Skip to content
MeshTale

Legal

Privacy Policy

This policy explains how MeshTale handles information connected with the Service.

Last updated: 2 June 2026

This Privacy Policy explains how Codas Labs, LLC (“Codas Labs,” “we,” “us,” or “our”) collects, uses, and protects information in connection with MeshTale (the “Service”), available at meshtale.com and app.meshtale.com. By using the Service, you agree to this Policy.

Who we are

MeshTale is a product of Codas Labs, LLC. MeshTale is a memory and knowledge layer that lets you import, search, recall, and govern your own content — including AI chat history and content you connect from third‑party services — across the AI tools you use.

Who is responsible for your data

Codas Labs, LLC, a North Carolina limited liability company, is the controller of personal information we collect about you directly — your account details, your billing information, and how you use the Service. Contact: legal@codaslabs.com.

Where you connect a source or upload content, we act as a processor for the personal information inside that content, and you are the controller of it. Our obligations in that role are set out in the data processing addendum.

We have not yet appointed representatives in the United Kingdom or European Union under Article 27 of the UK and EU GDPR. Where one is required, it will be appointed and named here.

Why we are allowed to use your information

Where the UK or EU GDPR applies, we must have a lawful basis for each thing we do with personal information. Ours are:

What we doWhy we are allowed to
Create and run your account, and provide the ServicePerformance of a contract — we cannot provide the Service without it
Process content you upload or connectPerformance of a contract, and, for personal information inside that content, on your instructions as processor
Take payment and keep financial recordsPerformance of a contract and legal obligation
Keep the Service secure, prevent abuse, and investigate incidentsLegitimate interests — see below
Understand how the Service is used so we can improve itLegitimate interests, or consent where analytics cookies are involved
Send you product and marketing emailConsent, or legitimate interests where the law permits. You can unsubscribe at any time
Respond to legal requests and defend legal claimsLegal obligation and legitimate interests

Our legitimate interests

Where we rely on legitimate interests, those interests are: running a secure and reliable service, preventing fraud and abuse, understanding which parts of the product work, and protecting our legal position. We have considered your rights in each case and do not believe these uses override them. You may object to processing based on legitimate interests — see your rights below.

Automated decision-making

We do not make decisions about you that produce legal or similarly significant effects using automated processing alone, and we do not carry out profiling for that purpose.

The Service does use automated processing on your content — search ranking, chunking, and generating summaries and answers with AI models. That processing produces results for you rather than decisions about you.

Information we collect

  • Account information. When you create an account, we collect your name, email address, and authentication details. If you sign in with Google, we receive basic profile information (name, email address, and a Google account identifier) to create and secure your account.
  • Content you provide or import.Content you upload, paste, or create in MeshTale, and content you choose to import from connected third‑party services (your “Content”).
  • Connected‑service data. When you connect a third‑party service, we access the content you authorize us to bring into your workspace. Supported connectors include Google Drive, Gmail, Notion, Slack, Dropbox, GitHub, and Confluence. You control which services you connect and can disconnect them at any time.
  • Usage and technical data. Logs, device and browser information, IP address, and similar technical data we use to operate, secure, and improve the Service.

Google user data

If you connect a Google service, MeshTale requests read‑only access to only the data needed to provide the feature you enable:

  • Google Drivedrive.readonly(read‑only): to import the Drive content you choose — either specific folders you select, or all of your Google Drive if you explicitly choose “All of My Drive.” Only files you own are imported.
  • Google Sheetsspreadsheets.readonly (read‑only): to import Google Sheets you choose into your MeshTale workspace.
  • Gmailgmail.readonly (read‑only): to import email messages you choose into your MeshTale workspace.

We use Google user data solely to provide the user‑facing features you activate — importing the content you select so you can search, recall, and govern it within MeshTale. We do not use it for any other purpose.

If you choose to keep a connected Google account up to date — a per‑account setting you control — MeshTale periodically re‑reads that account in the background so your imported content stays current. This recurring access is read‑onlyand limited to the scope you already chose: the specific labels and folders you selected, or all of your Google Drive if you chose “All of My Drive.” It imports only new or changed items within that scope and never reads beyond it. This changes only how often your already‑approved data is read. Nothing is shared into a team workspace automatically. That still happens only when you explicitly select it. You can turn this setting off at any time to stop further background access, and disconnecting the account revokes access entirely.

MeshTale’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, for data obtained through Google APIs:

  • We do not use it for serving advertising, including personalized or retargeted advertising.
  • We do not sell it.
  • We do not use it, or allow it to be used, to train generalized or foundation artificial‑intelligence models.
  • We do not allow humans to read it, except: (a) with your affirmative consent for specific items; (b) where necessary for security purposes (such as investigating abuse) or to comply with applicable law; (c) where the data has been aggregated and anonymized for internal operations; or (d) as needed to provide user‑initiated support.

You can revoke MeshTale’s access to your Google data at any time by disconnecting the connector in MeshTale or via your Google Account permissions page at https://myaccount.google.com/permissions.

How we use information

We use information to: provide and operate the Service (including search, recall, and memory features across your AI tools); authenticate and secure accounts; provide customer support; maintain, troubleshoot, and improve the Service (without training generalized AI models on your private Content); and comply with legal obligations.

AI processing and service providers (sub‑processors)

To operate the Service we rely on a limited set of third‑party providers acting on our behalf, including: cloud hosting and compute, managed databases, vector‑search infrastructure, caching, object storage, error and performance monitoring, and AI model providers used to generate embeddings and power retrieval. These providers process data only to provide services to us and under contractual terms that prohibit using your Content to train their own generalized models. We maintain a current list of sub‑processors and will provide it on request.

What we do not do

  • We do not sell your personal information or your Content.
  • We do not serve advertising in the Service or use your Content for advertising.
  • We do not use your private Content to train generalized or foundation AI models.

Advertising on our website

Read the section above carefully, because the distinction matters: those promises are about the Service — the product you sign into and the content you put in it. Nothing you upload or connect is ever used for advertising, ever shown to an advertising provider, or ever used to target you. That does not change.

Our public website is a different thing. Like most companies, we advertise our own product, and we use Meta, Google and LinkedIn to show those ads to people who have visited meshtale.com and to measure whether the ads worked. To do that, those providers may receive an identifier for your browser and the fact that you visited a page.

If you are in the UK, the European Economic Area, or Switzerland, none of this happens unless you agree first. Everywhere else it is on by default and you can turn it off at any time from the cookie link in our footer, or by sending a Global Privacy Control signal from your browser. Full detail, including the individual cookies and how long they last, is in our cookie policy.

We do not use these providers to advertise anyone else’s products to you, and we do not sell your information to them.

Security

We protect information using encryption in transit and at rest, access controls and least‑privilege practices, and monitoring. At import, MeshTale applies an automated safety baseline that blocks recognized secrets and credentials and detects common categories of sensitive personal information. This baseline is a best‑effort safety control, not a guarantee. Pattern‑based scanning cannot detect every secret or sensitive value, and you remain responsible for sanitizing content before importing it. No method of transmission or storage is completely secure.

Data retention and deletion

We retain your account information and Content for as long as your account is active or as needed to provide the Service. You may request deletion of your Content or account at any time, and disconnecting a connector stops further access to that service. We may retain limited audit and security metadata (which does not include the substance of your Content) for up to seven years to meet security and compliance obligations, and we may retain information as required by law.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. You can exercise these rights — and withdraw connector consent at any time — by using in‑product controls or by contacting us at legal@codaslabs.com. We honor applicable rights under laws such as the GDPR and CCPA/CPRA.

How to make a request, and what happens next

Email legal@codaslabs.comwith the words “privacy request” and tell us what you want. We may need to verify who you are before we act, and we will only ask for what is necessary to do that.

We aim to respond within 30 days, which is the deadline under the UK and EU GDPR, and within 45 days where a US state law sets that period. If a request is complex we may extend, and we will tell you why before the original deadline passes. There is no charge unless a request is manifestly unfounded or excessive.

Where we act as processor for content you connected, we will refer the request to you as the controller rather than answer it directly, and assist you in responding.

Withdrawing consent

Where we rely on your consent, you can withdraw it at any time. That does not affect anything we did lawfully before you withdrew it.

If you are unhappy with how we handled it

Tell us first and we will try to put it right. You also have the right to complain to a data protection regulator. In the UK that is the Information Commissioner’s Office (ico.org.uk). In the EEA it is the supervisory authority in the country where you live, work, or where you believe the problem occurred. You do not have to come to us first.

US state privacy rights

If you live in a US state with a consumer privacy law, you may have rights to know what we collect, to delete it, to correct it, to obtain a portable copy, and to opt out of sale, sharing, or targeted advertising. You may also appeal a refusal — email us with “privacy appeal” and we will respond with our reasoning.

We do not sell personal information. We do not process sensitive personal information for the purpose of inferring characteristics about you.

Where you have agreed to advertising cookies on our website, our advertising providers may receive an identifier for your browser so we can show you our own ads elsewhere. Under some US state laws that counts as “sharing” for cross-context behavioral advertising, so we disclose it plainly rather than argue about the definition. You can opt out at any time using the cookie link in our footer, or by sending a Global Privacy Control signal. This applies to our website only — never to content inside the product.

We honour the Global Privacy Control signal where your browser sends one, and treat it as an opt-out from both analytics and advertising cookies for that browser. No further action is needed from you.

You may authorize an agent to make a request for you. We may ask for proof of that authorization and may still ask you to verify your own identity.

International data transfers

We operate in the United States, and information may be processed there and in the countries where our providers operate. If you are in the UK or EEA, that means your personal information leaves your country.

For transfers from the EEA we rely on the European Commission’s Standard Contractual Clauses, and for transfers from the UK on the UK International Data Transfer Addendum to those clauses. The specific modules and options we use are set out in our data processing addendum. For Switzerland, the same clauses apply as adapted under Swiss law.

We are not currently certified under the EU–US Data Privacy Framework and do not rely on it.

You can ask us for a copy of the safeguards we rely on by emailing legal@codaslabs.com.

Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the “Effective date” above; material changes will be communicated as required by law.

Contact us

Questions or requests regarding this Policy or your data: legal@codaslabs.com (Codas Labs, LLC).