disclosure. We route your Inputs (prompts, files) to third-party AI model providers to generate Outputs; some providers may process limited logs under their terms.
What We Collect & Legal Bases
- Account & Contact Data. Email, display name/alias, avatar (optional), OAuth subject ID; password hash if password login is offered. Purposes: account, authentication, support, notices. Bases (GDPR): Contract; Legitimate interests (security).
- Billing & Transaction Data. Subscription tier, purchase history, invoices/receipts, tax/VAT info, last 4 digits or tokenized instrument as returned by processors. Purposes: billing, accounting, fraud prevention, tax compliance. Bases: Contract; Legal obligation; Legitimate interests (anti-fraud).
- Usage & Log Data. Request metadata (timestamps, model used, tokens/credits consumed), event logs, crash/diagnostic data, cookie IDs. Purposes: operate, rate limiting, troubleshooting, analytics, abuse detection. Bases: Legitimate interests; Legal obligation (where logs required).
- Technical Data. IP address, device/browser type/version, OS, locale, referrer/UTM, screen size, session IDs, approximate region. Purposes: security, localization, performance, abuse prevention. Bases: Legitimate interests; Legal obligation (security logging).
- Inputs & Outputs. Content you submit and receive in chat, search, or generation features. Purposes: perform the Service; history; safety monitoring (automated/manually) to enforce Terms. Bases: Contract; Legitimate interests (safety/abuse prevention); Consent where required for optional features. Training: We do not use your Inputs/Outputs to train MeshChat models unless you opt in. Some model providers may process logs under their policies.
- Communications & Marketing. Support tickets, feedback, NPS/CSAT, email engagement (opens/clicks) if permitted. Purposes: support, product research, direct marketing where permitted. Bases: Legitimate interests; Consent for electronic marketing in EEA/UK (opt-out anytime).
How We Use Personal Data
- Provide and operate the Service (test delivery, reports, AI coaching, updates)
- Secure the Service (abuse detection, rate limits, incident response)
- Improve features and quality (aggregate analytics; A/B tests with consent where required)
- Communicate about account, policy changes, security, and support
- Process payments, taxes, refunds, chargebacks
- Comply with law, enforce Terms, and protect rights/safety
Automated Moderation & Anti-abuse
Automated systems may flag policy-violating content (e.g., malware, exploitative/illegal content). Outcomes may include warnings, temporary blocks, rate limits, or content removal. You can contest outcomes via [email protected]. We do not make decisions with legal or similarly significant effects solely by automated means.
Sharing & Disclosures
- Service Providers (contracted sub-processors). Hosting/infra: Vercel (vercel.com). Email delivery: Resend (resend.com). Payments: Stripe (stripe.com). Analytics: Google Tag Manager (tagmanager.google.com) to load tags; Google Analytics 4 via server-side Measurement Protocol (analytics.google.com); Vercel Analytics/Speed Insights (vercel.com/analytics). Advertising/measurement: Meta Pixel and Conversions API (facebook.com/business/tools/meta-pixel). AI model providers: see "AI Providers".
- Compliance with Laws. When required by law, regulation, legal process, or governmental request.
- Business Transfers. In connection with a merger, acquisition, or sale of assets.
Payments
We do not collect or store full payment card numbers. Stripe processes payment information directly. We receive limited metadata (e.g., masked digits, status, subscription identifiers) for billing records and fraud prevention. Stripe maintains its own privacy and security controls (see stripe.com).
Analytics & Advertising
- GTM. Google Tag Manager helps manage client-side tag loading. GTM itself does not set cookies; it loads tags that may set cookies if enabled.
- GA4. We use server-side Measurement Protocol for essential product analytics with non-personalized ads; event payloads avoid unnecessary PII. Where applicable, client GA4 cookies may be set if consented.
- Meta CAPI. We may send hashed user identifiers (e.g., SHA-256 of email or internal ID), server event metadata, and, if available, first-party _fbp/_fbc values to improve event match quality. We do not transmit plain-text emails. We store _fbp/_fbc tied to your account solely for measurement and only when you are signed in; values are validated and size-limited.
- Vercel Analytics/Speed Insights. Used for performance/usage metrics; these are cookie-less.
AI Providers (Model Provider Appendix)
Providers may include OpenAI, xAI, Anthropic, Google (Gemini), Groq, Mistral, and image models via Together AI (e.g., black-forest-labs/FLUX series). Processing may occur in the US, EEA/UK, or other regions depending on capacity. We aim to enable no-training/zero-retention where supported; if limited retention is necessary (e.g., abuse/fraud prevention), we minimize scope and duration.
International Transfers
When we transfer personal data internationally, we rely on appropriate safeguards (e.g., SCCs/UK IDTA or equivalent). Our DPA is available upon request: [email protected].
Your Rights
- Access, rectify, erase, restrict, object, data portability
- Withdraw consent where applicable (withdrawal does not affect prior lawful processing)
- Object to direct marketing at any time
California (CPRA) Notice at Collection
We do not sell personal information and do not share personal information for cross-context behavioral advertising without consent where required. We honor Global Privacy Control (GPC) signals. Categories, purposes, and retention are mapped in the Retention Schedule below.
Children's Privacy
The Service is not intended for children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal data from such users. In the EEA, the default age of consent is 16 (Member States may set a lower age, not below 13). Where required, we will obtain verifiable parental consent.
Security
We implement appropriate technical and organizational measures, including encryption in transit, least-privilege access, access logging, monitoring, and periodic assessments. No method is 100% secure. We will notify users/regulators of data breaches without undue delay where required.
Retention Schedule
- Account & content: While the account is active; upon deletion we delete or anonymize, subject to legal retention.
- Logs/diagnostics: 90 days (extendable for security/incidents).
- Billing/tax records: 7 years (or statutory period).
- Backups: 35 days rolling; overwritten per schedule.
- Inputs/Outputs/history: Until you delete them or your account; we may purge inactive content after 18 months with prior notice.
- Meta cookies stored server-side (_fbp/_fbc for signed-in users): for measurement only; typically up to 13 months or until account deletion.
Cookies & Tracking
Strictly necessary cookies enable login, security, and core functionality. Analytics/marketing cookies are used only with consent where required. Manage preferences in your browser settings. To request changes to non-essential cookies or withdraw consent, email [email protected]. We honor Global Privacy Control (GPC). Disabling cookies may impact functionality.
- Strictly Necessary: better-auth.session_token (first-party, HttpOnly, Secure, SameSite=Lax) for authentication; admin-session (first-party, HttpOnly, Secure, SameSite=Strict) for admin access.
- Preferences: meshchat-selected-model (first-party) to remember your preferred AI model (up to 12 months).
- Analytics (with consent): _ga, _ga_<container> (up to 13 months); _gid (24 hours).
- Advertising/Measurement (with consent): _fbp (3 months); _fbc (up to 90 days from ad click).
- Payments (Stripe): __stripe_sid (~30 minutes); __stripe_mid (~1 year), used for session and fraud prevention on checkout or Stripe-hosted pages.
- Vercel Analytics/Speed Insights: cookie-less.
Do Not Sell or Share
Do Not Sell or Share My Personal Information: We do not sell personal information and do not share personal information for cross-context behavioral advertising. To exercise applicable opt-out rights, email [email protected].
Moderation Complaints (EU DSA)
If we take a moderation action affecting you, submit an internal complaint via [email protected] within 6 months. We will review and respond promptly and objectively. This is without prejudice to judicial remedies or out-of-court dispute settlement bodies.
Changes to This Privacy Policy
We may update this Policy. For material changes we will provide advance notice in-Service and/or by email and indicate the effective date.
Contact
Privacy inquiries & data subject requests: [email protected]
Security/vulnerability reports: [email protected]
General support: [email protected]
EU/UK representative (if appointed): Not currently appointed. For EU/UK inquiries, contact [email protected]
DSA single point of contact: [email protected]
Registered address: Nikou Parttihi 105, Office 1-2, 3070, Limassol, Cyprus
DPA (with SCCs/UK IDTA) available on request via [email protected]