Privacy policy
Last updated: 30 September 2026.
MeshArc is operated by [Legal entity name], [registered address, country] ("MeshArc", "we"). This policy says what we collect when you use the web app at https://mesharc.dev, the API at https://api.mesharc.dev, the mesharc SDKs and the MCP server, why we collect it, how long we keep it, and what you can ask of us. Questions go to [email protected].
There are two kinds of data here, and they are treated differently. Your account and workspace — who you are, what you configure, what you are billed — is data we hold about you. The pages you crawl are yours: you decide which sites to read, and we read them on your behalf. The first is covered in full below; the second has its own section, Pages you crawl.
What we collect#
Account. A work email address, a display name and a password. The password is stored only as a salted PBKDF2-SHA256 hash; we cannot read it. Your profile also holds a time zone and two preferences: whether you receive run emails and the weekly digest.
Workspace. Its name, its members and their roles, invitations (an email address and a role, valid for seven days), API keys (stored hashed, shown to you once), webhook secrets, and the connections you configure to your own databases, buckets and vector stores — including the credentials those need, which are encrypted at rest and never returned by the API.
Sessions. When you sign in we record the time, the IP address and the user agent of the browser, so Profile → Sessions can show you where you are signed in and let you end any of them. A session lasts 30 days and ends after 14 idle days.
Billing. Your plan, credit balance and usage. Card, UPI and bank details never reach us: payments are taken by Razorpay, and we keep only the Razorpay customer and subscription ids, the subscription state, and the invoices we issue.
Usage and logs. Every API request is logged with its time, path, status, the workspace and key it was made with, the credits it cost, and a request id. Logs are kept for [log retention, e.g. 30 days] for operations and abuse prevention.
Support mail. What you write to us at [email protected], kept as long as the conversation is useful.
Newsletter. If you sign up for the newsletter on the site: your email address, where on the site you signed up, the sentence you agreed to and when, and whether and when you confirmed or left. You need no account for it. Nothing is sent until you click the link in the confirmation email we send, and every newsletter carries a link to leave, which works at once.
Where you came from. The first time you visit the site, a cookie can note where that visit came from: the campaign tags in the link (utm_source and the like), the address of the site that sent you — its domain only — and the page you landed on, without anything after the ?. If you then create an account, that note is kept with it, so we can tell which pages and campaigns bring people who stay. Where the law asks for your consent first (see below), the note is only made after you say yes; it is never made when your browser sends Global Privacy Control.
Site analytics. The site loads Google Tag Manager, which runs Google Analytics: pages viewed, how you arrived, the browser and device type, an approximate location derived from your IP address, and a few events we send ourselves — a sign-up, a free-tool run, a purchase — without your name, email or anything you typed. Where consent is needed Analytics waits for a yes; you can change your answer under Cookie settings at the foot of every page.
Errors. When something breaks, an error report goes to Sentry with the stack trace, the release, the browser or server involved and the URL without its query string. We do not send session replays, form contents or your identity with an error.
Cookies and consent#
If you are in the European Economic Area, the United Kingdom or Switzerland — or we cannot tell where you are — a banner asks before any analytics or first-visit cookie is set, and saying no leaves only the cookies the site needs. Elsewhere they are on, and Cookie settings at the foot of every page turns them off. A browser that sends Global Privacy Control is treated as a no. We tell where you are from the country our network provider, Cloudflare, attaches to each request; we do not look up anything more precise.
| Cookie | What it is for | Kept |
|---|---|---|
mesharc_session | Keeps you signed in. Needed for the app to work | 30 days, or until you sign out |
mesharc_region | The country code of your visit, so the banner knows whether to ask. Needed | 30 days |
mesharc_consent | Your answer to the banner. Needed | 12 months |
mesharc_ft | Where your first visit came from, as described above. Only with consent where consent is needed | 90 days, or until you sign up |
_ga, _ga_* | Google Analytics: tells one visit from the next. Only with consent where consent is needed | Up to 2 years |
The app remembers your theme choice in your browser's local storage, which never leaves your browser. There is no advertising pixel, no session recording and no product analytics inside the app. We do not buy data about you from anyone, and we do not sell or share yours.
How we use it#
- To run the service: sign you in, keep your workspace, schedule and run your crawls, deliver pages to your destinations, meter credits and bill you.
- To tell you about your own account: verification codes, password resets, invitations, run emails and the weekly digest if you have them on, and notices about the service or this policy. We do not send marketing mail.
- To understand what works: which pages, articles and campaigns bring people to MeshArc, and which of them go on to use it — as aggregate numbers, not to profile you.
- To keep the service safe: rate limits, abuse detection and the investigation of incidents.
- To meet legal obligations, such as tax and accounting records.
We make no decision about you by automated means alone, and we do not profile you.
Under the GDPR and UK GDPR the legal bases are performance of our contract with you (running the service, billing), our legitimate interest in keeping it secure and working (logs, error reports, abuse prevention), and legal obligation (financial records). Where consent is the basis — run emails and the digest, the newsletter, and, in the EEA, the UK and Switzerland, analytics and the first-visit note — you can withdraw it at any time: in Profile for email, by the link in any newsletter for the newsletter, under Cookie settings for cookies. Elsewhere, analytics and the first-visit note rest on our legitimate interest in knowing which of our pages are useful, and you can object the same way.
Pages you crawl#
When you scrape, crawl or map a site, MeshArc fetches pages from that site and stores what came back — bodies, headers, extracted fields, screenshots if you asked for them, and a record of what changed since the last run — in your project. Whatever those pages contain, including any personal data on them, is collected on your instructions and for your purposes.
- You decide. You choose the sites, the scope, the schedule, the formats and where the results go. For that data you are the controller and we are the processor, acting only on your instructions. A data processing addendum is included on the Growth plan and above, and available on request to any workspace that needs one.
- Retention is yours to set. Each project keeps its pages for the retention you choose — 30 days, 90 days, a year, or until you delete them. Pages past retention are deleted. On the free plan retention is seven days. Deleting a project deletes its runs and pages.
- Who can see it. The members of your workspace, according to their roles, and the API keys you issue. Our staff do not read your pages except to investigate an incident you report, an abuse report, or a legal demand, and then as little as the task needs.
- Where it goes. Destinations you configure — your warehouse, your database, your bucket, your vector index — receive rows because you told us to write there. What happens to the data after it lands is governed by your agreement with that provider.
- What we do with it. Nothing but store it, diff it, and deliver it to you. We do not train models on your pages, do not read them for our own purposes, and do not combine them across workspaces.
If we crawled your site#
MeshArc reads public web pages on behalf of its customers. If our crawler has visited your site:
- It obeys
robots.txtand rate limits by default. A customer can override them, and it is the customer's responsibility to have the right to do so. - Requests identify themselves by user agent unless the customer chose otherwise, and come from addresses we operate or from residential exits we lease.
- To ask that your site not be crawled, or that pages already fetched be removed, write to [email protected] with the domain. We will identify the workspace, pass the request to it, and remove pages where the law requires it.
Who else sees it#
We use a small number of providers to run the service. Each processes only what its job needs, under a contract that holds it to this policy.
| Provider | What for | What it sees |
|---|---|---|
| [Hosting provider] | Runs the app, the API and the database | Everything above, encrypted at rest |
| Razorpay | Payments and subscriptions | Your email, name, plan, and the card, UPI or bank details you give Razorpay directly |
| Cloudflare | Delivers the site and the API, and protects them from attack | Your IP address, the country it resolves to, and the requests you make |
| Google (Tag Manager, Analytics) | Site analytics, where allowed | The pages you view, the events above, your browser and an approximate location |
| Sentry | Error reports | Stack traces, release, browser, URL without query string |
| [Email provider] | Verification codes, resets, invitations, run emails, digests, the newsletter's confirmation email | Your email address and the message |
| Proxy and unblocking providers | Reaching pages that refuse a plain request | The URLs the crawl fetches through them, never your account |
We disclose data beyond this only when the law requires it, to protect the service or someone's safety, or as part of a sale or merger, in which case this policy continues to apply and you will be told.
Where it is kept#
Data is stored in [region]. If you are in the EEA, the UK or Switzerland and data is transferred elsewhere, the transfer is covered by standard contractual clauses or an adequacy decision.
How long we keep it#
| Data | Kept |
|---|---|
| Account and workspace | Until you delete the account or the workspace |
| Sessions | 30 days, or 14 idle days, or until you end them |
| Invitations | Seven days |
| Verification codes and reset links | 30 minutes |
| Crawled pages, runs and change records | The project's retention setting (7 days on the free plan) |
| Request logs | [log retention, e.g. 30 days] |
| Where an account came from | As long as the account |
| A newsletter sign-up never confirmed | 30 days |
| A newsletter subscription | Until you unsubscribe; after that, your address and the dates, as the record of your choice, until you ask us to erase them |
| Site analytics in Google Analytics | [Analytics retention, e.g. 14 months] |
| Error reports | [Sentry retention, usually 90 days] |
| Invoices and financial records | As long as tax law requires, usually seven years |
Deleting your account removes your profile and ends your sessions at once. A workspace whose last owner deletes their account is deleted with its projects, pages, keys and connections within 30 days, except for the financial records above.
Your rights#
Wherever you are, you can see and correct what we hold about you in Profile and Settings. If you are in the EEA, the UK, Switzerland, California or another place with a data protection law, you also have the right to ask for a copy of your data, to have it corrected or erased, to restrict or object to its processing, to take it with you, and to complain to your supervisory authority. To exercise any of these, including deleting your account, write to [email protected] from the address on the account and we will answer within 30 days. You may also name someone to exercise these rights for you if you are unable to. We will never treat you differently for exercising a right.
Our grievance officer for data protection is [Grievance officer name], reachable at [email protected] and at the address below.
Security#
Everything travels over TLS. Passwords are hashed, API keys are hashed and shown once, destination credentials are encrypted at rest, and every query is scoped to the workspace that owns it. Keys carry scopes, an optional project list, an expiry and a rate limit. How we run security, and how to report a vulnerability, is on the security page.
If something goes wrong#
If personal data is lost, exposed or taken, we tell the supervisory authority within 72 hours where the law requires it, and we tell the workspace owners affected without undue delay, saying what happened, what data was involved, and what we are doing about it.
Children#
MeshArc is a tool for work and is not directed at anyone under 18. We do not knowingly hold data about children; tell us if we do and we will delete it.
Changes#
When this policy changes we update the date at the top. For a change that affects what we collect or how we use it, we email every workspace owner before it takes effect.
Contact#
[email protected] · [Legal entity name], [registered address].