Last Updated: August 10, 2026
Effective Date: August 10, 2026
Data Controller: MeshAI Labs
Contact: privacy@meshai.dev
Account Data: Email address, company name, API keys (hashed, never stored in plaintext).
Agent Metadata: Token counts, cost estimates, latency, model names, error types, and governance evidence.
Optional Sanitized Inputs: Payload capture is off by default. A customer administrator can explicitly enable capture of supported input fields from proxy requests and OpenTelemetry attributes. Mandatory and customer-defined redaction runs before storage, but sanitized inputs may still contain personal data and are not anonymous or guaranteed PII-free. Provider outputs and completions are never captured by this feature.
Newsletter: Email address only.
We do not capture provider outputs, completion content, or general conversation history through payload capture. When optional input capture is enabled, supported sanitized inputs may contain customer or end-user personal data.
MeshAI processes optional sanitized inputs as a processor on the customer's documented instruction. The customer must define the processing purpose and determine and document an applicable lawful basis before enabling capture, including any additional conditions or authorization required for special-category or criminal-offence data. Enabling the setting is not proof of consent or another lawful basis.
All data encrypted at rest (AES-256) and in transit (TLS 1.2+). API keys hashed with bcrypt.
Operational data is retained per plan (30 days to 6 months). Audit trails are retained per applicable record-keeping requirements. Optional sanitized inputs use the customer-selected 1-to-30-day setting, capped by plan. Disabling capture stops new capture after services observe the change, but in-flight or queued work may finish. Existing records remain eligible for scheduled deletion after their recorded expiry; deletion may not occur at that exact instant.
For access, rectification, erasure, portability, restriction, or objection, contact privacy@meshai.dev. There is no self-service sanitized-payload read, export, or delete endpoint. Requests involving captured inputs require a scoped support process, coordinated with the customer controller and using available tenant, agent, request or trace identifiers, and dates. We respond within the period required by applicable law.
Amazon Web Services (infrastructure), Buttondown (email), Resend (transactional email), Stripe (payments), Google Analytics (usage analytics, only with your consent). Our usage analytics run on Plausible Community Edition hosted on our own infrastructure, so that data is not shared with any analytics vendor.
We use essential cookies required for authentication. We also use Plausible Analytics, self-hosted on our own infrastructure, to measure site usage: it sets no cookies, stores nothing on your device, and collects no personal data or cross-site identifiers, so it needs no consent and runs for every visitor. Separately, only if you consent via the cookie banner, we use Google Analytics cookies; that stays disabled until you accept and you can decline at any time. No advertising cookies.
privacy@meshai.dev