Privacy Policy

Last updated: July 24, 2026

1. Introduction

Mesh ("we," "us," or "our") provides an AI-powered paraplanning platform for financial advisors. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our website and services (collectively, the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, organization name, and role. Authentication is handled through our identity provider (Supabase).

Meeting Recordings & Transcripts

When you use our meeting assistant or upload recordings, we process audio and video data to generate transcripts. These recordings and transcripts are stored securely and associated with your organization.

CRM & Contact Data

If you connect a CRM integration (e.g., Wealthbox, Redtail), we import contact records and sync meeting notes and action items back to your CRM. We only access the data you authorize.

Calendar Data

If you connect a calendar (Google Calendar, Microsoft Outlook, or Redtail), we access your calendar events to schedule and prepare for meetings. We do not modify or delete your calendar events. For full details on how we handle data from each provider, see our Google API Services Privacy Policy and our Microsoft API Services Privacy Policy.

Email Data

If you connect an email account (Microsoft Outlook or Gmail), Mesh uses a send-only permission. Mesh does not read your inbox or your sent mail, and it does not triage, classify, or scan your incoming or outgoing messages. Mesh drafts email only from your own Mesh workspace data, such as your meeting notes and client records, and you review and approve every message before it is sent.

Sending: when you approve a send, Mesh transmits the message through your own email account, and the message appears in your Sent folder. Every send requires your explicit approval; Mesh never sends without you, and no automated process or workflow sends on your behalf. We store the approved message content (encrypted) and delivery metadata as part of your records. For per-provider details on the permissions we request, see our Google API Services Privacy Policy and our Microsoft API Services Privacy Policy.

Usage Data

We automatically collect information about how you interact with the Service, including pages visited, features used, browser type, IP address, and device information.

3. How We Use Your Information

  • Meeting Processing: Transcribing recordings, generating AI-powered summaries, extracting action items, and identifying compliance findings.
  • AI Analysis: Using large language models to summarize meetings, prepare meeting briefs, draft follow-up emails, and enrich client profiles.
  • CRM Synchronization: Syncing meeting notes, action items, and contact data with your connected CRM.
  • Compliance Support: Flagging potential compliance issues from meeting transcripts to assist your review process.
  • Service Improvement: Analyzing usage patterns to improve the Service, fix bugs, and develop new features.
  • Communication: Sending service-related notifications, updates, and support responses.

4. Data Storage & Security

Your data is stored in secure, encrypted PostgreSQL databases hosted by our infrastructure providers. We implement industry-standard security measures including:

  • Encryption in transit (TLS) and at rest
  • Row-level security and application-level access controls ensuring strict tenant isolation between organizations
  • JWT-based authentication for all API requests
  • Regular security audits and access reviews
  • Audit logging of data access and modifications
  • Automated PII redaction (SSN, credit cards, account numbers) from transcripts before AI processing

We retain your data for as long as your account is active or as needed to provide the Service. You may request deletion of your data at any time (see "Your Rights" below).

4b. Data Retention

We retain your data for as long as your organization account is active. Meeting transcripts, summaries, and associated records are retained in accordance with financial services regulatory requirements (including SEC Rule 17a-4), typically for a minimum of seven years. Audit logs are retained indefinitely for compliance purposes.

Records of email messages you approve and send through a connected account (the encrypted message content plus delivery metadata) are treated as business records and retained in the same regulatory bucket, consistent with SEC Rule 17a-4 and Investment Advisers Act Rule 204-2. Sending from your own mailbox also files the message in your provider’s Sent folder and your firm’s own email supervision and archiving channel.

Delete All Data: You may choose to delete all operational data (meetings, transcripts, action items, clients, contacts, compliance findings, and connections) while preserving your account, organization, and subscription. Anonymized audit logs are retained.

Delete Account & All Data: Upon full account deletion, all organization data is permanently and irreversibly removed from our systems, including meetings, transcripts, client profiles, contacts, CRM connections, your user account, organization, and subscription. Anonymized audit logs (stripped of all personal identifiers) are retained for regulatory compliance as required by law.

In both cases, audit logs are anonymized by removing all personal identifiers (user IDs, IP addresses, and metadata) and retained indefinitely to satisfy financial services regulatory requirements. This retention is not optional and applies regardless of which deletion method you choose.

5. Data Sharing & Third Parties

We do not sell your personal information. We share data with third parties only in the following circumstances:

  • Meeting Recording Services: We use Recall.ai to join and record meetings on your behalf. Meeting audio is processed through their infrastructure.
  • AI/LLM Providers: PII-redacted meeting transcripts are sent to large language model providers (e.g., Anthropic) for processing. Sensitive information such as Social Security numbers, credit card numbers, and account numbers are automatically removed before any data leaves our systems. Data is sent only as needed and is not used by these providers to train their models.
  • CRM Integrations: When you connect a CRM, we exchange data with that provider as authorized by you.
  • Infrastructure Providers: We use cloud hosting and database services to operate the platform. These providers process data on our behalf under strict contractual obligations.
  • Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request.

5b. Subprocessors

We use the following categories of subprocessors to operate the Service:

  • Cloud Infrastructure: Amazon Web Services (AWS) (cloud hosting, KMS encryption key management, object storage)
  • Authentication & Database: Supabase (authentication, database hosting)
  • Payment Processing: Stripe (subscription billing - no card data stored in our systems)
  • AI/LLM Providers: Anthropic, Groq, AWS Bedrock (meeting summarization, profile extraction, compliance review - all receive PII-redacted data only; data is not used to train models)
  • Embedding Providers: OpenAI, Together AI (text embedding generation for knowledge retrieval - receives PII-redacted data only)
  • Speech-to-Text: Deepgram, AssemblyAI (audio transcription)
  • Meeting Recording: Recall.ai (meeting bot infrastructure)

Connected services under your direction

When you connect your own email account, calendar, or CRM, Mesh transmits data to that provider account at your direction. These are your service providers, not Mesh's subprocessors: Mesh is acting on your instruction to move your data into or out of an account you control. Providers you may connect include:

  • Google LLC (Gmail API for sending email you approve; Google Calendar for meeting scheduling) - see our Google API Services Privacy Policy
  • Microsoft Corporation (Microsoft Graph for Outlook calendar and sending email you approve) - see our Microsoft API Services Privacy Policy
  • Your CRM provider (e.g., Redtail, Wealthbox) when you connect it, as described above.

6. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion:Request deletion of your personal data, subject to legal retention requirements. You may delete all operational data while keeping your account, or delete your entire account. In both cases, anonymized audit logs are retained for regulatory compliance (see "Data Retention" above).
  • Data Export: Request your data in a portable, machine-readable format.
  • Opt-Out: Opt out of non-essential communications at any time.
  • Restrict Processing: Request that we limit how we process your data in certain circumstances.

To exercise any of these rights, please contact us at privacy@meshfp.com. We will respond within 30 days.

7. Cookies & Tracking

We use essential cookies to maintain your session and authentication state. We do not currently use third-party analytics tracking tools. You can control cookie preferences through your browser settings.

8. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us: