MeshkMeshk logoBack to Home

Meshk — Privacy Policy

Last Modified: 22 July 2026

This Privacy Policy explains how we collect, use, share, and protect your personal data when you use the Meshk mobile application, the website meshk.ai, and related services (the "Service").

By using the Service, you consent to the data practices described in this Policy. If you do not agree, please do not use the Service.


1. Who We Are

The data controller for personal data collected through the Service depends on the payment provider used at checkout:

(a) Boros Studio LLC, 1111b South Governors Avenue, STE 7399, Dover, DE 19904, United States.

(b) Oha Tech LTD, Promachon Eleftherias 1, Floor 1, Flat/Office 18/19, Agios Athanasios, 4103, Limassol, Cyprus.

Privacy contact: info@meshk.ai

Riser (RİSER YAZILIM REKLAM TEKNOLOJİLERİ ARAŞTIRMA GELİŞTİRME VE PAZARLAMA TİCARET ANONİM ŞİRKETİ; İçerenköy Mah., Topçu İbrahim Sk., Quick Tower No: 8-10D, Ataşehir / İstanbul, Türkiye) — the developer and technical provider of the Service — acts as a data processor on behalf of the applicable data controller above (Boros Studio LLC or Oha Tech LTD), in its capacity as technical infrastructure and content provider.

Where you purchase through the Outpost checkout channel, Outpost Technologies Ltd. acts as merchant of record and an independent controller of the billing and payment data it processes for that transaction, under its own privacy policy (see Section 4.2).


2. Data We Collect

2.1. Registration Information

When you create an account, we collect:

  • Email address (if you sign in with email or social login)
  • Device identifier (UUID generated by your device)
  • Display name / nickname (if you set one)
  • Age confirmation (you must confirm you are 18+)
  • Preferred language

2.2. Profile and Preferences

You may optionally provide:

  • Gender
  • Preferred character attributes (ethnicity, eye color, hair, body type — used for character creation only)
  • Profile photo (if uploaded)

2.3. Chat Content

  • Messages you send to AI Companions
  • AI-generated responses
  • Images and videos generated through the Service
  • Audio played by voice features. Voice features use text-to-speech to generate synthetic audio from text; we do not record, collect, or store your own voice, and we do not create any voiceprint or biometric identifier.
  • Gifts sent to AI Companions

2.4. Payment Information

  • We do not store full credit or debit card numbers or card security codes (CVC).
  • Payment processing is performed by third-party payment providers and Merchants of Record: Apple, Google, and our web card-payment providers (which may include Stripe, Adyen, and Unlimit, orchestrated via Payrails). Where the checkout channel indicates that the sale is made through Outpost, the transaction is processed by Outpost as Merchant of Record.
  • Data our web payment providers process to complete your purchase includes: your name, email address, card brand, the last four digits and expiry of your card, BIN and BIN country, transaction amount and currency, IP address, a recurring-billing indicator, and authorization/refund response codes.
  • Where your purchase is made through Outpost, Outpost acts as an independent controller of the payment and transaction data it processes and may share information with us to enable delivery, access, and support of the Service, in accordance with the Outpost Merchant of Record Terms and Outpost's privacy policy: https://outpost.ai/privacy-policy/.
  • We store transaction metadata: subscription status, plan type, purchase date, billing period, and a payment-provider customer ID.

2.5. Device and Technical Data

  • IP address (used for geolocation, fraud prevention, and service rendering)
  • Mobile Advertising ID (if not disabled by you)
  • Device model, operating system, app version
  • Browser type and version (for web)
  • Screen resolution
  • Approximate location (country / city — based on IP)

2.6. Usage Data

  • App / web events (screen views, button clicks, feature usage)
  • Session duration
  • Daily message count
  • Subscription and purchase events
  • Crash logs and performance metrics

2.7. Server Logs

Our hosting provider automatically logs: browser type and version; operating system; referrer URL; host name; time of server request; IP address. Logs are kept for 2 weeks for security and error analysis (GDPR Art. 6(1)(f)).

2.8. Cookies and Tracking

We use cookies and similar technologies on the website. See Section 6 for details.

2.9. Personal Data of Children

The Service is strictly for users aged 18 and over. We do not knowingly collect personal data from minors. If we learn that a minor has registered, we will delete the account immediately. Parents or guardians who believe a minor has used the Service may contact info@meshk.ai. We enforce a zero-tolerance child-safety policy and report apparent child sexual abuse material to the appropriate authorities, including NCMEC.


3. How We Use Your Data

PurposeLegal basis (GDPR)
Providing and operating the ServiceContract (Art. 6(1)(b))
Processing payments and subscriptionsContract (Art. 6(1)(b))
Payment orchestration and routing across providersLegitimate interest (Art. 6(1)(f))
AI Companion conversations and personalizationContract (Art. 6(1)(b))
Improving the Service and AI models (aggregated, de-identified)Legitimate interest (Art. 6(1)(f))
Sending product updates and important noticesContract / Consent
Marketing communications and promotional offersConsent (Art. 6(1)(a))
Advertising and audience targetingConsent (Art. 6(1)(a))
Fraud prevention and securityLegitimate interest (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))

4. How We Share Your Data (Third Parties)

We work with the following categories of third-party service providers. Each provider has access only to the data necessary to perform its function and is contractually obligated to protect your data.

4.1. AI Model Providers

  • OpenAI Inc. (USA) — AI text generation (chat conversations). Data shared: the content of your messages and prompts, with conversation context. We contract on terms that restrict use of your content to serving your request and prohibit its use to train the provider's own foundation models.
  • OpenRouter / X.AI (Grok) (USA) — alternative AI text generation. Data shared: same scope and same no-training terms as OpenAI.
  • ElevenLabs Inc. (USA) — voice synthesis for voice features. Data shared: the text to be converted to speech. Your own voice is not sent, recorded, or stored.
  • fal.ai (USA) — AI image and video generation. Data shared: text prompts.
  • getimg.ai — character image generation. Data shared: text prompts.

A limited number of trained personnel may review de-identified interactions for safety, moderation, and quality purposes.

4.2. Payment Processors (Merchants of Record)

  • Apple Distribution International Ltd. (Ireland) — App Store subscription payments. Data shared: payment is handled entirely by Apple under Apple's own policies; we receive transaction and subscription status, not your card data.
  • Google Commerce Limited (Ireland) — Google Play subscription payments. Data shared: same as Apple.
  • Stripe Payments Europe Ltd. (Ireland) — website / funnel card payments. Data shared: name, email, card brand, last four digits and expiry of your card, BIN and BIN country, transaction amount, currency, IP address, recurring-billing indicator, and authorization/refund codes. We do not receive your full card number.
  • Adyen N.V. (Amsterdam, Netherlands) — website / funnel card payments. Data shared: same categories as Stripe.
  • Unlimit (Unlimint EU Ltd, Limassol, Cyprus, for EU/EEA users; Unlimit UK Ltd, London, United Kingdom, for other users) — website / funnel card payments. Data shared: same categories as Stripe.
  • Payrails GmbH (Berlin, Germany) — payment orchestration; routes each transaction to the appropriate payment provider above. Data shared: transaction routing metadata, tokenized payment identifiers, IP address, and device metadata.
  • We may also engage other web payment service providers from time to time for card processing on the website / funnel channel.
  • Outpost Technologies Ltd. (United Kingdom) — Merchant of Record and seller of record for the Outpost checkout channel. For purchases made through this channel, Outpost processes your order, billing, payment, tax, and transaction data as an independent controller under its own privacy policy: https://outpost.ai/privacy-policy/. Data shared: order, billing, and payment information necessary to complete and support your purchase.
  • RevenueCat Inc. (USA) — subscription state management across platforms. Data shared: app/device user identifier, subscription status, and purchase events.
  • Web2Wave — web paywall processing for gem purchases. Data shared: checkout/paywall interaction and purchase events, with transaction metadata.

4.3. Analytics and Attribution

  • Google Firebase Analytics (Google LLC, USA) — app and web behavior tracking. Data shared: pseudonymous app/web event data, device identifiers, and IP address.
  • AppsFlyer Ltd. (Israel) — mobile attribution and marketing analytics. Data shared: mobile device identifiers, IP address, app-installation events, and in-app purchase events, for advertising attribution purposes.
  • Sentry (Functional Software Inc., USA) — application error tracking. Data shared: crash and error diagnostics, device model/OS, app version, and technical request context.
  • Firebase Crashlytics (Google LLC, USA) — crash reporting. Data shared: crash reports, device model/OS, and app version.
  • Microsoft Clarity (Microsoft Corporation, USA) — session-replay and heatmap analytics on the website. Data shared: anonymized interaction and session-replay data.

4.4. Advertising and Marketing

  • Meta / Facebook (Meta Platforms Ireland Ltd.) — Facebook Pixel and Meta Ads for advertising, retargeting, and audience building. Data shared: hashed email, device ID, app events (install, purchase, signup), and aggregated audience signals.
  • Google Ads (Google LLC) — search and display advertising, conversion tracking. Data shared: Google Click ID, hashed email, conversion events.
  • TikTok Ads (TikTok Pte. Ltd.) — app install and conversion campaigns. Data shared: hashed email, install and purchase events.
  • Snapchat Ads (Snap Inc.) — app install and conversion campaigns. Data shared: device ID, install events.

4.5. Push Notifications and Engagement

  • Firebase Cloud Messaging (Google LLC) — push notification delivery (mobile). Data shared: your device push token.
  • Pushwoosh — push campaign management and engagement analytics. Data shared: device push token, device identifier, and engagement events.
  • Resend — transactional email delivery (magic link, receipts, account notifications). Data shared: your email address and email delivery/open status.

4.6. Infrastructure and Storage

  • Amazon Web Services (AWS) — cloud hosting and S3 media storage (chat images, character photos, voice-feature audio). Data shared: the Service content and account data stored to operate the Service. Data centers may be located in the EU (Frankfurt, eu-central-1) or the USA depending on the resource.
  • Google Cloud / Vercel — hosting and web deployment. Data shared: web application hosting data and request logs.

(Our databases and caches — e.g. PostgreSQL and Redis — are internal components operated within the infrastructure above, not separate third-party recipients of your data.)

4.7. Customer Support

  • Zendesk (Zendesk Inc., USA) — customer support ticketing. Data shared: the content of your support messages, your email/contact details, and your account reference.

4.8. Cookie Consent

  • Cookiebot — cookie consent management on the website.

4.9. Legal and Compliance

We may disclose personal data to law enforcement or other authorities when required by applicable law, subpoena, or court order.

4.10. Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to this Policy.

4.11. We Do NOT Sell Personal Data

We do not sell your personal data to third parties for monetary consideration. Our use of advertising and attribution partners (Section 4.4) constitutes "sharing" for cross-context behavioral advertising under the CPRA. You may opt out of this sharing via the "Do Not Sell or Share My Personal Information" control in our cookie consent banner, through your device advertising settings, or by sending a Global Privacy Control (GPC) signal, which we honor.

4.12. AI Model Improvement

We may use aggregated, de-identified, and/or anonymized user interactions to improve our AI models, the quality of our Service, and to develop new features. Where re-identification is not reasonably possible, such data no longer constitutes personal data under applicable data protection law.


5. International Data Transfers

5.1. Your personal data may be transferred to and processed in countries outside your country of residence, including the United States, the United Kingdom, Israel, and EU member states (e.g. Ireland, Cyprus, Germany, the Netherlands).

5.2. For transfers from the EU/UK to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent safeguards. Transfers to the United States may additionally rely on a provider's certification under the EU-US Data Privacy Framework where applicable. Israel benefits from an EU adequacy decision.


6. Cookies and Tracking Technologies

6.1. We use cookies on our website to: enable basic functionality (necessary cookies); remember preferences (preference cookies); analyze usage (statistical cookies — Firebase, Microsoft Clarity); and display relevant ads (marketing cookies — Facebook Pixel, Google Ads, TikTok Ads, Snapchat Ads).

6.2. You can manage cookies via the consent banner (Cookiebot) on first visit, or via your browser settings. A detailed, current list of the specific cookies we use, their purpose and duration, is available in the consent banner's preference center.

6.3. The mobile app uses Mobile Advertising ID (Apple IDFA / Google Advertising ID), which you can reset or limit in your device settings.


7. Your Rights

Under GDPR (EU), CCPA / CPRA (California), and other applicable laws, you have the right to:

RightWhat it means
AccessRequest a copy of personal data we hold about you.
RectificationCorrect inaccurate or incomplete data.
ErasureRequest deletion of your account and personal data.
RestrictionRestrict processing in certain circumstances.
PortabilityReceive your data in a structured, machine-readable format.
ObjectObject to processing for marketing or based on legitimate interest.
Withdraw consentWithdraw consent for processing based on consent.
ComplainLodge a complaint with your local data protection authority.

To exercise any right, contact info@meshk.ai. We will respond within 30 days (GDPR) or as required by local law.

7.1. Account Deletion

You can delete your account directly in the app: Settings → Delete Account. Account deletion will:

  • Mark your account as deleted and anonymize personal identifiers.
  • Permanently remove account data within a reasonable period (typically within 90 days of the deletion request), except where retention is required by applicable law (for example, financial transaction records for tax purposes, fraud prevention, or legal claims), and except for aggregated/de-identified data used to improve our Service, which is retained in non-identifying form.

Note: Mobile subscriptions purchased via App Store / Google Play must be cancelled separately in your store account settings. Website subscriptions billed via our web payment providers will be cancelled together with account deletion.

7.2. Marketing Opt-Out

Unsubscribe from marketing emails via the link at the bottom of each email, or in your account settings.

7.3. Advertising Opt-Out

Disable Mobile Advertising ID in your device settings, or use the cookie consent banner on the website.


8. Data Retention

8.1. We retain personal data only as long as necessary for the purposes described in this Policy or as required by law.

8.2. General retention periods:

  • Active account data: retained while your account is active.
  • Deleted account data: anonymized following the deletion request, fully removed within a reasonable period (typically within 90 days), except data required for legal retention (for example, billing records for tax purposes — typically 5–10 years depending on jurisdiction).
  • Chat messages and generated media: retained while your account is active, removed in line with account deletion.
  • Aggregated/de-identified data used to improve our Service and models: retained in non-identifying form and not deleted with your account.
  • Server logs: 2 weeks.
  • Crash and error logs: 90 days.
  • Marketing consent records: retained for the duration of consent + 3 years for proof.

9. Security

9.1. We use industry-standard technical and organizational measures to protect your personal data: SSL / TLS encryption for data in transit; encryption at rest for sensitive data; access controls and authentication; regular security audits; incident response procedures.

9.2. Despite our measures, no internet transmission is 100% secure. You use the Service at your own risk.

9.3. If we become aware of a personal data breach affecting your rights, we will notify the relevant data protection authority and (where required) you, within 72 hours of becoming aware.


10. California Privacy Rights (CCPA / CPRA)

10.1. If you are a California resident, you have additional rights under CCPA / CPRA, including: the right to know what categories of personal information we collect; to delete personal information; to correct inaccurate personal information; to opt out of "sale" or "sharing" of personal information; to limit the use of sensitive personal information; and to non-discrimination for exercising privacy rights.

10.2. To exercise these rights, contact info@meshk.ai or use the "Do Not Sell or Share My Personal Information" link in our cookie consent banner. We honor Global Privacy Control (GPC) signals.


11. Changes to This Policy

We may update this Policy at any time. Material changes will be communicated via in-app notification, email, or website banner. Your continued use of the Service after a change constitutes acceptance.


12. Contact

For privacy questions or data subject requests, you can contact:

Merchant of Record (Company / Seller): Boros Studio LLC, 1111b South Governors Avenue, STE 7399, Dover, DE 19904, United States — info@meshk.ai

Merchant of Record (Company / Seller): Oha Tech LTD, Promachon Eleftherias 1, Floor 1, Flat/Office 18/19, Agios Athanasios, 4103, Limassol, Cyprus — info@meshk.ai

Developer / Technical Provider: RİSER YAZILIM REKLAM TEKNOLOJİLERİ ARAŞTIRMA GELİŞTİRME VE PAZARLAMA TİCARET ANONİM ŞİRKETİ, İçerenköy Mah., Topçu İbrahim Sk., Quick Tower No: 8-10D, Ataşehir / İstanbul, Türkiye — info@meshk.ai

Support: https://support.meshk.ai/