Privacy Policy
Effective 6 August 2026
Effective date: 3 September 2026
Meshanics ("Meshanics", "we", "us") builds zero-trust over-the-air update and fleet-management infrastructure for industrial and edge-AI devices. This Privacy Policy explains what personal data we collect, why, how we handle it, and the rights you have. It covers our public websites (meshanics.com and docs.meshanics.com), our operator console (panel.meshanics.com), and our APIs.
The update service processes artifact bytes and related supply-chain documents when needed to store, verify, scan, and deliver an update. The normal update path does not collect raw application data or raw inference inputs and outputs from your devices. Optional diagnostics and aggregate model-quality statistics are described below.
Who we are
Meshanics operates this platform and is the data controller for the personal data described in this policy, except where we act as a processor on behalf of a customer (see "Customer data and our role"). For any privacy question, or to exercise your rights, contact us at hello@meshanics.com.
Information we collect
Account and contact data. When you create an account or contact us, we collect your name, work email, company name, and the password you set (stored only as an argon2id hash, never in plain text).
Billing data. For paid plans we collect billing-profile details such as company legal name, billing address, and tax identifiers. We invoice manually; we do not store full payment-card numbers.
Device and fleet metadata. To run the service we process operational metadata about your devices: device identifiers, hardware profile (SoC, architecture, accelerators), agent version, update and rollback status, health-probe results, and the append-only audit events that record fleet activity. If enabled, we also process aggregate model-quality windows such as counts, histograms, latency, errors, dropped samples, and thermal state. These windows do not contain raw inference inputs or outputs. Device logs are collected only when an authorized user requests them.
Artifact and supply-chain data. When you publish an update, we process and store the artifact bytes or signed descriptor needed for delivery, together with manifests, hashes, SBOMs, provenance, vulnerability findings, and related release metadata. Container inspection may temporarily read a digest-pinned image to generate an SBOM; the image pulled for that inspection is removed after processing. Self-hosted and air-gapped deployments keep this material in the infrastructure you operate.
Usage and technical data. When you use the console or APIs we record technical logs such as IP address, browser and device type, timestamps, and the actions taken, for security, debugging, and abuse prevention.
Marketing-analytics data (public sites only). On meshanics.com and docs.meshanics.com we use privacy-conscious web analytics to understand how the sites are used. Analytics run only with your consent and never on the operator console. See "Cookies and analytics" below.
Information you send us. Support tickets, emails, and any content you choose to share with us.
How we use your data
We use personal data to:
- provide, operate, secure, and maintain the platform;
- authenticate you and protect accounts and fleets from abuse;
- process invoices and manage paid plans;
- respond to support requests and communicate about the service;
- meet legal, regulatory, and compliance obligations;
- improve the product and, with your consent, measure marketing.
Legal bases (GDPR)
Where the EU/UK General Data Protection Regulation applies, we rely on: the performance of our contract with you (providing the service); our legitimate interests (securing the platform, preventing abuse, and improving the product), balanced against your rights; your consent (marketing analytics and non-essential cookies); and compliance with legal obligations.
Cookies and analytics
The operator console uses a single strictly necessary cookie: an httpOnly session cookie that keeps you signed in. We do not use it for tracking, and the console loads no third-party scripts.
Our public marketing sites use Google Analytics 4 and PostHog Cloud EU. We send only page and explicitly defined interaction events. PostHog session recording, automatic element capture, surveys, feature flags, and user identification are disabled. PostHog IP data capture is configured to discard, so client IP addresses are not retained with PostHog analytics events. Analytics and any non-essential cookies stay disabled until you opt in through the cookie banner, and you can change your choice at any time using the "Manage cookies" link in the site footer. If you decline or withdraw consent, analytics collection stops and readable analytics cookies are removed.
Customer data and our role
For your account and billing details, Meshanics is the data controller. For device, fleet, artifact, diagnostic, and supply-chain data we process on your behalf to deliver the service, Meshanics acts as a data processor and you are the controller. You are responsible for ensuring that uploaded artifacts, logs, and documents contain only data you are authorized to provide. This processing is governed by our Data Processing Agreement, available to customers on request at hello@meshanics.com.
Sharing and subprocessors
We do not sell personal data. We share data only with service providers who process it on our behalf under contract, and only as needed to run the platform:
- Cloud hosting - infrastructure that runs the managed service and stores account, fleet, artifact, and supply-chain data. (Self-hosted and air-gapped deployments keep this data within your own environment.)
- Google Analytics - marketing-site analytics, consent-gated, public sites only.
- PostHog Cloud EU - marketing-site analytics, consent-gated, public sites only, with IP data capture set to discard. Operator-console, account, fleet, artifact, and device data are not sent to PostHog.
- Resend - delivery of transactional and notification emails.
We may also disclose data where required by law, to enforce our terms, or to protect the rights, safety, and security of our users and the public. A current list of subprocessors is available to customers on request.
International transfers
Where personal data is transferred outside your region, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Customers who require data residency can run Meshanics on-premises or air-gapped, in which case data stays within their own infrastructure.
Data retention
We keep personal data for as long as your account is active and as needed to provide the service, then for the period required to meet legal, tax, and compliance obligations or to resolve disputes. Artifact retention follows the customer's lifecycle and service configuration. Audit and update-history records are retained to support product-security and regulatory evidence needs. When data is no longer needed, we delete or anonymize it, subject to the agreed retention settings and legal obligations.
Security
We are part of our customers' supply chain and treat it accordingly. Measures include mutual TLS between services and devices, per-device cryptographic identities, signed and verified update metadata, encryption of secrets at rest, argon2id password hashing, scoped API keys, and a database hash-chained audit log. No system is perfectly secure, but security is the core of what we build. For details see meshanics.com/security.
Your rights
Subject to applicable law, you may request to access, correct, delete, restrict, or port your personal data, and object to certain processing. Where we rely on consent, you may withdraw it at any time without affecting prior processing. To exercise any right, email hello@meshanics.com; we will respond within the time the law requires. You also have the right to lodge a complaint with your local data-protection supervisory authority.
Children
The platform is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We may update this policy as the service evolves or the law changes. We will post the revised version here and update the effective date above; material changes will be communicated through the service or by email.
Contact
Questions, requests, or concerns about this policy or your data: email hello@meshanics.com.