MeshTalk

Legal

Privacy policy

Last updated 2026-09-09

The short version: chats are end-to-end encrypted, work over LAN with no internet at all, and the control service never sees message contents. There is one exception: optional, off-by-default analytics in release builds. That is all this policy covers.

1. Scope

This policy applies only to the analytics described here. It does not apply to:

  • your messages, files, friends, rooms, or identities, which never leave your devices except as end-to-end encrypted traffic to peers you chose;
  • the control and relay service and STUN, which necessarily observe network endpoints to connect peers;
  • third-party services you interact with directly, such as update channels or Cloudflare edge logs.

2. What we collect, only with your consent

Analytics is off until you explicitly opt in at first launch, with Off preselected and no pre-ticked boxes. Two levels exist:

  • Basic: a version ping at most once per app version: app version, operating system, CPU architecture.
  • Extended (optional): the above plus aggregate room, group, and transport counters, and sanitized stability counters (exception class names only). Sent at most hourly and on clean shutdown. Counts saturate at 10,000 and clear after each attempt.

3. What we never collect

No persistent or installation IDs, peer IDs, public keys, room IDs or secrets, invites, message or file contents, filenames, paths, usernames, or activity counters. There is deliberately no way to join analytics records back to a person or device on our side.

4. How we use it

Solely to understand release adoption and connection health so development effort goes where it matters. We do not use it for advertising, profiling, pricing, or automated decision-making, and we do not sell or share aggregates.

5. Sharing and third parties

  • The analytics proxy runs on Cloudflare Workers and forwards to our ingest. Neither sells or shares this data.
  • IP addresses are not stored; the server keeps only daily aggregate counters. They are still unavoidably visible in transit and for per-IP rate limiting.
  • Counts are approximate: the endpoint is open and unauthenticated by design, so counts are poisonable and must not be treated as exact.

6. Retention

Ninety days of rolling daily aggregates, then deleted. No raw requests, payloads, or IPs are logged or retained by us.

7. Your choices and rights

  • Change or withdraw consent anytime: Settings › Diagnostics, or MESHTALK_ANALYTICS=extended|basic|off.
  • Verify for yourself: with analytics off, tcpdump or your proxy logs should show no egress to the analytics hosts outside update checks.
  • Because we hold no identifiers, we cannot look up, export, or delete "your" records. There is nothing keyed to you.

8. Children

MeshTalk has no age-gated accounts and analytics contains no personal data, but analytics should not be enabled for children under 13, or your local age of digital consent. Leave it off.

9. Changes to this policy

Material changes appear here with a new date and, where feasible, are announced with a release. Continued opt-in after a change takes effect constitutes acceptance; you can always switch analytics off.

10. Contact

Questions or requests: open an issue at QinCai-rui/MeshTalk.