MeshMsg Legal & Security Documentation
1. Privacy Policy
- We Collect Nothing: MeshMsg operates on a strict Zero-Knowledge architecture. We do not store, access, or process your personal messages, photos, videos, or files. All communication is end-to-end encrypted and transmitted directly between users using WebRTC.
- Minimal Metadata: The only data required for basic functionality:
- Username Registry: To ensure your 11-digit Private Number is uniquely yours.
- Notification Tokens: Used exclusively to wake up your device for incoming calls/messages.
- Report Metadata: If you voluntarily report a user for abuse, the associated User ID and reported content are forwarded to our grievance team for review.
- No Third-Party Access: Because we do not possess your conversational data, we cannot share it with advertisers, governments, or third parties.
- Location Privacy: Untrackable P2P Location Sharing. Location pins and Live Location streams are transmitted securely over E2E channels. Live Location data is never sent to central servers and automatically self-destructs when your custom timer expires.
- Anti-Scam Verification: Unlike legacy apps, random phone numbers cannot contact you. Users must explicitly share and verify their unique 11-digit Private Number or scan a private QR code to establish a trusted connection.
- ZKP Proof-of-Humanity & Sensor Data: To prevent botnets from attacking the peer-to-peer network, MeshMsg locally analyzes brief hardware accelerometer (motion) data and human interaction patterns to verify you are a real person. This generates a Zero-Knowledge Proof (ZKP). The raw sensor data is never transmitted over the network or saved anywhere. Only the mathematical proof is shared to establish a trusted connection.
- Context-Aware Dynamic Avatars: MeshMsg may periodically share non-identifying telemetry (such as your device's battery level percentage or network latency) with your direct contacts to visually update your profile avatar status (e.g., showing a red border if your battery is critically low). This data is shared strictly over secure E2E channels and is never collected or logged by any server.
- EXIF Metadata Stripping: To prevent accidental tracking, all images selected from your gallery are automatically stripped of hidden EXIF metadata (e.g., GPS coordinates, camera model, timestamps) locally on your device before encryption.
- Serverless Group Video Calls: Group video and audio calls are fully peer-to-peer (up to 5 users). No central SFU (Selective Forwarding Unit) or media server is used. Your audio and video streams flow directly between participants and are strictly end-to-end encrypted.
- Local VPN Service (Mesh Firewall): MeshMsg includes an optional "Network Lockdown Firewall" feature that uses Android's VpnService API. This is a strict local-only loopback VPN that intercepts and filters ONLY MeshMsg's own app traffic to prevent IP leakage during P2P calls. Important: It does NOT route, monitor, log, or intercept traffic from any other apps on your device, nor does it send any VPN traffic to external servers. No browsing activity or data is collected or stored by this service.
- Absolute User Control: Your data resides exclusively on your local device hardware. We provide no cloud backups. Your only backup mechanism is your 12-word cryptographic BIP39 seed phrase. Deleting the app permanently wipes all local data.
2. Terms of Service (ToS)
- Acceptance: By using MeshMsg, you agree to these terms.
- Usage Policy: MeshMsg is intended for private, secure communication. It must not be used to facilitate illegal activities, terrorism, child exploitation, or harassment.
- Zero-Tolerance for Abuse: Although we cannot read your encrypted messages, if a user is reported with valid evidence of illegal activity, we reserve the right to permanently ban the offending account ID from our signaling servers.
- No Liability for Lost Keys: You are solely responsible for securing your 12-word Recovery Phrase. If you lose it, MeshMsg cannot recover your account or your chats.
- Service Availability: As a decentralized mesh network app, message delivery depends on the peer-to-peer network and local device connectivity. We do not guarantee 100% uptime.
3. Law Enforcement Guidelines
- What We Can Provide: Upon receipt of a valid legal request, we can only provide the date an account was registered and the associated Firebase Cloud Messaging token.
- What We Cannot Provide: We cannot provide chat histories, media, IP logs, or contact lists, as this data is never stored on our servers. Our architecture ensures cryptographic impossibility of mass surveillance.
4. How to Delete Your Data
- In-App Deletion (Recommended): You can permanently delete all your data and account directly from the app. Open MeshMsg, navigate to Settings > Delete Account & Reset, and confirm the deletion. This will instantly wipe your 11-digit Private Number, all chats, media, and encryption keys from your device and our registry.
- Local Data Wipe: Because MeshMsg uses a Zero-Knowledge, Serverless architecture, simply uninstalling the app from your device will also permanently destroy all your local data, messages, and cryptographic keys. We do not keep cloud backups.
- Data Retention: Since we do not store your messages or personal files on our servers, there is no remote data for us to delete. Once you delete your account or uninstall the app, your data is cryptographically irrecoverable.