Privacy Policy

What MeshSail collects and why, where your code goes when an audit runs, and how to get it deleted. In short: we keep the minimum needed to run the Service, your model key is stored encrypted, your code is read from GitHub and sent to the model provider you chose to run the audit, and we do not sell your data or train models on it.

Last updated 5 September 2026

This Privacy Policy explains how MeshSail(“we”, “us”) handles personal information and your code. It applies to the MeshSail website and service. By using the Service you agree to this policy and to the Terms of Service.

1. What we collect

Account information. Your email address, display name, username, and date of birth (used only to enforce the 18+ age requirement). If you sign in with GitHub, we also receive your GitHub username and user id.

Repository access.When you connect a repository, we store the GitHub App installation identifier and the repository name and branch you chose. During an audit we read the repository's files and metadata. We do not keep a full copy of your repository. We store the audit's output, which can include short excerpts of code and file paths inside individual findings and in the audit chat.

Your model API key. The key you supply is encrypted before it is stored and is decrypted only in memory while an audit runs. We keep only a short hint (the last few characters) to show you which key is set.

Project context you enter. The description and notes you add to a project, including any test-account details you choose to provide, so the audit can use them. Treat these as you would any credential you paste into a tool, and use only disposable test accounts.

Usage and technical data. Basic logs needed to operate and secure the Service, such as request and error logs and the timing of audit runs.

2. How we use it

  • to run the audits and features you request;
  • to open pull requests you approve;
  • to operate, secure, debug, and improve the Service;
  • to enforce our Terms and prevent abuse; and
  • to contact you about your account or important changes to the Service.

We do not sell your personal information, and we do not use your code to train machine-learning models.

3. Where your code goes when an audit runs

Running an audit necessarily moves your code through a few services. Specifically, we read the relevant files from GitHub, and we send the portions needed for the audit to the model provider whose API key you supplied (for example, the provider you selected when you set your key). That provider processes the request under your account and its own terms. We do this only to produce the audit you asked for.

4. Who we share data with

We share data only with the service providers that make MeshSail work, and only as needed to run it:

  • GitHub, to read the repository you connect and open pull requests you approve.
  • Your model provider, to run the audit using the key you supplied.
  • Our infrastructure providers for hosting, database, and background jobs, which store the data described above on our behalf.

We may also disclose information if required by law, or to protect the rights, safety, and security of MeshSail, our users, or the public.

5. How we protect it

Model keys are encrypted at rest with strong encryption and are only decrypted in memory for the duration of a run. Access to your projects and audits is restricted to your account through database-level access rules. No system is perfectly secure, but we take reasonable measures to protect your information.

6. How long we keep it

We keep account information for as long as your account is open. We keep audit data (projects, runs, findings, and chat) until you delete it or close your account. Routine backups may persist for a limited period after deletion before they are overwritten.

7. Deleting your data

You can delete your account at any time from Settings, under Data and deletion. Deleting your account removes your projects, audits, findings, stored keys, and profile. You can also remove MeshSail's access to your repositories at any time from your GitHub settings, which stops any further reading of that repository.

8. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise most of these directly in the app, or contact us at privacy@meshsail.com and we will respond as required by applicable law. We do not discriminate against you for exercising these rights.

9. Children

The Service is for people 18 and older. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.

10. Cookies

We use a small number of strictly necessary cookies to keep you signed in and to keep the Service secure. See the Cookie Policy for details.

11. Changes to this policy

We may update this policy. When we make a material change, we will update the date below and ask you to accept the updated terms before you continue using the Service.

12. Contact

For privacy questions, contact privacy@meshsail.com.