MESH CollectiveSign In

Privacy Policy

MESH AI Platform Privacy Policy

Last Updated: September 1, 2026

Effective Date: March 15, 2026


1. Introduction

This Privacy Policy describes how MESH, L.L.C. ("MESH," "we," "us," or "our") collects, uses, stores, and protects information when you access or use the MESH AI Platform (the "Service"), our website at app.whenwemesh.ai (the "Site"), and any related services we provide.

MESH is a business-to-business ("B2B") software-as-a-service platform that provides AI-powered brand content generation tools. This Privacy Policy applies to all users of the Service, including account holders, authorized team members, and visitors to our Site.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.


2. Information we collect

We collect the following categories of information:

2.1 Account information

When you create an account or register for the Service, we collect:

  • Email address — used for account creation, authentication, and communications
  • Company name — used to identify your organization and customize the Service
  • Name and job title — used for account personalization and communications
  • Password (encrypted) — used for account authentication

2.2 Payment information

When you subscribe to a paid plan, we collect billing information through our third-party payment processor, including:

  • Credit or debit card number
  • Billing address
  • Transaction history and subscription plan details

We do not store your full credit card number on our servers. Payment information is transmitted directly to and processed by our payment processor, which handles your data in accordance with PCI DSS standards.

2.3 Brand assets and content

When you use the Service, you may provide:

  • Brand guidelines — including brand colors, fonts, typography preferences, tone of voice, and style instructions
  • Logos and images — uploaded brand assets stored for content generation
  • Input text and prompts — text you provide to generate content through the Service
  • Generated content — AI-generated outputs created through the Service

2.4 Social media account information

When you connect third-party publishing destinations — social platforms, video platforms, or your own website — we may receive:

  • Public profile information (name, profile picture, profile URL) for the specific account, page, channel, or site you connected
  • Account identifiers necessary to publish content on your behalf
  • Page or account management permissions you authorize
  • Engagement metrics for posts we published on your behalf, where you have granted read access

We access only the data you explicitly authorize during the consent flow, and only for the account you connected. Connecting one account does not give us access to any other account you hold on that platform.

Access credentials. To publish at a scheduled time we must hold the access credential the platform issues. These credentials are encrypted at rest using AES-256-GCM, are decrypted only in memory at the moment a publish request is made, are never written to logs, and are never shared with third parties. Website destinations use a scoped credential you generate yourself (a WordPress Application Password or a Webflow Site API Token) and can revoke from your own admin at any time.

2.4a Scheduled content and publishing records

When you use the Content Scheduler we store the content you have scheduled and a record of what was published:

  • Post copy, article bodies, attached images and video, and any first comment
  • The destination, the scheduled time, and the time zone it was resolved against
  • The approval trail — who submitted, approved, or requested changes, and any comments they left
  • After publishing: the platform's identifier for the post, its public URL where the platform returns one, and any error if publishing failed

Publishing is unattended by design. Once content has been approved and scheduled by a user in your organization, our systems submit it to the destination at the chosen time without a person present. Nothing is published unless it has been explicitly approved and scheduled, and an item can be edited, unscheduled, or deleted at any time before it is sent.

2.5 Google Search Console data

If you choose to connect your Google Search Console account, we access:

  • Search performance data (queries, impressions, clicks, average position)
  • Website property information for your verified domains

This data is used exclusively to provide SEO analytics and content optimization features within the Service.

2.6 Usage and technical data

We automatically collect certain information when you use the Service:

  • IP address and approximate geolocation
  • Browser type, operating system, and device information
  • Pages viewed, features used, and interactions with the Service
  • Date and time of access, session duration
  • Referring URLs and navigation patterns
  • Error logs and performance data

3. How we use your information

We use the information we collect for the following purposes:

  • Providing the Service — to operate, maintain, and deliver the features and functionality of the MESH AI Platform, including generating AI-powered content based on your inputs and brand guidelines
  • Account management — to create and manage your account, authenticate your identity, and provide customer support
  • Payment processing — to process subscription payments, manage billing, and maintain transaction records
  • Social media publishing — to publish content to your connected social media accounts when you authorize such actions
  • Analytics and improvement — to understand how users interact with the Service, identify trends, and improve platform features and performance
  • Communications — to send you service-related notices, updates, security alerts, and support messages
  • Security and fraud prevention — to detect, prevent, and address technical issues, security threats, and fraudulent activity
  • Legal compliance — to comply with applicable laws, regulations, and legal processes

4. How we do NOT use your information

We believe transparency about what we do not do with your data is equally important:

  • We do NOT sell your personal information to third parties, and we have never sold personal information.
  • We do NOT share your personal information with third parties for their own marketing or advertising purposes.
  • We do NOT use your inputs, brand assets, or generated content to train AI models. Your content is processed by our AI service providers solely to generate outputs for you and is not used to improve or train any artificial intelligence or machine learning models.
  • We do NOT use your brand guidelines, logos, or generated content for any purpose other than providing the Service to you.
  • We do NOT access your social media private messages, friend lists, contacts, or personal photos beyond what is explicitly authorized through the OAuth consent flow.

5. AI processing and third-party AI services

5.1 How AI processing works

Our Service uses artificial intelligence technologies, including third-party AI models, to process your inputs and generate content. When you use our AI-powered features, your input text and relevant brand context are transmitted to our AI service providers for processing.

5.2 Anthropic Claude API

We use the Anthropic Claude API to power our AI content generation features. When you submit content for AI processing:

  • Your input text is transmitted to Anthropic's servers for processing and response generation
  • Under our commercial API agreement with Anthropic, your data is not used to train Anthropic's AI models
  • Inputs may be retained by Anthropic for a limited period solely for safety monitoring and abuse prevention, as governed by Anthropic's commercial terms
  • Anthropic's privacy practices are described in their privacy policy at https://www.anthropic.com/privacy

5.3 Automated decision-making

Our Service uses automated processing to generate content based on your inputs. This automated processing does not make decisions that produce legal or similarly significant effects on you. You retain full control over whether to use, modify, or discard any AI-generated content.


6. Third-party services

We use the following categories of third-party services to operate the MESH AI Platform. Each service receives only the minimum data necessary to perform its function.

6.1 Authentication — Google OAuth

We offer the option to sign in using your Google account via OAuth 2.0. When you sign in with Google, we receive your name, email address, and profile picture from your Google account. We use this information solely to create and manage your account on our Service. We do not access, store, or share any other Google account data. We do not sell your Google user data to third parties. Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

6.2 Cloud infrastructure — DigitalOcean

Our Service is hosted on DigitalOcean cloud infrastructure. Your data, including account information, brand assets, and generated content, is stored on DigitalOcean Spaces and related infrastructure. DigitalOcean acts as our infrastructure provider and processes data solely on our behalf under a data processing agreement.

6.3 Payment processing

We use a third-party payment processor to handle payment transactions. When you make a purchase, your payment information is transmitted directly to our payment processor and is not stored on our servers. Our payment processor's handling of your payment information is governed by their own privacy policy and PCI DSS compliance obligations.

6.4 Publishing destinations

We offer the ability to connect publishing destinations to our Service. Social and video platforms connect via OAuth; website platforms connect with a scoped credential you generate yourself. A permission-by-permission breakdown of what we request and why is published at app.whenwemesh.ai/integrations.

  • LinkedIn — When you connect your LinkedIn account, we may access your public profile information and, with your authorization, publish content to your LinkedIn profile or company pages on your behalf.
  • Facebook — When you connect your Facebook account, we access your public profile information and page management capabilities as authorized by you during the OAuth flow.
  • Instagram — When you connect your Instagram account, we access your business or creator account information and, with your authorization, publish content on your behalf.
  • X (formerly Twitter) — When you connect your X account, we may access your profile information and, with your authorization, post content on your behalf.
  • TikTok — When you connect your TikTok account, we access your basic account information and, with your authorization, publish videos to it or deliver them to your drafts.
  • YouTube — When you connect a YouTube channel, we upload the videos you scheduled to that channel and set them to publish at the time you chose. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: this data is used only to provide the publishing features you requested, is not transferred to third parties except as needed to provide those features or as required by law, is not used for advertising, and is not read by humans except with your explicit consent, for security, to comply with law, or when aggregated and anonymized.
  • WordPress — When you connect a WordPress site using an Application Password you generate, we use it to create posts on that site. We do not read your users, comments, or settings.
  • Webflow — When you connect a Webflow site using a Site API Token you generate, we use it to create items in the one CMS collection you nominate.

Where a platform supports it and you have chosen to use the feature, we may post a single first comment on a post we have just published — typically to carry a link or hashtags. This is the only comment we post. We do not reply to other people, moderate, or interact with anyone else's content.

Where you have granted read access, we retrieve engagement metrics for posts we published on your behalf (impressions, reach, likes, comments, shares) to provide performance reporting inside your own account.

Our use of Meta platform data complies with the Meta Platform Terms and Developer Policies.

For all publishing connections: We do not access your private messages, friend lists, or personal contacts. Data obtained from social media platforms is used solely to provide the features you have requested and is not sold or shared with third parties. We do not use data obtained from these platforms to train machine-learning models, and we do not use it for advertising or to build profiles of individuals.

You may disconnect any destination at any time from the Connections screen in your account, or revoke our access from the platform's own settings. On disconnect we stop using the credential immediately, delete it from our systems, and do not send any content still scheduled to that destination. Records of what was already published are retained as part of your account history; content already live on the platform is unaffected and must be removed there if you want it taken down.

6.5 Google Search Console

When you connect your Google Search Console account, we access your website's search performance data, including search queries, impressions, click-through rates, and average position data for your verified properties. This data is used exclusively to provide content performance analytics and SEO optimization recommendations within our Service. We do not share your Search Console data with third parties. Our use of Google Search Console data complies with the Google API Services User Data Policy.

6.6 Additional data processors

We use the following additional third-party services to provide specific features of our Service. Each service receives only the minimum data necessary to perform its function:

  • OpenAI — We use OpenAI's embedding models to generate vector representations of your brand assets for search and retrieval purposes. Text content is transmitted to OpenAI for processing; under our API agreement, this data is not used to train OpenAI's models. See OpenAI's privacy policy.
  • Google Gemini and Veo — We use Google's Gemini models for AI image generation and Veo models for AI video generation. Your text prompts and optional reference images are transmitted to Google for processing. See Google's AI privacy practices.
  • DataForSEO — When you use keyword research features, search queries are transmitted to DataForSEO to retrieve search volume, difficulty, and competitor data. No personal information is shared.
  • Hunter.io — When you use lead enrichment features, company names and domain URLs are transmitted to Hunter.io to retrieve publicly available professional contact information.
  • Apify — When you use website auditing or content analysis features, website URLs are transmitted to Apify's web scraping infrastructure to retrieve publicly available page content for analysis.
  • PostHog — We use PostHog for product analytics and event tracking to understand how users interact with our Service. PostHog collects anonymized usage data including page views, feature usage, and navigation patterns. See PostHog's privacy policy.
  • Resend — We use Resend to deliver transactional emails including account verification, password reset, and invitation emails. Your email address and name are transmitted to Resend solely for email delivery.

6.7 Agency access to brand data

If your account is managed by an agency or managed service provider using the MESH AI Platform, authorized agency administrators may access your brand data (including brand assets, generated content, conversations, and strategy reports) for the purpose of providing services to you. This access is subject to the following safeguards:

  • Agency access is limited to authorized administrators with appropriate roles
  • All agency access to brand data is logged for audit purposes
  • Agency administrators access your data solely to deliver the services you or your organization have engaged them to provide
  • Brand administrators may request access restrictions by contacting their agency representative

7. Cookies and tracking technologies

We use cookies and similar technologies to operate and improve the Service.

7.1 Essential cookies

These cookies are strictly necessary for the operation of the Service. They include session cookies that keep you logged in, security cookies that protect against cross-site request forgery (CSRF), and cookies that maintain your preferences within a session. These cookies cannot be disabled without affecting the functionality of the Service.

7.2 Analytics cookies

We use analytics tools to understand how users interact with the Service. These cookies collect information about page views, feature usage, and navigation patterns. This data is aggregated to help us improve the Service. Analytics cookies include:

  • Usage pattern tracking to improve platform features
  • Performance monitoring to identify and resolve technical issues
  • Session recording (anonymized) to improve user experience

7.3 Managing cookies

Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all cookies or to indicate when a cookie is being sent. However, disabling essential cookies may prevent you from using certain features of the Service. For analytics cookies, you may opt out through your account settings or browser controls.


8. Data retention

We retain your information only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law. Our general retention practices are as follows:

  • Account data — retained for the duration of your active account, plus a reasonable period after account closure to allow for reactivation or data export
  • Payment and billing records — retained for seven (7) years to comply with tax and accounting obligations
  • Brand assets and generated content — retained for the duration of your active account; deleted upon account termination (subject to the data retrieval period described below)
  • AI input and output data — retained for up to thirty (30) days for operational purposes, then automatically purged (separate from content saved to your account)
  • Usage logs and analytics data — retained in aggregated or anonymized form for up to twenty-four (24) months
  • Support communications — retained for up to three (3) years for dispute resolution and service improvement

8.1 Account termination and data deletion

Upon termination or deletion of your account:

  • You will have thirty (30) days to export your data through the Service
  • After the 30-day data retrieval period, we will permanently delete your personal data, brand assets, and generated content
  • Certain information may be retained where required by law (such as billing records for tax compliance) or to resolve disputes
  • Some data may persist in encrypted backups for a limited additional period, after which it will be permanently removed

8.2 Data deletion requests

You may request deletion of your personal data at any time by contacting us at [email protected]. We will process your request within thirty (30) days and confirm completion. We may need to retain certain information where we have a legal obligation to do so.


9. Data security

We implement industry-standard technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and vulnerability testing
  • Employee access limited to personnel who require it for their job functions
  • Incident response procedures for potential security events

While we take commercially reasonable steps to protect your information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security of your data.


10. Data breach notification

In the event of a data breach that affects your personal information, we will notify affected users in accordance with applicable law. This includes:

  • Notifying affected individuals as promptly as possible, and within the timeframes required by applicable state laws
  • Providing a description of the incident, the types of data involved, steps we are taking in response, and contact information for further inquiries
  • Reporting to applicable state Attorneys General and other regulatory bodies as required by law

11. Your rights and choices

Depending on your jurisdiction, you may have certain rights regarding your personal information:

  • Access — You may request a copy of the personal information we hold about you
  • Correction — You may request that we correct inaccurate or incomplete information
  • Deletion — You may request that we delete your personal information, subject to certain exceptions
  • Portability — You may request a copy of your data in a structured, commonly used, machine-readable format
  • Opt-out — You may opt out of non-essential communications and analytics tracking
  • Withdrawal of consent — Where we rely on your consent to process data, you may withdraw consent at any time

To exercise any of these rights, please contact us at [email protected] or use the relevant controls in your account settings. We will respond to your request within thirty (30) days.

We do not discriminate against users who exercise their privacy rights. Exercising your rights will not affect the quality or availability of the Service.


12. Children's privacy

Our Service is not directed to individuals under the age of 18. We do not knowingly collect, maintain, or use personal information from children under 13 years of age, and no part of our Service is designed to attract anyone under 13. If we learn that personal information has been collected from a user under 13 years of age, we will take appropriate steps to delete that information promptly.

By using our Service, you represent that you are at least 18 years of age, or the age of majority in your jurisdiction, whichever is greater. Our Service is designed for business use and is not intended for use by minors.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected].


13. Do Not Track signals

Some web browsers transmit "Do Not Track" (DNT) signals. Because there is no common industry standard for interpreting DNT signals, the Service does not currently alter its practices when it receives a DNT signal. We do honor the Global Privacy Control (GPC) signal where required by applicable law.


14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. If we make material changes, we will notify you by:

  • Posting the updated Privacy Policy on our Site with a new "Last Updated" date
  • Sending an email notification to the address associated with your account

Material changes will take effect thirty (30) days after we provide notice. Your continued use of the Service after the effective date of the updated Privacy Policy constitutes your acceptance of the changes. If you do not agree with the updated Privacy Policy, you must discontinue use of the Service.


15. Contact us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

MESH, L.L.C. Email: [email protected] Address: MESH, L.L.C., 7924 Wrenwood Blvd, Baton Rouge, LA 70809

© 2026 MESH Collective. All rights reserved.

Privacy PolicyTerms & ConditionsIntegrationswhenwemesh.com