Skip to content
MeshTransit
  • Product
  • Use cases
  • Roadmap
  • FAQ
Log inGet started
  • Product
  • Use cases
  • Roadmap
  • FAQ
Log inGet started

Legal

Privacy Policy

Last updated 8 October 2026

MeshTransit is built to show exactly who can reach what. We hold ourselves to the same standard: this page says plainly what we collect, why, and what you can do about it.

On this page

  1. Who we are and what this covers
  2. What we collect
  3. How we use it
  4. Your network traffic
  5. Who we share it with
  6. How long we keep it
  7. How we protect it
  8. Your choices and rights
  9. Cookies
  10. Changes and contact

Who we are and what this covers

This policy covers the MeshTransit website at meshtransit.net and the MeshTransit service: the Console, the control plane your devices connect to, and the client software. For account and website data we decide how data is used. For the configuration and records you create inside your Workspace, we process data on behalf of the organisation that owns the Workspace, under its instructions.

What we collect

  • Account data. When you sign in through your identity provider (for example Google), we receive a stable identifier, your name and your email address. We do not receive or store your password.
  • Invitation data. When an admin invites you, we store the invited email address, the role and the invitation status. The invitation link is stored only as a one-way digest.
  • Workspace data. Networks, members, roles, groups, tags, rules, shares and guardrails that admins create.
  • Device data. For each enrolled device: its name, public keys, assigned private addresses, operating system and client version, and the network endpoints it reports so devices can connect directly.
  • Audit records. Who changed what, when, from which session and why, sealed into a tamper-evident audit stream.
  • Technical logs. IP addresses, request times and error codes, used to run the service, limit abuse and investigate problems.
  • Messages you send us. If you request access or contact us, the details you choose to include.

How we use it

  • To sign you in, apply the roles and rules your Workspace defines, and connect your devices.
  • To send service email such as invitations and security notices.
  • To keep the audit evidence your organisation relies on.
  • To secure the service, prevent abuse and fix problems.
  • To send product news, only if you agree. You can withdraw that consent at any time, and it never affects your access.

We do not sell personal data, and we do not use your data for advertising.

Your network traffic

Traffic between your devices is encrypted end to end with WireGuard®. The control plane distributes keys, addresses and rules; it does not see the contents of your traffic. When a direct path is not possible, a relay forwards packets it cannot decrypt.

Optional flow summaries, when they become available, will be off by default, limited to packet headers such as addresses, ports and protocol, and enabled only by your Workspace admins.

Who we share it with

  • Service providers that host and operate MeshTransit for us, including cloud infrastructure providers and Amazon Web Services for email delivery, bound by contracts to use data only to provide their service.
  • Your identity provider, which you choose, to sign you in.
  • The other side of a share. When your Workspace shares a resource with another organisation, that organisation sees the shared resource and the terms. It does not see your reasons, sessions or other Workspace details.
  • Authorities, only when the law requires it, and we will tell the affected organisation unless we are legally prevented.

How long we keep it

We keep account and Workspace data while the account or Workspace exists. Audit records are kept so they remain verifiable for your organisation's reviews. Technical logs are kept for a short period for security and troubleshooting. When a Workspace is closed, we delete or anonymise its data after any period the law or our agreement with the organisation requires.

How we protect it

Data is encrypted in transit. Each Workspace is isolated in the database itself, not only in the interface. Tokens and keys are stored as digests wherever possible, and access by our staff is limited and recorded.

Your choices and rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict some uses. If you use MeshTransit through your organisation, contact its admins first; we will help them answer your request. You can also write to us at privacy@meshtransit.net.

Cookies

This website uses no tracking or advertising cookies. The Console uses strictly necessary cookies to keep you signed in securely and to complete invitations.

Changes and contact

We will update this page when our practices change and show the date at the top. For significant changes we will also notify Workspace owners. Questions: privacy@meshtransit.net.

MeshTransit

Access without broad trust.

Product

  • Policy Explain
  • Use cases
  • Roadmap

Account

  • Log in
  • Get started
  • Contact

© 2026 MeshTransit. All rights reserved.

Privacy Policy