Privacy Policy
Last updated: 18 de setembro de 2026
Esta página é uma tradução. A versão em inglês é a que vale.
Meshory is a local-first desktop app: the product itself never uploads your files anywhere. This policy covers the personal data this website handles: your email address if you join the early-access list, your purchase details if you buy a license, and limited data used to measure our advertising. It also covers what the desktop app sends: anonymous crash reports and usage statistics you can turn off, the details it needs to activate your license, and, only if you set them up, what its optional AI features send. The optional browser extension is covered too: it sends us nothing at all.
What we collect
If you join the early-access list, we store the email address you entered. No names, no passwords.
If you buy a license, payment is handled by Stripe, our payment processor. Stripe collects your name, email, payment details, and billing country (used for tax calculation). Your card number never touches our servers. We receive and store your email, the license key issued to you, and a record of the purchase so we can look your license up for support and refunds.
What it's used for
Your email is used to send a signup confirmation and occasional updates about Meshory: early-access invites, launch news, and roadmap votes. We don't sell or share your address with anyone for marketing.
Where it's stored
Emails are stored in our subscriber database and with Resend, the email service we use to send messages. Purchase and license records live in our license database and with Stripe.
Analytics
We use PostHog (EU-hosted) to understand how the site is used: pages visited, referral source, and anonymous usage events. For visitors in the EU/EEA/UK/Switzerland, PostHog runs in a cookieless mode that stores no analytics identifiers on your device; elsewhere, PostHog uses cookies and local storage to recognize repeat visits. A single first-party cookie remembering your country code selects the right mode. We never sell your data. How we measure advertising is covered below.
We also use DataFast to see which pages and which marketing channels bring visitors, and which of them lead to a purchase. It stores two first-party cookies on your device: datafast_visitor_id for a year, and datafast_session_id for thirty minutes. Those two identifiers are attached to the Stripe checkout if you buy, which is what lets a purchase be credited to the visit that led to it; they carry nothing about you beyond the visit itself. For visitors in the EU/EEA, UK, and Switzerland it loads only after you accept cookies on the banner shown on your first visit, and decline means nothing is stored at all. Elsewhere it is active by default. Clearing the mshy_ads_consent cookie resets that choice, and setting datafast_ignore to true in your browser's local storage opts you out everywhere.
Advertising
We advertise Meshory on Meta platforms (Facebook and Instagram). To measure whether those ads work, we use the Meta Pixel, which reports events such as page views, checkout starts, and purchases back to Meta, along with technical data (IP address, browser) and, where available, a hashed version of your email used to match the event to a Meta account. This lets us see which ads lead to purchases and reach similar people. We use it only to measure and improve our advertising, and we never sell your personal data.
Some of these events are sent from our server rather than your browser, so that ad measurement still works when a browser extension blocks the Pixel. They carry the same information described above, plus a random identifier we generate for your visit, and they are matched with the browser event so a single action is never counted twice. If you arrive from a Meta ad we also store that ad's click identifier in a mshy_fbc cookie so the purchase can be attributed to it. Both are subject to the same consent choice below: decline and neither the server events nor that cookie happen.
For visitors in the EU/EEA, UK, and Switzerland, the Meta Pixel loads only after you accept advertising cookies on the banner shown on your first visit. Decline and it never loads. Elsewhere it is active by default. You can change your choice at any time by clearing the mshy_ads_consent cookie, and you can control ad personalization in your Facebook and Instagram settings. Data shared with Meta is also governed by Meta's Privacy Policy.
We also use Google Tag Manager to load our measurement tags, and Google Analytics to report on how the site is used alongside our advertising. These receive page views and conversion events such as checkout starts and purchases, along with technical data (IP address, browser), and Google Analytics sets cookies on your device to recognize repeat visits. We use them only to measure and improve our advertising, and we never sell your personal data.
Google is governed by the same consent choice as Meta. Google's tag loads in a consent-aware mode: for visitors in the EU/EEA, UK, and Switzerland it stores nothing on your device (no cookies, no identifiers) until you accept advertising cookies on the banner, and declining keeps it that way; before consent it can send Google at most cookieless, aggregate signals. Accepting enables the cookies and measurement described above. Elsewhere it is active by default. Clearing the mshy_ads_consent cookie resets the choice. Data shared with Google is also governed by Google's Privacy Policy.
The desktop app
Your model files stay on your computer. The app has no account and never uploads them. It does send some information, depending on what you use: crash reports and usage statistics, the details it needs to activate your license, and, only if you set them up, what the optional AI features need.
Crash reports and usage statistics. These are anonymous: they're tied only to a random identifier generated on install, which isn't linked to your email, your license, or your purchase.
Crash reports go to Sentry (EU-hosted) and contain the error and the stack trace that produced it. Before a report is sent, the paths in it are stripped: your watched folders, your home directory, and the name of any model, image, archive, or document file are replaced with placeholders. Native crash dumps, which can contain arbitrary memory, are disabled entirely.
Usage statistics go to PostHog (EU-hosted) and are limited to a fixed list of events defined in the app: which version, operating system, and architecture you run; that a feature was used, such as starting a search, sending a model to a slicer, or creating a collection; and how big your library is. Library size is reported only as a range, for example “1,000–5,000 models” or “10–50 GB”, never as an exact figure, and no more than once a day. We use it to know which library sizes to make the app fast for.
Crash reports and usage statistics never include file names, folder names, file paths, tags, notes, or search terms. You can turn both off from the banner shown when you first open the app, or at any time in Settings. With them off, the app sends no crash reports or usage statistics.
Your license. To activate your license, to renew it (about once a week, or each time you open the app during a trial), and to check whether an update is covered by it, the app sends our license server your license key, an identifier for this computer, and the computer's name. We use these to confirm your license is valid and to see which computers it's used on. This happens whether or not crash reports and usage statistics are on. The app also checks our download server for new versions; that request carries no license or library details.
Optional AI features. AI tagging and semantic search send nothing about your library until you add your own OpenRouter API key. When you use them, the app sends requests directly from your computer to OpenRouter, using your key. They don't pass through Meshory's servers. OpenRouter forwards each request to the AI model that handles it, and OpenRouter's and that provider's privacy policies apply.
AI tagging sends each model's file name, folder path, and existing tags. If you turn on image tagging, it also sends a rendered picture of the model.
Semantic search sends each model's file name, folder path, tags, and AI description, plus the names of files inside archives, to build its index, and sends your search terms each time you search. It uses OpenAI's text-embedding-3-small model.
The browser extension
Meshory Capture is an optional Chrome extension, installed separately, that brings a Patreon release into the desktop app. It sends nothing to Meshory: no analytics, no crash reports, and no copy of anything it reads.
When you press its button on a Patreon post, it reads that release from the page you are on or from Patreon's own API: the title, the description, the pictures, and the names and sizes of its attachments. That capture is kept in the extension's storage in your browser, where it stays until the next one replaces it, and is handed to the Meshory desktop app on the same computer through Chrome's native messaging. It does not leave your computer.
To fetch a file, the extension resolves that attachment's authorized link using the Patreon session your browser already has, and passes the desktop app a short-lived link to the file. Your cookies are managed by your browser and are never read by the extension, and your Patreon password never passes through it. It reaches only what you can already open while signed in, and does not bypass paywalls, membership tiers, or creator settings.
Unsubscribing & deletion
Every email we send includes an unsubscribe link. If you'd like your address removed from the list entirely, email us and we'll delete it.
Contact
Questions about this policy or your data: support@meshory.com.