Who we are and what this covers
This policy covers the MeshTransit website at meshtransit.net and the MeshTransit service: the Console, the control plane your devices connect to, and the client software. For account and website data we decide how data is used. For the configuration and records you create inside your Workspace, we process data on behalf of the organisation that owns the Workspace, under its instructions.
What we collect
- Account data. When you sign in through your identity provider (for example Google), we receive a stable identifier, your name and your email address. We do not receive or store your password.
- Invitation data. When an admin invites you, we store the invited email address, the role and the invitation status. The invitation link is stored only as a one-way digest.
- Workspace data. Networks, members, roles, groups, tags, rules, shares and guardrails that admins create.
- Device data. For each enrolled device: its name, public keys, assigned private addresses, operating system and client version, and the network endpoints it reports so devices can connect directly.
- Audit records. Who changed what, when, from which session and why, sealed into a tamper-evident audit stream.
- Technical logs. IP addresses, request times and error codes, used to run the service, limit abuse and investigate problems.
- Messages you send us. If you request access or contact us, the details you choose to include.
How we use it
- To sign you in, apply the roles and rules your Workspace defines, and connect your devices.
- To send service email such as invitations and security notices.
- To keep the audit evidence your organisation relies on.
- To secure the service, prevent abuse and fix problems.
- To send product news, only if you agree. You can withdraw that consent at any time, and it never affects your access.
We do not sell personal data, and we do not use your data for advertising.
Your network traffic
Traffic between your devices is encrypted end to end with WireGuard®. The control plane distributes keys, addresses and rules; it does not see the contents of your traffic. When a direct path is not possible, a relay forwards packets it cannot decrypt.
Optional flow summaries, when they become available, will be off by default, limited to packet headers such as addresses, ports and protocol, and enabled only by your Workspace admins.
How long we keep it
We keep account and Workspace data while the account or Workspace exists. Audit records are kept so they remain verifiable for your organisation's reviews. Technical logs are kept for a short period for security and troubleshooting. When a Workspace is closed, we delete or anonymise its data after any period the law or our agreement with the organisation requires.
How we protect it
Data is encrypted in transit. Each Workspace is isolated in the database itself, not only in the interface. Tokens and keys are stored as digests wherever possible, and access by our staff is limited and recorded.
Your choices and rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict some uses. If you use MeshTransit through your organisation, contact its admins first; we will help them answer your request. You can also write to us at privacy@meshtransit.net.
Changes and contact
We will update this page when our practices change and show the date at the top. For significant changes we will also notify Workspace owners. Questions: privacy@meshtransit.net.