MeshMsg — Privacy Policy & Terms of Service
Summary: MeshMsg is built on a Zero-Knowledge, end-to-end encrypted, peer-to-peer architecture. We do not read, store, or sell your messages or personal data. The sections below explain exactly what minimal data is used and why.
1. Privacy Policy
1.1 What We Do NOT Collect
- Messages & Media: We do not store, access, or process your messages, photos, videos, voice notes, or files. All content is end-to-end encrypted (E2E) and transmitted directly between users via WebRTC.
- Plaintext Contact Lists & Phone Numbers: Your raw address book and plaintext phone numbers are never uploaded to any server. Contact matching is conducted on-device using irreversible cryptographic hashes.
- IP Addresses / Browsing: We do not log your IP address or monitor your browsing or usage behavior.
- Location History: Live location data is sent exclusively over encrypted peer-to-peer channels directly to the contact you choose and is never stored on our servers.
1.2 Minimal Data We Use (and Why)
| Data Type |
Purpose |
Stored Where? |
| 11-Digit Private Number (Username) |
To ensure your unique identity on the network |
Our secure registry (Firebase) |
| Cryptographic Phone Hash (Optional) |
Optional Zero-Knowledge contact discovery so mutual friends can find you. Converted on-device into an irreversible SHA-256 hash. Plaintext numbers are never stored on servers. |
Secure directory (Firebase Firestore) as irreversible 256-bit hashes only. Can be deleted/unlinked anytime from Profile. |
| FCM Push Token |
To wake your device for incoming call/message notifications |
Our server (Firebase FCM) |
| Abuse Report Metadata |
If you voluntarily report a user, the reported User ID & summary is sent to our grievance team |
Temporary review log only |
1.3 Third-Party Services We Use
To operate key features, MeshMsg uses the following trusted third-party services. None of these services have access to your message content.
| Service |
Provider |
Purpose |
Data Shared |
| Firebase (FCM) |
Google LLC |
Push Notifications (to wake device for incoming messages & calls) |
FCM token only. No message content. |
| Firebase Hosting |
Google LLC |
Hosting the invite links, web guest access & this privacy page |
Standard web server logs (IP, timestamp) |
| MQTT Public Relay (test.mosquitto.org) |
Eclipse Foundation |
Used ONLY as a temporary, anonymous WebRTC signaling bridge for the "Web Guest Access" feature, allowing someone without the app to initiate a connection request. This relay carries no personal data — only short-lived, anonymous connection handshake signals. |
Anonymous session tokens only. No user identity, no messages. |
| Google ML Kit (On-Device) |
Google LLC |
On-device neural language translation. Runs entirely locally on your phone. |
Nothing. Fully offline. No data leaves your device. |
1.4 Device Permissions & Why We Need Them
- Microphone & Camera: For voice messages and video/voice calls only. Never activated without user action.
- Contacts (Read): To discover mutual friends who also use MeshMsg and let you invite contacts. Raw address books are never uploaded to any server. Phone numbers are hashed locally on-device using irreversible SHA-256 before matching.
- Location (Fine & Background): Used ONLY when you explicitly start the "Share Live Location" feature. Background location is needed so the stream continues when you switch apps. You can stop sharing at any time.
- Bluetooth & Nearby WiFi Devices: For the Offline Mesh Network feature, which allows you to chat with nearby users without internet. This is opt-in and controlled by you.
- Phone State (READ_PHONE_STATE): Used to detect incoming phone calls so that an active VoIP call in MeshMsg can be automatically paused, preventing audio conflicts.
- Motion Sensor (Accelerometer): Used briefly and locally to generate a Zero-Knowledge Proof (ZKP) of humanity to prevent bot attacks on the P2P network. The raw sensor data is never transmitted or stored.
- Notifications: To display incoming message and call alerts.
1.5 Special Features — Privacy Details
- Zero-Knowledge Mutual Phone Discovery: If you optionally link your mobile number, MeshMsg generates salted, irreversible SHA-256 cryptographic hashes on-device. Discovered contacts appear only if both users mutually have each other saved in their phonebooks. Your plaintext phone number is never stored on servers, and you can unlink/delete your number anytime.
- EXIF Metadata Stripping: All images are automatically stripped of hidden GPS, camera, and timestamp metadata locally before sending.
- Offline Mesh Network: Messages sent via Bluetooth/WiFi Direct mesh are E2E encrypted and travel only between nearby devices. No internet required.
- Swarm Compute Network (Optional): If you enable "Join Swarm Compute Network," your device's idle processing power may be used to assist with distributed P2P network tasks. This is entirely opt-in. No personal data is collected or transmitted as part of this feature.
- Local VPN / Mesh Firewall (Optional): This is a strict local-only loopback that filters only MeshMsg's own traffic to prevent IP leakage during P2P calls. It does NOT monitor or intercept traffic from any other app.
- Zero-Energy Ambient SOS (Beta): If enabled, when your battery drops below 5%, the app simulates broadcasting a local emergency beacon. No data is sent to external servers.
2. Terms of Service (ToS)
- Acceptance: By using MeshMsg, you agree to these terms.
- Usage Policy: MeshMsg is intended for private, secure communication between consenting adults. It must not be used to facilitate illegal activities, terrorism, child exploitation, or harassment.
- Zero-Tolerance for Abuse: Although we cannot read your encrypted messages, if a user is reported with valid evidence of illegal activity, we reserve the right to permanently ban the offending account ID from our signaling servers.
- No Liability for Lost Keys: You are solely responsible for securing your 12-word Recovery Phrase. If you lose it, MeshMsg cannot recover your account or your chats.
- Service Availability: As a decentralized mesh network app, message delivery depends on the peer-to-peer network and local device connectivity. We do not guarantee 100% uptime.
- Prohibited Content: You agree not to use MeshMsg to send, store, or share illegal content of any kind, including but not limited to CSAM, incitement to violence, or fraudulent material.
3. Law Enforcement Guidelines
- What We Can Provide: Upon receipt of a valid legal request, we can only provide: the date an account was registered, the associated Firebase Cloud Messaging token, and cryptographic phone hash (if optionally linked).
- What We Cannot Provide: We cannot provide chat histories, media, IP logs, or contact lists, as this data is never stored on our servers. Our architecture ensures cryptographic impossibility of mass surveillance.
4. How to Delete Your Data
- Unlinking Phone Number: You can unlink or delete your mobile number anytime inside the app via Profile > Edit Profile > Delete Phone Number. This instantly and permanently deletes your cryptographic phone hash from our registry.
- In-App Account Deletion (Recommended): Open MeshMsg → Settings > Delete Account & Reset. This instantly wipes your Private Number, phone hash, all chats, media, and encryption keys from your device and our registry.
- By Uninstalling: Because MeshMsg uses a Zero-Knowledge, Serverless architecture, simply uninstalling the app also permanently destroys all your local data, messages, and cryptographic keys.
- Data Retention: Since we do not store your messages or personal files on our servers, there is no remote data for us to delete. Once you delete your account, your data is cryptographically irrecoverable.
5. Children's Privacy
- MeshMsg is not intended for use by children under the age of 13. We do not knowingly collect any data from children. If you believe a child has registered on our platform, please contact us immediately.
6. Changes to This Policy
- We may update this Privacy Policy from time to time. Any significant changes will be announced within the app. Continued use of the app after changes constitutes acceptance of the new policy.
7. Contact Us
- For privacy concerns, data deletion requests, or abuse reports, please contact us via the "Report / Feedback" option inside the app, or email us at: paresh101p@gmail.com