Privacy Policy

Last updated: September 25, 2026

Who we are

MESH-API (mesh-api.dev) is operated by BOT-HOLDINGS, LLC, doing business as codedatda.casa (“BOT-HOLDINGS”, “we”, “us”), based in Las Vegas, Nevada, United States. We are the data controller for the personal data described here. Questions and requests go to dev@codedatda.casa.

MESH-API itself is open-source software (GPL-3.0) that you install and run on your own hardware; it connects to the radios, AI providers, messaging services and map-tile sources you set up or leave at their defaults, and those connections are between you and those services. Two exceptions: its update checker asks GitHub for new releases, and its dashboard loads its logo image from mr-tbot.com, a server we run, so that server’s logs see the IP address and browser of whoever opens the dashboard. This policy covers the mesh-api.dev website and the contact form, support chat and donation links on it.

What we collect, and why

  • Server and security logs. Like every website, when you visit we and the services in front of us receive your IP address, browser type, the pages you request, timestamps and referring page. Our host keeps standard access logs and our content delivery network (Cloudflare) filters traffic for attacks. We use this to run the site, keep it secure and investigate abuse.
  • Contact form. When you use it we collect what you type: name, email address, topic, message, the IP address you sent it from (recorded automatically). We use it to answer your question, bug report or partnership request. The submission is emailed to our team mailbox and kept in the site’s database. We keep it for 24 months from when you send it (the IP address for 30 days), unless you ask us to delete it sooner.
  • Support chat. The chat button on this site opens a support assistant that is an AI: its answers are generated by an AI model run by OpenAI, using this site’s own pages and help articles. To start a chat you give your name and your email address. Before your first message a Cloudflare Turnstile check runs to keep out bots; it sends browser signals and your IP address to Cloudflare. Each message you send, the details you entered, and the title and address of the page you are on are sent to OpenAI to produce the reply. A member of our team can read the conversation and may join it. Once a team member has joined, you may be able to send each other photos, videos, audio and documents (for example screenshots or PDFs), up to 20 MB each. Files go only to our team, never to the AI (the AI sees only the file’s name). They are stored on our server with the conversation and can be opened by anyone who has the file’s private link. Photos keep the details your camera embedded in them, such as location and time, so remove those before sending if you prefer. We email our team when a chat starts (your details, the page and your first question), when it needs a person, and a full transcript when it ends, and we email a copy of the conversation to the address you gave. On the site we keep the conversation, the details you entered, the pages you chatted from, a random chat ID, a shortened IP address (for IPv4 the last number is removed; for IPv6 only the network prefix is kept) and any thumbs-up or thumbs-down rating you give (with any comment you add to it); your browser keeps the open chat in session storage until you close the tab. Once a week, conversations our team handled are sent to OpenAI with email addresses, phone numbers and order or ZIP numbers masked, so it can suggest answers for the assistant’s knowledge base; a person reviews every suggestion before the assistant uses it. Conversations, files and the details you entered are deleted from the site 90 days after the chat started; records of which team member handled a chat, and our team’s own internal chat about it, are kept for up to 12 months; emailed copies stay in the mailboxes they were sent to. Our team’s phones are alerted through Google Firebase Cloud Messaging (and Apple’s push service on iPhone); the alert contains only a chat reference, not what you wrote. Please do not send payment card numbers, passwords, government ID or health information in the chat.
  • Donations. The Donate button takes you to PayPal, which processes your donation, one-time or recurring, under its own terms and privacy policy and shares with us the details its donation service normally provides, such as your name, email address, the amount and any note you add. We use them only to keep a record of donations and to thank you. Crypto donations are recorded on public blockchains that anyone can read; we see only what the blockchain shows, such as the sending address and the amount.

We do not collect more than we list here, we do not buy data about you from data brokers, and we do not sell your personal data.

How we use AI

Some of what this service does is generated by machine-learning models run by a third-party provider. Specifically:

  • the support chat assistant’s replies, which draw on this website’s content and product notes we wrote
  • suggested knowledge-base answers drafted from chats that a team member handled, with email addresses, phone numbers and long numbers removed first, which a person reviews before the assistant uses them

We use OpenAI (OpenAI, L.L.C.) for this. We send them only what is needed to answer the request. Under their API terms they do not use the content we send to train their models, and we do not use your content to train models either. Generated text can be wrong, incomplete or out of date; treat it as a draft, not as professional, legal, medical or financial advice. A person on our team may read a conversation or output to help you or to check quality.

Legal bases (EU, UK and similar laws)

  • Contract: to provide what you asked for, such as answering a message, fulfilling an order or running your account.
  • Legitimate interests: keeping the site secure, preventing fraud and abuse, understanding aggregate use of the site, and running our business, balanced against your rights.
  • Consent: any optional field you choose to fill in, and any optional feature you switch on. You can withdraw consent at any time; it does not affect processing that already happened.
  • Legal obligation: tax, accounting and responding to lawful requests.

Cookies and similar technologies

This site sets no tracking cookies. It may set strictly necessary cookies (for example a Cloudflare security cookie such as cf_clearance or __cf_bm, or a cookie that remembers your cookie choice) that do not track you across sites and need no consent.

Our site does not currently respond to Do Not Track or Global Privacy Control browser signals; use your browser settings instead.

Who we share it with

We share personal data only with the service providers that help us run this site and deliver what you asked for. Each is a separate company that processes it under its own terms, which include data-protection commitments:

Provider What they do for us Where
Cloudflare, Inc. content delivery network, DNS, TLS termination, bot and attack filtering (sees every request, including IP address and browser details) United States (global network)
Namecheap, Inc. web hosting (the server that runs this site and stores its database, backups and access logs) United States
Forward Email, LLC outbound and inbound email delivery for form notifications and support mail United States
OpenAI, L.L.C. AI model provider that writes the support chat’s replies, searches our knowledge base, and drafts suggested knowledge-base answers from the text we send it, under its API terms; API inputs are not used to train OpenAI models United States
Cloudflare, Inc. (Turnstile) bot check that runs when a page with our contact form loads and before a chat starts (receives your IP address and browser signals; sets no tracking cookies) United States
Google LLC (Google Fonts) web font delivery (your browser requests font files from Google, which sees your IP address) United States
Google LLC (Firebase Cloud Messaging) and Apple Inc. (Apple Push Notification service) deliver alerts to our support team’s phones; an alert contains only a chat reference, never what you wrote United States

Some recipients decide for themselves how they use what you give them and are not our service providers: PayPal, Inc.: your payment details, name, email address and donation amount when you donate through the Donate button. Their own privacy policies apply to that use.

We also disclose data when the law requires it (for example a valid court order), to protect our rights, safety or property or those of others, and, if our business is sold or reorganized, to the successor under this same policy. We do not sell personal data and we do not share it for cross-context behavioral advertising.

International transfers

We are based in the United States and our providers are mostly US companies, so your data is processed mainly in the United States. Our team also administers our sites and services from Hong Kong, and working copies of some production data are kept on our administrators’ workstations there. If you are in the EU, UK or Switzerland, transfers rely on the providers’ EU Standard Contractual Clauses or Data Privacy Framework certification, plus the security measures below. You can ask us for details of the safeguard that applies.

How long we keep it

  • Server and security logs: kept by our hosting provider as part of its standard log rotation; our content delivery network keeps request logs only briefly.
  • Contact form: 24 months from when you send it (the IP address for 30 days), unless you ask us to delete it sooner.
  • Support chat: conversations, files, and the details you entered, 90 days from the start of the chat; records of which team member handled a chat and our team’s internal team chat about it, 12 months; suggested knowledge-base answers (with contact details and numbers masked), until we delete them; emailed copies stay in the receiving mailboxes while we may need them to help you.

Security, and what happens if something goes wrong

We protect personal data with encryption in transit (HTTPS), with every plain-HTTP request redirected to HTTPS, Cloudflare’s edge network in front of the site, which blocks known attack traffic, login protection with automatic blocking of repeated failed logins, access limited to the people on our team who need it, and uptime and health monitoring of our servers. No system is perfectly secure, so we also plan for failure: if we learn of a security incident that affects your personal data, we will investigate, contain it, and notify you and any regulator we are required to notify without undue delay and within the time the applicable law sets (72 hours to the supervisory authority under the GDPR).

If you believe you have found a security problem in this site or any of our services, please tell us at dev@codedatda.casa before you tell anyone else. We will not pursue good-faith researchers who report responsibly and do not access, change or destroy other people’s data.

Your rights

Wherever you live, you can ask us what personal data we hold about you, ask us to correct or delete it, ask for a copy in a portable format, object to or restrict how we use it, and withdraw any consent you gave. If you are in the EU, UK or Switzerland these are your rights under the GDPR and UK GDPR, and you may also complain to your data protection authority. If you are a California resident, the CCPA/CPRA gives you the rights to know, delete, correct, and to opt out of sale or sharing (we do not sell personal data and we do not share it for cross-context behavioral advertising), and we will not treat you differently for exercising them; residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other US states with privacy laws have similar rights, including the right to appeal a decision we make about your request.

To exercise any of these, email dev@codedatda.casa from the address you used with us, or tell us enough for us to find and verify your record. An authorized agent may act for you if they show us your written permission. We answer within 30 days (45 for California requests, extendable once) and we do not charge for this unless a request is clearly excessive.

Children

This site is not directed to children and we do not knowingly collect personal data from anyone under 13 (or under 16 in the EU). If you believe a child has given us data, contact us and we will delete it.

Third-party content

Some pages embed content from other companies (Google Fonts, GitHub (the latest-release lookup, which your browser makes directly), Shields.io (project badges)). When such content loads, that company receives your IP address and may set its own cookies under its own policy. Where we can, we load it only after you interact with it.

Links to other sites

Links to sites we do not run (including app stores, GitHub, payment processors and social networks) are covered by those sites’ own policies.

Changes

When we change this policy we update the date at the top and, for material changes, post a notice on the site or email registered users. Earlier versions are available on request.

Contact

BOT-HOLDINGS, LLC, doing business as codedatda.casa
Las Vegas, Nevada, United States
dev@codedatda.casa