01 Who We Are & Scope of This Policy
This Privacy Policy describes how Mesh Labs Cloud, Inc., a Delaware corporation having its mailing address at 2810 North Church Street, Wilmington, Delaware 19802, United States ("Mesh", "we", "us" or "our"), processes personal data in connection with MESH and any related websites, applications (including the MESH desktop application, the MESH mobile application, and the MESH IDE extensions for Visual Studio Code, Cursor, Antigravity and compatible editors), SDKs, browser-based grid nodes, control plane and APIs (collectively, the "Service").
For purposes of the EU and UK General Data Protection Regulations ("GDPR"), the Israeli Privacy Protection Law, 5741-1981 and its regulations ("PPL"), the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") and similar laws, Mesh is the controller (or "business") of personal data we collect directly from you and technical telemetry generated by your use of the Service. Where the Service is embedded or administered by a third-party customer, Mesh may act as a processor (or "service provider") on that customer's behalf, as described in the applicable customer agreement or data processing addendum.
In this Policy, "personal data" includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual, as defined by applicable law.
You are generally not legally required to provide personal data to us, and providing it is voluntary. However, without information required for an account, device connection, payment, security or a requested feature, we may be unable to provide some or all of the Service.
This Policy supplements, and is incorporated into, our Terms & Conditions. Capitalized terms not defined here have the meanings given in those Terms.
02 Plain-Language Summary
- We collect account data (e.g., email), technical telemetry (e.g., IP, peer ID, GPU/backend capabilities, performance metrics), usage data (jobs you submit, models you use, contributions you make as a Provider) and, where you choose, payment data (handled by our payment processor).
- We use that data to operate the Service, match jobs to nodes, calculate Compute Units (CU), validate results, prevent fraud and abuse, comply with law, and improve the Service.
- The Service is decentralized: your inputs and intermediate results may be processed on third-party browser nodes that we do not control. You should treat any data you submit as visible to such nodes for the duration of the job.
- Personal AI conversations live on your devices by default. For multi-device access, if and when that feature is enabled, we may transmit them directly between your signed-in devices, relay them transiently through our servers without retaining them, or offer an opt-in service to store them on our servers so they follow your account across devices.
- If you enable Agentic Features, the desktop application may access resources you authorize and act through connected accounts, including changing or deleting files, executing commands, publishing or uploading content, sending messages or emails, and invoking third-party tools. Data is sent to a third party when the requested action requires interacting with that party.
- Global-network jobs may be processed by unrelated Provider nodes. Organization Cluster jobs are scheduled to participating devices in the applicable cluster, which may include devices operated by invited members or suppliers, while Mesh-controlled cloud infrastructure may still process metadata, inputs and outputs.
- We do not sell your personal data. We share data only with the sub-processors and partners listed below, with peer nodes assigned to your jobs, and where required by law.
- We are based in the United States. The Service connects users and Provider nodes globally, and your data may be processed in countries other than your own. Where required, we use contractual and other safeguards for international transfers.
- You have rights of access, rectification, erasure, restriction, portability and objection, subject to applicable law. See §13.
03 Categories of Personal Data We Process
| Category | Examples |
|---|---|
| Account & identity | Email address, display name, password hash, organization name (for business accounts), authentication tokens (JWT), API keys, role and permission metadata. |
| Device & browser capabilities | User-agent, browser type/version, operating system, screen size, supported web APIs, WebGPU/WebNN/WASM availability, GPU adapter name and feature flags, available memory, CPU class, device language and time zone; and, where you install the desktop application: your device name (hostname, shown in your dashboard to distinguish your devices), system resource state (total and available memory, CPU load, disk capacity), power source and battery state, thermal state, and screen-lock / user-idle state (used to schedule work when your device is unattended and to yield resources when you are active). |
| Network identifiers | IP address, approximate geolocation derived from IP, a pseudonymized network-locality identifier (a salted hash derived from your IP address; the raw address is not stored in this identifier), peer round-trip-time measurements between your node and peers it connects to, peer identifier (PeerJS / WebRTC ID), session identifier, signaling room membership. |
| Hardware attestation | Where supported and where you opt in, cryptographic device attestations issued by your platform authenticator (e.g., WebAuthn, TPM or Secure Enclave). We process the resulting public key and assertion. |
| Usage & job metadata | Job IDs, model identifiers, job type (text-to-image, image-to-video, etc.), parameters (steps, guidance, resolution), timing, timeouts, success/failure status, validation outcomes and quorum results. |
| Job content (Requesters) | Prompts, source images, source videos, source 3D inputs, source code, file contents and repository context submitted through the IDE extensions, intermediate tensors and generated outputs to the extent they pass through the control plane or persistent storage. Inputs submitted to the Global network may also be transmitted directly to unrelated Provider nodes. Organization Cluster workloads are scheduled to eligible devices participating in that cluster, which may include devices operated by invited members or suppliers. Mesh's hosted control plane and S3-compatible object storage may still process Organization Cluster metadata, inputs, intermediate artifacts and outputs. Where you use a genuinely local-only model in the IDE extensions, chat and autocomplete content is processed on your device and is not transmitted to us or to peer nodes. |
| Artifact access links | Upload and download URLs for job inputs, checkpoints and generated outputs. Some are time-limited presigned bearer URLs: they do not require a separate Mesh login after issuance, and anyone who obtains the complete URL may access the associated object until the URL expires. This can apply to Global-network, personal-cluster and Organization Cluster jobs. |
| Personal AI conversations | Conversations and messages you exchange with the on-device Personal AI in the desktop application. By default these are stored only locally on your device; we do not store them on our servers. If and when multi-device access is enabled, conversation content may be transmitted directly between your signed-in devices over encrypted channels or relayed transiently through our servers. Where a relay is expressly described as transient, content is processed in memory to deliver it and is not retained. If we offer and you opt in to a conversation-storage service, conversations may be stored on our servers until you delete them, subject to the notice and controls presented with that feature. |
| Agentic content, permissions & actions | If you enable Agentic Features: selected files and folders, file contents and metadata, directory listings, page and application content, command and tool inputs and outputs, MCP responses, installed skills and MCP servers, granted roots, capability settings, consent requests and decisions, schedules, Agent Actions and their results, and agent transcripts and audit history. Agent Actions may include reading, creating, editing, moving, overwriting or deleting files; operating software or a browser; submitting forms; publishing or uploading content; sending messages or emails; invoking APIs; and, where enabled, using paid services or making purchases. |
| Connected accounts & communications | Connected-service account identifiers, authorization scopes, OAuth or API access tokens, browser-session data and cookies, recipient and contact information, message and email content and attachments, public posts and uploads, transaction details and amounts, and responses received from connected services. Password fields and credentials entered during a human-takeover flow are not intended to be exposed to the AI model, although the relevant third-party service necessarily receives the credentials you enter into it. |
| Contribution metrics (Providers) | Compute time, accelerator and CPU operations executed, validated job completions, shard seeding contributions, uptime, latency to peers, idle/busy state. |
| Reputation & Compute Units (CU) | Reputation scores, CU balances, CU transactions, deterministic complexity metrics and oracle-based reward calibration outputs. |
| Communications & support | Emails, support tickets, in-product feedback, security reports. |
| Payment data (where applicable) | Billing name, address, VAT/tax identifier, transaction amounts. Payment-card data is processed directly by our payment processor and is not stored by Mesh. |
| Logs & security data | Request and response logs, error traces, heartbeat events, signaling messages, abuse-detection signals, IP reputation data, rate-limit telemetry. |
04 Where the Data Comes From
We obtain personal data from the following sources:
- Directly from you, when you create an account, configure a node, submit a job, contact us or make a payment;
- Automatically, when your browser, desktop or mobile app, IDE extension, SDK client or node connects to the control plane, executes shards, exchanges signaling messages or completes jobs;
- From peer nodes, in the form of trustless validation reports, divergence measurements and reputation feedback;
- From third parties, including identity providers if you sign in using SSO, payment processors, anti-fraud and anti-abuse vendors, public IP-reputation feeds and, when you enable Agentic Features, websites, APIs, MCP servers, skills and connected account providers with which the agent interacts.
- From your device and your instructions, when you grant access to files, folders, commands, applications or browser sessions, configure permissions or schedules, approve an Agent Action, or ask an agent to interact with local or connected resources.
05 Purposes & Legal Bases for Processing
| Purpose | Categories used | Legal basis (EU/UK GDPR) |
|---|---|---|
| Provide the Service: account management, scheduling, peer matching, shard distribution, signaling, job execution, result delivery. | Account, device, network, usage, job content and artifact access links. | Performance of a contract; consent (where required for sensitive client-side storage). |
| Operate the Compute Units (CU) and reputation systems, including oracle-based reward calibration and reputation scoring. | Contribution metrics, reputation, hardware attestation. | Performance of a contract; legitimate interests in operating a fair, sybil-resistant marketplace. |
| Multi-device access to Personal AI conversations: relaying conversation content between your signed-in devices and, if and when offered and enabled, storing conversations server-side so they are available across your devices. | Personal AI conversations, account, network identifiers. | Performance of a contract; consent (for opt-in server-side storage, withdrawable at any time). |
| Provide Agentic Features: interpret instructions, access user-approved resources, operate enabled tools and connected accounts, request and record permissions, perform Agent Actions, maintain action history, prevent abuse and support revocation. | Agentic content, permissions and actions; connected accounts and communications; account, device, network and security data. | Performance of a contract; consent where required for a particular permission, connected account, sensitive device access or storage; legitimate interests in security, abuse prevention and maintaining an auditable Service. |
| Network-aware scheduling: inferring which nodes are likely on the same local network (using the pseudonymized network-locality identifier and peer latency measurements) in order to place related work units on nodes with fast connections to each other. | Network identifiers, contribution metrics. | Performance of a contract; legitimate interests in efficient job placement. |
| Trustless validation and abuse prevention: redundant execution, canonical hashing, divergence statistics, sanction-screening, rate-limiting, fraud detection. | Job metadata, reputation, network identifiers, security data. | Legitimate interests; legal obligation (sanctions and AML). |
| Billing, invoicing, taxation, accounting, audit and bookkeeping. | Account, payment data, contribution metrics, CU transactions. | Performance of a contract; legal obligation; legitimate interests. |
| Service security, integrity and continuity: incident response, vulnerability management, intrusion detection, backups, disaster recovery. | All categories, on a need-to-know basis. | Legitimate interests; legal obligation. |
| Customer support and user communications. | Account, communications, job metadata. | Performance of a contract; legitimate interests. |
| Service improvement, analytics, capacity planning and benchmarking on the Oracle Node, primarily using de-identified or aggregated data. | Device, usage, job metadata, contribution metrics. | Legitimate interests; consent for non-essential analytics where required. |
| Compliance with legal obligations and protection against legal claims. | As required. | Legal obligation; legitimate interests; establishment, exercise or defense of legal claims. |
| Marketing communications, where you opt in. | Account, communications. | Consent (you can withdraw at any time). |
06 Peer-to-Peer Data Flows (Important)
Mesh does not control Provider devices. The Service is designed with the architectural assumption that nodes are untrusted, and we apply trustless validation, quorum acceptance and reputation-aware scheduling to mitigate that risk. Despite these measures, network execution is not appropriate for regulated or confidential content unless an applicable agreement and Service configuration expressly permit it. See the Acceptable Use and Requester-Specific Terms in our Terms & Conditions. Available controls may include:
- anonymizing or pseudonymizing inputs before submission; and
- using a local-only or other approved execution mode rather than the peer network when working with sensitive content.
Presigned artifact URLs are bearer capabilities rather than session-bound links. Possession of the complete URL may permit access without a further Mesh authentication check until the signature expires. Do not publish or forward such URLs, and treat them as confidential while valid.
08 Agentic Features Data Flows
Agent processing may occur locally on your device, but enabling a website, connected account, API, cloud model, MCP server, skill or other network tool may transmit selected prompts, files, page content, command output, tool inputs, communications or other data to that third party. Information intentionally published, uploaded or sent by an Agent Action becomes available to the selected public audience, platform, account or recipient and may be copied or retained by them. Mesh cannot delete or retrieve copies held by those recipients.
The application may store agent transcripts, action and approval history, granted folders, capability settings, installed MCP servers and skills, schedules and a dedicated browser profile locally under your signed-in account profile. AI model files may be shared across accounts on the same device. Application-level separation does not prevent a person with operating-system or administrator access from accessing unencrypted local files or browser-profile data.
A dedicated in-app browser may retain cookies and authenticated sessions so connected sites remain signed in. Sensitive credentials entered during a human-takeover flow are intended to remain between you, the browser and the relevant site rather than being provided to the AI model. Access tokens and browser sessions are nevertheless sensitive data. You should grant the narrowest available permissions, review requested actions, disconnect integrations you no longer use and use available controls to stop Agent Actions and revoke grants.
Permission and action records are processed to enforce your choices, display an action history, investigate failures and abuse, and provide security and support. If an action is approved from a paired device, we may also process the approving device, time and decision as part of that record.
10 International Data Transfers
Mesh is a Delaware corporation with its principal mailing address in the United States. Our infrastructure, service providers and peer nodes may be located throughout the world, including in destinations that may not provide the same level of data protection as your home jurisdiction. Peer-to-peer execution may transfer job content directly to the countries in which assigned Provider nodes are located.
Where the EU/UK GDPR or Swiss data-protection law requires a transfer mechanism, we rely as applicable on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, the Swiss adaptations to the Standard Contractual Clauses, adequacy decisions, or another lawful mechanism. We apply supplementary measures where appropriate, such as encryption in transit and at rest, access controls, minimization and transfer-risk assessments. You may request information about applicable safeguards by contacting privacy@meshlabs.cloud.
11 Data Retention
We keep personal data only as long as necessary for the purposes described in this Policy and to satisfy our legal, accounting and reporting obligations. Indicative retention windows (which may be adjusted to reflect operational and legal requirements):
- Account data: for the life of the account and up to 24 months after closure.
- Uploaded job inputs and transient artifacts: generally retained only for the operational life of the job and typically removed from object storage within approximately 24 hours, subject to retries, legal holds and exceptional incident or support requirements.
- Final generated outputs: output records and, where configured, downloadable artifacts may be retained for up to 12 months to provide job history and result delivery, unless you delete them earlier or a shorter storage lifecycle applies. Artifact files may become unavailable before the associated job record, so you should download outputs you wish to retain.
- Presigned artifact URLs: input download links are generally issued for up to 24 hours and output links are generally issued for shorter periods and may be refreshed while the underlying artifact remains available.
- Job and contribution metadata, CU ledger entries: up to 7 years for accounting, audit and tax compliance.
- Personal AI conversations: stored on your own devices under your control by default. If and when a transient multi-device relay is enabled, relayed copies are processed in memory and not retained as conversation storage. If you opt in to a server-side conversation-storage feature, the retention period and deletion controls presented with that feature will apply.
- Agentic Features data stored locally: agent transcripts, action and approval history, granted roots, capability settings, schedules, installed MCP servers and skills, and the per-account browser profile are retained on the device until you remove the applicable data, integration, account profile or application, subject to available product controls and operating- system behavior.
- Agentic data held by third parties: information sent to websites, connected accounts, MCP servers, skills, message recipients or public audiences is retained under those parties' policies and cannot necessarily be deleted through Mesh.
- Security and abuse logs: typically 90–365 days.
- Backups: rolled off on a defined backup-retention schedule (typically up to 35 days).
Where you exercise your right to erasure (§13), we will delete or de-identify personal data unless we are legally required or permitted to retain it.
12 Security Measures
We implement technical and organizational measures appropriate to the risks presented by our processing, including:
- encryption of data in transit (TLS) and at rest where applicable;
- role-based access control with the principle of least privilege, enforced at the API, service and database layers and segmented by organization (RBAC);
- cryptographic integrity verification of model assets (e.g., SHA-256 content addressing);
- trustless validation, redundancy and quorum acceptance for compute results;
- hardware-backed device attestation to mitigate Sybil attacks (where supported);
- logging, monitoring, intrusion detection and anomaly detection;
- for Agentic Features, permission scopes and revocation controls, folder boundaries, action and approval history, per-account browser profiles, and human-takeover flows for sensitive interactions, where applicable;
- secure-development practices, code review and dependency-vulnerability management;
- a documented incident-response process, including notifications to regulators and affected users where required.
No security measure is perfect. If you suspect a vulnerability or breach, please contact security@meshlabs.cloud promptly.
13 Your Privacy Rights
Subject to applicable law (including the EU/UK GDPR, Swiss and U.S. state privacy laws, and the CCPA/CPRA), you may have the following rights:
- Access. Confirmation of whether we process personal data about you and a copy of that data. See Article 15 GDPR.
- Rectification. Correction of inaccurate or incomplete data. See Article 16 GDPR.
- Erasure ("right to be forgotten"). Deletion of personal data, subject to exceptions (e.g., legal obligations, defense of claims). See Article 17 GDPR.
- Restriction. Restriction of processing in defined circumstances. See Article 18 GDPR.
- Portability. Receipt of personal data in a structured, commonly used, machine-readable format and transmission to another controller, where technically feasible. See Article 20 GDPR.
- Objection. Objection to processing based on legitimate interests, including profiling. See Article 21 GDPR.
- Withdrawal of consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Non-discrimination. We will not discriminate against you for exercising any of these rights.
- Lodging a complaint. You may lodge a complaint with your local data-protection authority.
To exercise your rights, email privacy@meshlabs.cloud from the address associated with your account, or use the in-product privacy controls. We may need to verify your identity before responding. We will respond within the time periods required by applicable law (typically 30 days under GDPR, extendable by 60 days for complex requests; 45 days under CCPA, extendable once).
14 Children
The Service is not directed to, and we do not knowingly collect personal data from, individuals under the age of 18 (or the age of legal majority in their jurisdiction, whichever is greater). If you believe a child has provided us with personal data, please contact privacy@meshlabs.cloud and we will take appropriate steps to delete it.
15 Automated Decision-Making & Profiling
The Service performs a number of automated processing operations that may affect you, including: scheduling jobs to peer nodes (using device capability, network locality, latency and reputation inputs), accepting or rejecting compute results based on quorum and divergence statistics, computing reputation and CU, and detecting fraud, abuse and Sybil behavior. If you enable Agentic Features, AI models also interpret your instructions, select tools and propose or perform actions within the permissions you configure. Those actions may affect files, accounts, communications, publications, purchases and third parties.
We endeavor not to engage in automated decisions that produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR. Where such decisions occur (for example, an account suspension based primarily on automated abuse signals), you have the right to obtain human review, express your point of view and contest the decision by contacting privacy@meshlabs.cloud.
This statement about decisions Mesh makes concerning you does not mean that an Agent Action you instruct or permit cannot have legal or similarly significant consequences. You should use human review and confirmation for consequential actions involving contracts, purchases, employment, finance, healthcare, government services or other people's rights.
16 Use of Data for AI Training & Improvement
We do not use the content of Requester prompts, source media, source code, Personal AI conversations (whether stored locally, relayed, or stored server-side at your request), agent transcripts, selected file or page content, command or MCP output, communications, Agent Actions or generated outputs to train Mesh's own foundation models without a separate, opt-in agreement with you. We may use de-identified or aggregated job metadata (for example, model identifiers, latency distributions, hardware-class distributions, average shard memory consumption) to evaluate, benchmark and improve the Service, including to recalibrate the deterministic complexity profile used by the Oracle Node, optimize job scheduling and node matching, plan network capacity and refine validation mechanisms. We do not describe data as anonymous unless it has been processed so that it no longer relates to an identified or identifiable person under applicable law.
17 Region-Specific Disclosures
17.1 European Economic Area, United Kingdom and Switzerland
The legal bases on which we rely are listed in §05. You may contact our team at privacy@meshlabs.cloud for any data-protection enquiry. Where Article 27 of the EU or UK GDPR requires us to appoint a local representative, the representative's identity and contact details will be published in this Policy.
17.2 Israel
Our processing is governed by the Israeli Privacy Protection Law, 5741-1981 and its regulations, including the Privacy Protection (Data Security) Regulations, 5777-2017. Subject to applicable law, you may have rights to access information about you in a database and to request correction or deletion of information that is inaccurate, incomplete, unclear or outdated, including under Sections 13 and 14 of the Privacy Protection Law. Contact privacy@meshlabs.cloud to exercise those rights.
17.3 United States, including California
Residents of U.S. states with applicable comprehensive privacy laws may have rights to access, correct, delete or obtain a copy of personal data; opt out of certain sales, targeted advertising or profiling; and appeal a denied request. To the extent the CCPA/CPRA applies, California residents may also request to know the categories and specific pieces of personal information we collect and limit certain uses of sensitive personal information. We do not sell personal information or share it for cross-context behavioral advertising. During the preceding 12 months, we may have disclosed the categories described in §03 for the business purposes and to the recipient categories described in §§05–09; we have not sold personal information or shared it for cross-context behavioral advertising. To exercise rights or submit an appeal, contact privacy@meshlabs.cloud. You may designate an authorized agent, subject to legally permitted verification, and we will not discriminate against you for exercising applicable rights.
17.4 Other Jurisdictions
We will honor applicable rights granted under other privacy laws (e.g., Brazilian LGPD, Canadian PIPEDA, Singapore PDPA). Where local law requires specific disclosures or additional rights, those will apply in addition to the rights listed in §13.
18 Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will provide reasonable notice (e.g., by email or in-product banner) and update the "Last Updated" date above. Your continued use of the Service after the effective date of the updated Policy constitutes acceptance of the changes.
19 Contact & Complaints
For questions, requests or complaints regarding this Policy or our data practices:
Mesh Labs Cloud, Inc.
Attn: Privacy
2810 North Church Street
Wilmington, Delaware 19802, United States
Privacy: privacy@meshlabs.cloud
Security: security@meshlabs.cloud
Legal: legal@meshlabs.cloud
If you have an unresolved concern, you may also contact your local data-protection authority or other competent regulator.