← Meshia

Privacy Policy

Last updated: July 30, 2026

The short version

We collect the minimum data needed to run Meshia. We don't sell your data. We don't train AI models on your code, your conversations, or your experiment results. We don't read your sessions unless you ask us to debug one.

What we collect

Account data: your email address (for sign-in and billing receipts), the date you signed up, and which plan you're on.

Session data: the names of sessions you create, the GPU type and storage size you picked, when each session started and ended, and how much it cost. We need this for billing and for showing you your own dashboard.

Message data: the messages between you and the in-pod agent, stored in our database so the conversation persists between page reloads. This is yours. We don't read it and we don't use it to train anything. We may temporarily access a specific session when you explicitly ask us for help debugging it.

Payment data: handled by Stripe. We never see your full card number. We only get back a customer ID and the last four digits of your card.

Usage telemetry: page views, button clicks, and funnel events through PostHog only after you opt in to analytics. Account identifiers are hashed before they are sent. No raw email addresses in PostHog. You can opt out from the footer of any page.

Server logs: standard things like the IP that hit our API, the route, the response code, and the timestamp. Retained for 30 days for debugging and abuse prevention, then deleted.

Who we share data with

We use a small number of vendors to run the service. Each one only sees the data they need:

  • GPU compute providers: GPU compute. See your runtime configuration and the code you run inside the pod.
  • Anthropic: the Claude model that powers the in-pod agent. Sees the messages you send to the agent. Anthropic does not train on Meshia API traffic.
  • Supabase: our database. Sees account data, session metadata, and message history.
  • Vercel: hosts the web frontend. Sees request headers and the response body.
  • Stripe: payment processing. Sees your email and payment method.
  • Resend: sends auth code and notification emails. Sees your email address.
  • PostHog: product analytics (when enabled). Sees hashed identifiers and event names. No raw email addresses.

We do not sell, rent, or share your personal data for advertising.

Cookies

We use one essential cookie (your session token) so the site knows you're signed in, plus first-party browser storage for security, preferences, and workspace continuity. PostHog browser storage is created only after you opt in to analytics. We don't use advertising cookies. See the Cookie Notice for the current inventory and controls.

Your rights

Subject to applicable exceptions, you can exercise the right to:

  • Right to know and access the personal information we have about you
  • Right to correct inaccurate personal information
  • Right to delete personal information we collected from you
  • Right to portability where applicable
  • Right to opt out of sale or sharing of personal information
  • Right to limit certain uses of sensitive personal information
  • Opt out of analytics and marketing emails

For any of these, email privacy@meshia.io from the address on your account. We confirm California requests as required and respond within 45 calendar days, with an additional 45 days when legally permitted and after notice.

Meshia does not sell personal information or share it for cross-context behavioral advertising. We honor Global Privacy Control as a request to opt out of sale and sharing and do not discriminate against you for exercising privacy rights.

Children

Meshia is not for children under 13. If you're between 13 and 18, you need a parent or guardian's permission to use the service.

Changes to this policy

If we make material changes, we'll email you and update the date at the top of this page at least 30 days before the changes take effect.

Contact

Privacy questions, data requests, or a complaint go to privacy@meshia.io.