mesh.me Privacy Policy
Your data should stay legible to you.
Last updated: July 19, 2026
This policy explains how Mesh.me collects, uses, shares, retains, protects, exports, and deletes your data — and the rights and controls you have over it. The product goal is privacy-first operation with user-visible controls, not hidden exploitation.
Section 1
1. Information we collect
Account data. When you create a Mesh.me account we collect what is needed to operate it — your email address, username, display name, and a hashed (never plaintext) password. We may use email or phone-number verification to help prevent abuse and secure your account.
Profile and content. Optional profile details you provide (bio, location, website, avatar, banner image, accent color, interest tags) and the content you create — posts, comments, messages in MeChat, community activity, and your Meshi customization.
Connected accounts. When you connect a third-party platform (Instagram, TikTok, YouTube, X/Twitter, Threads, Facebook, Snapchat, Discord, Twitch, Reddit, LinkedIn, or Pinterest), we store the platform name, your platform username/ID, and encrypted OAuth tokens for the scopes you explicitly authorize, plus the specific content those scopes let you view or manage inside Mesh.me.
Payment data. MeshPro payments are processed by Stripe. We receive limited billing metadata (such as subscription status and the last four digits/card brand) but we do not receive or store your full card number.
Age-verification status. If you opt into age-restricted content, identity/age verification is performed by a third-party verifier. We receive only a pass/fail verification status — we do not receive or store your ID document.
Usage and technical data. For operating, securing, and debugging the Service we collect data such as pages visited, features used, device type, browser, operating system, approximate location derived from IP, and IP address.
Section 2
2. How we use your information
We use your information to operate and personalize Mesh.me; power the Mesh, Feed, MeChat, Communities, Analytics, and Meshi experiences; support connected-platform features you enable; process MeshPro subscriptions through Stripe; communicate with you about your account and security; and improve the Service.
We also use data to detect and prevent abuse and fraud, maintain security, enforce our Terms and age-verification requirements, and comply with legal obligations.
Mesh.me does not use your data to sell advertising, build third-party advertising profiles, or engage in data-broker monetization, and we will never sell your personal data. This is a permanent, foundational commitment.
Section 3
3. Legal bases for processing (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we process your personal data on these legal bases: performance of a contract (to provide the Service you request); legitimate interests (to secure, improve, and protect the Service, balanced against your rights); consent (for optional features such as connecting a third-party account or opting into age-restricted content, which you may withdraw at any time); and legal obligation (to comply with applicable law).
Section 6
5a. Meshi and AI processing
Meshi's replies are generated by a third-party AI provider, OpenAI. When you ask Meshi something we send that provider what you typed, your username and display name, and — where it is needed to answer — grounding context from your Mesh: your follower, following, post, community and platform counts; the names, handles and follower counts of up to 40 people or communities visible to you at the time; and the post you are looking at, including its author and up to 900 characters of its text. Recent turns of the same conversation go with it.
You control the context. The Meshi memory rule in your privacy controls governs it. Set it to hidden and Mesh.me stops looking your Mesh up and stops sending it — no counts, no names, no post text, no conversation history. What you typed and your display name still reach the provider, because that is the question being answered; if you do not want something sent, do not type it. Turning the rule off does not delete anything already sent.
Other people's data. Your own choice does not speak for anyone else, so before any third party's name, handle or post text is included we check their Meshi memory rule and drop it if they have switched it off.
Meshi's journal. Separately from the read rule above, you can let Meshi keep a small durable journal — only things you explicitly dictate (“remember that…”), never anything inferred or observed. Every entry is listed in your privacy controls and individually deletable, and turning the journal off deletes every entry immediately and permanently — unlike the read rule, which stops future sending but cannot recall what a provider already received.
Not every reply involves the provider — some Mesh.me answers entirely from your own data without contacting it. We do not send your MeChat messages, mirrored platform DMs, email address, password, payment details or connected-platform tokens; we do not use the output to build advertising profiles; and we do not sell any of it.
Section 7
6. Connected platforms and third-party API compliance
When you connect a third-party account, Mesh.me uses that platform's official API only for the scopes you authorize, and only to power the features you use inside Mesh.me. We do not use connected-platform data for advertising, and we do not transfer or sell it.
Google API Services Limited Use. Mesh.me's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google (including YouTube) is used solely to provide and improve the user-facing features you request, is not transferred to third parties except as necessary to provide those features or as required by law, is not used for advertising, and is not read by humans except with your consent, for security purposes, or to comply with applicable law.
Meta platforms. For Facebook, Instagram, and Threads, removing Mesh.me from your platform account triggers automatic deletion of the associated connected-account data through our data deletion and deauthorize callbacks. You can also request deletion at any time from the Data Deletion page.
Section 8
7. Data retention and deletion
We retain information while your account is active and as needed to provide the Service. If you delete your account, we delete or anonymize personal data within 30 days, except where longer retention is required by law. Connected-platform tokens are deleted immediately when you disconnect an account, and backup or cached copies are purged within 90 days.
For step-by-step instructions on deleting your account, removing a single connected platform, or how platform-initiated deletion works, see our Data Deletion page. You can also request a copy (export) of your data through product settings.
Section 9
8. Your privacy rights and choices
You can review and update your profile, visibility settings, connected accounts, message permissions, notifications, and data controls from product settings at any time.
Depending on where you live, you may have rights to access, correct, delete, restrict, or export your personal data, to object to certain processing, and to withdraw consent. EEA/UK residents have these rights under the GDPR and may lodge a complaint with their local supervisory authority. California residents have rights under the CCPA/CPRA to know, access, delete, and correct personal information and to opt out of "sale" or "sharing" — Mesh.me does not sell or share personal information as those terms are defined, and we do not discriminate against you for exercising your rights.
To exercise any right, use the controls in settings or contact security@meshs.me. We will verify your request and respond within the timeframe required by applicable law.
Section 10
9. Children's privacy
Mesh.me is not directed to children under 13, and you must be at least 13 to use the Service. We do not knowingly collect personal information from children under 13; if we learn we have, we will delete it. Age-restricted (NSFW) content is limited to verified users who are at least 18. If you believe a child under 13 has provided us information, contact security@meshs.me.
Section 11
10. International data transfers
Mesh.me is operated from the United States, and our subprocessors may process data in the United States and other countries. If you access the Service from outside the United States, you understand your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Where required, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) for international transfers.
Section 12
11. Security, changes, and contact
We apply industry-standard safeguards including password hashing, encrypted OAuth-token storage, HTTPS transport security, secure HTTP headers, CSRF protection, rate limiting, and input validation across endpoints. MeChat conversations are restricted to their members, connected-platform tokens are encrypted at rest, and payment details are handled by Stripe rather than stored by Mesh.me. No internet service can guarantee absolute security.
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date below and, where appropriate, provide additional notice. If you have privacy questions or want to exercise your rights, contact security@meshs.me.
Need the product controls too?
The policy pages explain the rules. The Trust Center and in-app controls show how the product exposes them.