Legal
Data Safety Policy
This Data Safety Policy summarizes how the Polymesh apps
(io.polymesh.app on Google Play and the Apple App Store) and the
related web Service handle user data. It is written to align with Google Play’s
Data safety form and Apple’s App Privacy / privacy nutrition-label expectations.
The full narrative disclosure is in our
Privacy Policy.
- Overview
- Data collection summary
- Purposes
- Sharing
- Security practices
- Deletion
- Google Play Data safety mapping
- Apple App Privacy mapping
- Contact
1. Overview
- App name: Polymesh |
Package / Bundle ID:
io.polymesh.app - Data is collected to provide private household coordination features — not for advertising.
- We do not sell user data.
- We do not use advertising or analytics SDKs that track users across apps.
- Sensitive mesh content is encrypted in transit and with application-layer envelope encryption at rest (server-managed keys — not zero-knowledge).
- Users can request deletion of their account and associated personal data.
2. Data collection summary
“Collected” means transmitted off the device to Polymesh servers (or to a processor acting on our behalf), unless noted as on-device only.
| Category | Examples | Required? | Shared with other companies? |
|---|---|---|---|
| Personal info | Email, display name, optional pronouns/bio | Email & name required for account | No (processors only) |
| Photos and files | Avatar; expense receipt images | Optional | No (processors only) |
| App activity / content | Calendars, expenses, chat, relationships, agreements | As you use features | Only to mesh members you share with; processors for hosting |
| Location | Approximate/precise location, places, geofence events | Optional; off by default | Shared only with mesh members you grant; Worker-side geocode via LocationIQ |
| Identifiers | User ID, session/refresh tokens, push tokens | Needed to operate account & optional push | Push tokens with FCM/APNs |
| Diagnostics (limited) | Security/rate-limit signals; hashed IP on waitlist | Service protection | Cloudflare as processor |
| Calendar credentials (optional) | Google OAuth refresh; Apple CalDAV credentials | Only if you enable sync | Google/Apple as the connected provider |
3. Purposes of collection
- App functionality — authentication, mesh membership, calendars, expenses, chat, relationships, agreements, optional location
- Account management — profile, sessions, invites, password / passkey / email OTP
- Communications — transactional email and optional push / digest notifications
- Fraud prevention, security, and compliance — Turnstile, rate limits, session integrity
- Developer communications — waitlist / early-access contact (marketing site)
We do not collect data for advertising or personalized ads.
4. Data sharing
“Data sharing” for store forms generally means transfer to a third party for an independent purpose (for example advertising). Polymesh:
- Does not share data for advertising
- Does not sell data
- Uses service providers / processors to host and deliver the product (Cloudflare; Firebase/FCM and APNs for push; Google/Apple only when you connect calendar sync; LocationIQ for server-side reverse geocoding)
- Makes content visible to other members of your private mesh according to the access controls you and your moderators configure
When you enable Google or Apple calendar sync, event fields you choose to export are disclosed to that provider under their terms. That outbound sync is user-initiated and optional.
5. Security practices
- Data encrypted in transit (TLS)
- Sensitive mesh fields protected with per-mesh envelope encryption (AES-GCM) at rest; object storage for receipts holds ciphertext
- Invite-only tenancy with hard mesh isolation controls
- HttpOnly session cookies and rotating refresh tokens
- Passkeys preferred; email OTP secondary; passwords as last resort
- Map tiles served from our infrastructure; geocoding performed server-side
Encryption keys are server-managed. See the Privacy Policy security section for the residual-risk disclosure.
6. Data deletion
Users can:
- Edit or remove much of their profile and content in-product
- Stop optional collection (location grants, push, calendar sync)
- Leave a mesh (triggers offboarding cleanup for location and membership-scoped data)
- Request full account deletion by emailing privacy@polymesh.io
After a verified deletion request, we delete or irreversibly anonymize personal data that is no longer needed, except where retention is required for security, dispute resolution, or legal obligations. Shared mesh content may remain for remaining members when it is part of the household record.
7. Google Play Data safety form mapping
Use this section when completing the Play Console Data safety questionnaire. Adjust only if product behavior changes.
| Play topic | Polymesh response guidance |
|---|---|
| Does your app collect or share user data? | Yes — collects data required for core functionality and optional features |
| Is all user data encrypted in transit? | Yes |
| Do you provide a way for users to request deletion? | Yes — in-product controls plus privacy@polymesh.io |
| Data sold? | No |
| Data used for advertising? | No |
| Location | Collected optionally for app functionality; approximate and/or precise when sharing is enabled; not for ads |
| Photos / files | Optional avatars and receipt images for app functionality |
| Messages / app activity | Chat and in-app content for app functionality within an invite-only mesh |
| Personal info / account identifiers | Email, name, user IDs, auth material for account management |
| Device or other IDs | Push tokens and session identifiers for functionality / security |
| Background location declaration | Only if/when the shipped build uses background location sharing; must match actual OS permission usage and in-app disclosure |
Privacy policy URL for store listing: https://www.polymesh.io/privacy
Data safety details URL (optional supplemental link): https://www.polymesh.io/data-safety
8. Apple App Privacy mapping
Suggested App Store Connect privacy nutrition labels (confirm against the shipped binary):
| Data type | Linked to user? | Used for tracking? | Purpose |
|---|---|---|---|
| Contact Info (Email Address, Name) | Yes | No | App Functionality |
| Location (Precise / Coarse) | Yes | No | App Functionality (optional) |
| Photos or Videos | Yes | No | App Functionality (optional avatar / receipts) |
| Other User Content (messages, calendars, finances, etc.) | Yes | No | App Functionality |
| Identifiers (User ID) | Yes | No | App Functionality |
| Product Interaction / diagnostics (limited security signals) | Yes / may vary | No | App Functionality / Fraud Prevention |
Polymesh does not use data for tracking across other companies’ apps and websites as defined by Apple. App Tracking Transparency is not required for our current product behavior because we do not track for advertising.
9. Contact
Data safety and deletion requests: privacy@polymesh.io
Related policies: Privacy Policy · Terms of Use