Legal ยท Privacy Policy

We don't sell your data. We don't train on it. Full stop.

This policy describes what MeshInfer.AI collects, why, how long we keep it, and every right you have over it. Effective April 20, 2026.

1

Who we are

MeshInfer.AI ("MeshInfer.AI", "we", "us") is a Delaware corporation operating the distributed AI inference platform at meshinfer.ai. Our registered address is 548 Market St, PMB 91410, San Francisco, CA 94104, USA.

For EU/UK residents, MeshInfer.AI acts as a data controller under the GDPR and UK GDPR respectively. Our Data Protection Officer can be reached at support@dosfi.ai.

2

What we collect and why

Account data

Name & emailRequired to create an account and send invoices.
Company nameOptional. Used for enterprise contract management.
Billing addressRequired by payment processor (Stripe) for invoicing.

Usage & telemetry data

API request metadataRoute chosen (local/mesh/cloud), model alias, token counts, wall time, cost. No prompt or response bodies.
SDK telemetryAnonymous, aggregated performance metrics (latency, error rates). No user-identifying fields. Can be disabled via telemetry: false in SDK init.
Node capability vectorsHardware fingerprint (CPU/GPU/RAM class) signed and uploaded on SDK init. Used for routing only. Rotated every 24h.

What we never collect

Zero prompt retention
Prompt and completion bodies are never written to disk by the Coordinator. They exist only in-memory for the duration of inference routing. This is architecturally enforced, not a policy promise โ€” there is no store to subpoena.
3

How we use your data

Service operationRouting decisions, billing, fraud prevention, SLA monitoring.
Product improvementAggregated, de-identified telemetry to improve routing heuristics and latency.
Legal complianceResponding to lawful requests from courts or regulators. We will notify you unless legally prohibited.
SecurityDetecting and investigating abuse, verifying node integrity.

We do not use your data for advertising, behavioural profiling, or any purpose beyond operating and improving the MeshInfer.AI platform.

4

Data sharing

We share data only with:

StripePayment processing. Subject to Stripe's privacy policy.
AWS / CloudflareInfrastructure. Data processed under DPA with EU SCCs.
ClickHouse CloudMetering analytics (no prompt data). DPA in place.
Legal authoritiesOnly in response to valid, lawful orders. We challenge overbroad requests.

We do not sell, rent, or broker personal data to any third party.

5

Data retention

Prompt / response bodiesNever stored. Zero retention.
Metering events30 days hot storage, 13 months cold (S3 Glacier). Fields: no body, no prompt hash.
Account dataRetained while your account is active + 90 days post-closure for dispute resolution.
Audit logs (Enterprise)7 years, append-only. Required for compliance frameworks.
Capability vectors24-hour rolling window.
6

Your rights

Depending on your jurisdiction you may have the right to:

  • Access โ€” request a copy of all personal data we hold about you.
  • Rectification โ€” correct inaccurate data.
  • Erasure โ€” request deletion of your data (subject to legal retention requirements).
  • Portability โ€” receive your data in a machine-readable format.
  • Objection โ€” object to processing based on legitimate interests.
  • Restriction โ€” request we limit processing while a complaint is investigated.

Exercise any right by emailing support@dosfi.ai. We respond within 30 days. EU/UK residents may also lodge a complaint with their local supervisory authority.

7

Cookies & tracking

Strictly necessarySession token, CSRF cookie. Cannot be disabled.
AnalyticsAnonymous product analytics (PostHog, self-hosted). Can be disabled in account settings.
No advertising cookiesWe do not run ad networks or third-party retargeting pixels.
8

Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to production systems requires hardware MFA and is limited to on-call engineers under a least-privilege model. Breaches are disclosed to affected users within 72 hours of discovery per GDPR Article 33.

9

Changes to this policy

Material changes will be communicated by email and via a banner on the dashboard at least 14 days before taking effect. Continued use after the effective date constitutes acceptance. Prior versions are archived at meshinfer.ai/legal/privacy/history.

10

US State Privacy Rights

Depending on the US state where you reside, you may have specific privacy rights under applicable state law. The following states have enacted comprehensive consumer privacy legislation that may apply to you:

Covered states

California (CCPA/CPRA)California Consumer Privacy Act & California Privacy Rights Act
Virginia (VCDPA)Virginia Consumer Data Protection Act
Colorado (CPA)Colorado Privacy Act
Connecticut (CTDPA)Connecticut Data Privacy Act
Utah (UCPA)Utah Consumer Privacy Act
Texas (TDPSA)Texas Data Privacy and Security Act
Oregon (OCPA)Oregon Consumer Privacy Act
Montana (MCDPA)Montana Consumer Data Privacy Act
Iowa (ICDPA)Iowa Consumer Data Protection Act
Delaware (DPDPA)Delaware Personal Data Privacy Act

Your rights under state law

Residents of the above states have the right to:

  • Know / Access โ€” request disclosure of the categories and specific pieces of personal data we have collected about you, the sources, our business purpose for collection, and third parties we share it with.
  • Delete โ€” request deletion of personal data we have collected from you, subject to certain exceptions (e.g., legal obligations, fraud prevention).
  • Correct โ€” request correction of inaccurate personal data (available in most states).
  • Opt-Out of Sale / Sharing โ€” we do not sell or share personal data for cross-context behavioral advertising. No opt-out is required, but you may submit a request for confirmation.
  • Opt-Out of Targeted Advertising โ€” we do not conduct targeted advertising using your personal data.
  • Data Portability โ€” receive a copy of your personal data in a portable, machine-readable format.
  • Limit Sensitive Data Use โ€” we do not process sensitive personal data beyond what is strictly necessary to operate the service.
  • Non-Discrimination โ€” we will not discriminate against you for exercising any of these rights.

California-specific disclosures (CCPA/CPRA)

Personal data "sold" or "shared"None. We do not sell or share personal data as defined under the CCPA/CPRA.
Sensitive personal dataWe collect billing address and payment method (processed by Stripe). We do not use or disclose sensitive personal data for purposes other than service operation.
Financial incentivesWe do not offer any financial incentive programs that involve the collection or use of personal data.
"Do Not Sell or Share" signalWe honor Global Privacy Control (GPC) browser signals as a valid opt-out request.
Shine the LightCalifornia Civil Code ยง 1798.83: we do not disclose personal data to third parties for their direct marketing purposes.

Categories of personal data collected (CCPA)

IdentifiersName, email address, IP address (hashed), API key. Collected for account management and fraud prevention.
Commercial informationBilling records, purchase history, plan tier. Collected for invoicing.
Internet / network activityAPI request metadata (no prompt bodies), SDK telemetry (anonymized). Collected for service operation.
Geolocation dataCountry / region inferred from IP for routing and compliance only. Not precise location.
Professional informationCompany name (optional). Collected for enterprise account management.

We do not collect: biometric data, health data, racial/ethnic origin, sexual orientation, religious beliefs, or precise geolocation.

How to exercise your rights

Submit a verifiable consumer request by emailing support@dosfi.ai with the subject line "US Privacy Rights Request" and your state of residence. We will verify your identity before processing the request. You may also designate an authorized agent to act on your behalf โ€” provide written authorization when submitting.

Response time45 days from receipt of a verifiable request. May be extended by an additional 45 days with notice.
CostFree for up to two requests per 12-month period.
AppealsIf we deny your request, you may appeal by replying to our denial notice. We will respond within 60 days. You may then contact your state Attorney General.
Authorized Agent
California and Virginia residents may designate an authorized agent to submit requests on their behalf. To do so, provide a signed written authorization or a valid power of attorney at the time of the request.
Contact
Privacy questions: support@dosfi.ai ยท DPO: support@dosfi.ai ยท Last updated: April 20, 2026