We don't sell your data. We don't train on it. Full stop.
This policy describes what MeshInfer.AI collects, why, how long we keep it, and every right you have over it. Effective April 20, 2026.
Who we are
MeshInfer.AI ("MeshInfer.AI", "we", "us") is a Delaware corporation operating the distributed AI inference platform at meshinfer.ai. Our registered address is 548 Market St, PMB 91410, San Francisco, CA 94104, USA.
For EU/UK residents, MeshInfer.AI acts as a data controller under the GDPR and UK GDPR respectively. Our Data Protection Officer can be reached at support@dosfi.ai.
What we collect and why
Account data
| Name & email | Required to create an account and send invoices. |
| Company name | Optional. Used for enterprise contract management. |
| Billing address | Required by payment processor (Stripe) for invoicing. |
Usage & telemetry data
| API request metadata | Route chosen (local/mesh/cloud), model alias, token counts, wall time, cost. No prompt or response bodies. |
| SDK telemetry | Anonymous, aggregated performance metrics (latency, error rates). No user-identifying fields. Can be disabled via telemetry: false in SDK init. |
| Node capability vectors | Hardware fingerprint (CPU/GPU/RAM class) signed and uploaded on SDK init. Used for routing only. Rotated every 24h. |
What we never collect
How we use your data
| Service operation | Routing decisions, billing, fraud prevention, SLA monitoring. |
| Product improvement | Aggregated, de-identified telemetry to improve routing heuristics and latency. |
| Legal compliance | Responding to lawful requests from courts or regulators. We will notify you unless legally prohibited. |
| Security | Detecting and investigating abuse, verifying node integrity. |
We do not use your data for advertising, behavioural profiling, or any purpose beyond operating and improving the MeshInfer.AI platform.
Data sharing
We share data only with:
| Stripe | Payment processing. Subject to Stripe's privacy policy. |
| AWS / Cloudflare | Infrastructure. Data processed under DPA with EU SCCs. |
| ClickHouse Cloud | Metering analytics (no prompt data). DPA in place. |
| Legal authorities | Only in response to valid, lawful orders. We challenge overbroad requests. |
We do not sell, rent, or broker personal data to any third party.
Data retention
| Prompt / response bodies | Never stored. Zero retention. |
| Metering events | 30 days hot storage, 13 months cold (S3 Glacier). Fields: no body, no prompt hash. |
| Account data | Retained while your account is active + 90 days post-closure for dispute resolution. |
| Audit logs (Enterprise) | 7 years, append-only. Required for compliance frameworks. |
| Capability vectors | 24-hour rolling window. |
Your rights
Depending on your jurisdiction you may have the right to:
- Access โ request a copy of all personal data we hold about you.
- Rectification โ correct inaccurate data.
- Erasure โ request deletion of your data (subject to legal retention requirements).
- Portability โ receive your data in a machine-readable format.
- Objection โ object to processing based on legitimate interests.
- Restriction โ request we limit processing while a complaint is investigated.
Exercise any right by emailing support@dosfi.ai. We respond within 30 days. EU/UK residents may also lodge a complaint with their local supervisory authority.
Cookies & tracking
| Strictly necessary | Session token, CSRF cookie. Cannot be disabled. |
| Analytics | Anonymous product analytics (PostHog, self-hosted). Can be disabled in account settings. |
| No advertising cookies | We do not run ad networks or third-party retargeting pixels. |
Security
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to production systems requires hardware MFA and is limited to on-call engineers under a least-privilege model. Breaches are disclosed to affected users within 72 hours of discovery per GDPR Article 33.
Changes to this policy
Material changes will be communicated by email and via a banner on the dashboard at least 14 days before taking effect. Continued use after the effective date constitutes acceptance. Prior versions are archived at meshinfer.ai/legal/privacy/history.
US State Privacy Rights
Depending on the US state where you reside, you may have specific privacy rights under applicable state law. The following states have enacted comprehensive consumer privacy legislation that may apply to you:
Covered states
| California (CCPA/CPRA) | California Consumer Privacy Act & California Privacy Rights Act |
| Virginia (VCDPA) | Virginia Consumer Data Protection Act |
| Colorado (CPA) | Colorado Privacy Act |
| Connecticut (CTDPA) | Connecticut Data Privacy Act |
| Utah (UCPA) | Utah Consumer Privacy Act |
| Texas (TDPSA) | Texas Data Privacy and Security Act |
| Oregon (OCPA) | Oregon Consumer Privacy Act |
| Montana (MCDPA) | Montana Consumer Data Privacy Act |
| Iowa (ICDPA) | Iowa Consumer Data Protection Act |
| Delaware (DPDPA) | Delaware Personal Data Privacy Act |
Your rights under state law
Residents of the above states have the right to:
- Know / Access โ request disclosure of the categories and specific pieces of personal data we have collected about you, the sources, our business purpose for collection, and third parties we share it with.
- Delete โ request deletion of personal data we have collected from you, subject to certain exceptions (e.g., legal obligations, fraud prevention).
- Correct โ request correction of inaccurate personal data (available in most states).
- Opt-Out of Sale / Sharing โ we do not sell or share personal data for cross-context behavioral advertising. No opt-out is required, but you may submit a request for confirmation.
- Opt-Out of Targeted Advertising โ we do not conduct targeted advertising using your personal data.
- Data Portability โ receive a copy of your personal data in a portable, machine-readable format.
- Limit Sensitive Data Use โ we do not process sensitive personal data beyond what is strictly necessary to operate the service.
- Non-Discrimination โ we will not discriminate against you for exercising any of these rights.
California-specific disclosures (CCPA/CPRA)
| Personal data "sold" or "shared" | None. We do not sell or share personal data as defined under the CCPA/CPRA. |
| Sensitive personal data | We collect billing address and payment method (processed by Stripe). We do not use or disclose sensitive personal data for purposes other than service operation. |
| Financial incentives | We do not offer any financial incentive programs that involve the collection or use of personal data. |
| "Do Not Sell or Share" signal | We honor Global Privacy Control (GPC) browser signals as a valid opt-out request. |
| Shine the Light | California Civil Code ยง 1798.83: we do not disclose personal data to third parties for their direct marketing purposes. |
Categories of personal data collected (CCPA)
| Identifiers | Name, email address, IP address (hashed), API key. Collected for account management and fraud prevention. |
| Commercial information | Billing records, purchase history, plan tier. Collected for invoicing. |
| Internet / network activity | API request metadata (no prompt bodies), SDK telemetry (anonymized). Collected for service operation. |
| Geolocation data | Country / region inferred from IP for routing and compliance only. Not precise location. |
| Professional information | Company name (optional). Collected for enterprise account management. |
We do not collect: biometric data, health data, racial/ethnic origin, sexual orientation, religious beliefs, or precise geolocation.
How to exercise your rights
Submit a verifiable consumer request by emailing support@dosfi.ai with the subject line "US Privacy Rights Request" and your state of residence. We will verify your identity before processing the request. You may also designate an authorized agent to act on your behalf โ provide written authorization when submitting.
| Response time | 45 days from receipt of a verifiable request. May be extended by an additional 45 days with notice. |
| Cost | Free for up to two requests per 12-month period. |
| Appeals | If we deny your request, you may appeal by replying to our denial notice. We will respond within 60 days. You may then contact your state Attorney General. |
