Legal
Privacy Policy
This Privacy Policy explains how Polymesh (“Polymesh,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use our websites, web application, and native iOS/Android apps (together, the “Service”). It is intended to meet Apple App Store and Google Play disclosure expectations, including clear descriptions of data collection, use, sharing, retention, and deletion.
- Who we are
- Scope
- Data we collect
- How we use data
- How we share data
- Mobile permissions
- Security and encryption
- Retention
- Your choices and rights
- Children
- International transfers
- Changes
- Contact
1. Who we are
Polymesh is a private, invite-only coordination product for partners,
co-parents, housemates, and chosen family. The Service is available at
www.polymesh.io (marketing),
app.polymesh.io (application),
and as the native app package io.polymesh.app.
2. Scope
This Policy covers:
- The Polymesh marketing site and waitlist
- The Polymesh web application and Progressive Web App (PWA)
- The Polymesh iOS and Android apps
- Related APIs, push notifications, and optional integrations you enable
For a store-oriented summary of data categories, collection purposes, sharing, and security practices, see our Data Safety Policy. Use of the Service is also governed by our Terms of Use.
3. Data we collect
We collect information you provide, information generated by your use of the Service, and information from third parties when you connect optional integrations. Categories include:
Account and profile
- Email address, display name, and authentication credentials
- Optional profile details such as pronouns, bio, and avatar image
- Authentication material: passkey/WebAuthn public keys, password hashes (if you choose a password), and short-lived email one-time codes / magic links
Mesh content you create
- Calendars, events, RSVPs, and related notes
- Expenses, settlements, and receipt images
- Chat messages and room membership
- Relationship graph data, negotiation requests, and private interest flags
- Agreements / boundary documents and acknowledgments
Location (optional, off by default)
- Live or last-known coordinates, place labels, and geofence enter/leave events when you enable sharing with specific people in your mesh
- Saved places you create and any place-share grants you configure
Location sharing requires explicit grants. Mesh members do not see your location unless you choose to share. OS-level “Always” / background location is requested only when you use background sharing features on a supported native app.
Notifications and device data
- Web Push subscription endpoints (VAPID) and native push tokens via Firebase Cloud Messaging (FCM), which may relay through Apple Push Notification service (APNs) on iOS
- Notification preference settings (in-app and email digests)
- Limited device/session metadata needed for security (for example session identifiers and refresh-token families)
Optional calendar sync
- Google Calendar: OAuth refresh tokens and selected calendar event fields you choose to sync
- Apple Calendar (CalDAV): credentials you supply (such as an app-specific password) and selected event fields
Sync is opt-in per calendar. Default export mode is busy/free; exporting title and time requires an additional confirmation. Notes, RSVP details, location fields, and relationship context are not mapped outbound.
Waitlist and marketing site
- Email address, optional name, and optional note
- Hashed IP address for abuse prevention and rate limiting
- Bot-protection signals via Cloudflare Turnstile on waitlist and auth forms
We do not sell personal information
We do not sell your personal information. We do not use third-party advertising SDKs or sell data to data brokers. We do not use your mesh content to train third-party AI models.
4. How we use data
We use information to:
- Provide, maintain, and secure the Service for your mesh
- Authenticate you and protect accounts against abuse
- Deliver features you use (calendars, expenses, chat, relationships, location, agreements)
- Send transactional email (invites, OTP / magic links, digests you enable)
- Send push notifications you enable
- Operate optional integrations you connect (calendar sync, reverse geocoding)
- Diagnose reliability issues and prevent fraud or misuse
- Comply with law and enforce our Terms of Use
5. How we share data
We share data only as needed to operate the Service:
- Other members of your mesh — content and presence you create or share according to product access controls (invite-only tenancy, calendar/room ACLs, location grants, and similar).
- Infrastructure processors — Cloudflare (Workers, D1, R2, KV, Email Sending, Turnstile, Durable Objects) to host and operate the Service.
- Push providers — Firebase Cloud Messaging and, on iOS, Apple Push Notification service, to deliver notification payloads.
- Optional calendar providers — Google or Apple, only when you connect sync and only for the fields/modes you enable.
- Geocoding — LocationIQ is called from our servers (not from the browser) to reverse-geocode coordinates into place labels; map tiles are served from our own infrastructure so pan/zoom does not leak viewport data to a third-party map vendor.
- Legal / safety — if required by law, or to protect the rights, safety, and integrity of users or the Service.
6. Mobile app permissions
Depending on platform and features you enable, the native apps may request:
- Internet — required to use the Service
- Notifications — optional push alerts
- Location (When In Use) — optional foreground location sharing
- Location (Always) / background location — optional background location sharing when that feature is enabled and you grant OS permission
You can revoke OS permissions in system settings. Revoking location or notifications disables the related Polymesh features but does not by itself delete historical content already stored in your mesh.
7. Security and encryption
We use industry-standard transport security (HTTPS/TLS) and application-layer envelope encryption for sensitive mesh fields (AES-GCM with per-mesh keys). Receipt objects in object storage are stored as ciphertext with access controls on download.
Important limitation: encryption keys are server-managed. This is not a zero-knowledge architecture. Operators with access to Worker secrets could decrypt envelope-encrypted content. We design for strong tenant isolation and least-privilege operations, but you should understand this residual risk before storing highly sensitive material.
Sessions use HttpOnly cookies (including __Host- access cookies)
and rotating refresh tokens. You can sign out of all devices from your profile.
8. Retention
- Account and mesh content generally persist while your membership and the mesh remain active.
- Leaving or being removed from a mesh clears location grants/snapshots and related membership-scoped data according to our offboarding process; shared content created for the mesh may remain visible to remaining members.
- Short-lived auth codes expire quickly and are stored in hashed form.
- Calendar sync tokens and imported external events are deleted when you disconnect sync.
- Waitlist records are retained until we process early access or you ask us to remove them.
- Backups, logs, and security records may persist for a limited period for reliability and abuse prevention.
9. Your choices and rights
Depending on your location and applicable law, you may have rights to:
- Access the personal information we hold about you
- Correct inaccurate profile information in the app
- Delete or request deletion of your account and associated personal data
- Export or receive a copy of certain data where feasible
- Withdraw consent for optional features (location, push, calendar sync)
- Object to or restrict certain processing, where applicable
In the product you can update profile details, notification preferences, leave a mesh, disconnect calendar sync, stop location sharing, and sign out of all devices. To request account deletion or a broader data request, email privacy@polymesh.io. We will verify the request and respond within a reasonable period (and within timelines required by applicable law).
10. Children
The Service is not directed to children under 13 (or the minimum digital consent age in your jurisdiction). We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact privacy@polymesh.io and we will take appropriate steps to delete it.
11. International transfers
We host the Service on Cloudflare’s global network. Your information may be processed in the United States and other countries where Cloudflare or our subprocessors operate. Where required, we rely on appropriate transfer mechanisms and contractual protections.
12. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the effective date. Material changes may also be communicated in-product or by email when appropriate. Continued use of the Service after an update means you acknowledge the revised Policy.
13. Contact
Privacy and data requests: privacy@polymesh.io
General product contact for account holders: app@polymesh.io
Website: https://www.polymesh.io