OVERVIEW
1. Overview
MeshInfer.AI, Inc. ("Company," "we," "us," or "our") operates DOSFI, the distributed operating system, and the MeshInfer.AI runtime. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Services.
We are committed to transparency and user control. We do not sell your personal data to third parties. We collect only what we need to operate and improve our Services, and we handle all data in accordance with applicable privacy law.
This policy applies to all users globally, with specific rights and disclosures for residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Florida, Montana, Oregon, Pennsylvania, and other states with applicable privacy and breach notification laws.
COLLECTION
2. Information We Collect
We collect information in three ways:
INFORMATION YOU PROVIDE:
• Account registration: name, email address, password (hashed), organization
• Partner Portal: company name, role, pilot project details
• Forms & requests: whitepaper requests, pilot inquiries, support tickets
• Communications: emails, support messages
INFORMATION COLLECTED AUTOMATICALLY:
• Usage data: pages visited, features used, session duration, click patterns
• Device information: browser type, OS, device type, screen resolution
• Network data: IP address, approximate location (city/region), referral source
• Node telemetry (if participating): device model, available compute capacity, thermal readings, readiness score, uptime — never personal content from your device
INFORMATION FROM THIRD PARTIES:
• Authentication providers (if using OAuth login)
• Analytics partners (aggregated, de-identified)
• Enterprise pilot partners (for authorized user provisioning)
USE
3. How We Use Your Information
We use collected information to:
• Provide, operate, and improve the Services
• Authenticate users and maintain account security
• Process API requests and manage node participation
• Send transactional emails (account verification, security alerts, whitepaper delivery)
• Respond to support requests and inquiries
• Analyze usage patterns to improve product features
• Detect, prevent, and respond to fraud, security incidents, and abuse
• Comply with legal obligations
• Enforce our Terms of Use
We do NOT use your data to:
• Build advertising profiles or sell to advertisers
• Sell, rent, or broker your personal data to third parties
• Use node telemetry data for any purpose other than mesh operation and your account dashboard
SHARING
4. Information Sharing & Disclosure
We share your information only in these circumstances:
SERVICE PROVIDERS: Trusted vendors who help operate our Services (cloud hosting, email delivery, analytics) under strict data processing agreements that prohibit them from using your data for their own purposes.
BUSINESS TRANSFERS: If MeshInfer.AI is acquired, merges, or transfers substantially all assets, your data may be transferred as part of that transaction. We will provide notice and honor existing privacy commitments.
LEGAL COMPLIANCE: We may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of our users or the public.
WITH YOUR CONSENT: We may share information for other purposes when you have provided explicit consent.
WE DO NOT SELL PERSONAL DATA. This applies to all users, including California residents under CCPA and all other state privacy laws.
NODE-PRIVACY
5. Node Participation Privacy
Node participation has specific privacy properties by design:
WHAT WE COLLECT FROM NODES:
• Device capability metrics (CPU cores, GPU model, available RAM, thermal headroom)
• Readiness score (computed locally and reported)
• Uptime and participation logs
• Shard completion confirmations (no content, only completion status)
WHAT WE NEVER ACCESS FROM YOUR DEVICE:
• Personal files, photos, messages, or any content stored on your device
• Workload payload content (all payloads are encrypted end-to-end)
• Browsing history, app usage, or any data outside the DOSFI node client sandbox
ZERO-KNOWLEDGE DESIGN:
Node operators never see the content of workloads they process. Workload requesters never see which specific devices processed their request beyond aggregate mesh statistics.
You may stop node participation at any time from within the node client settings. Stopping participation does not delete your account.
RETENTION
6. Data Retention
We retain your data for as long as your account is active or as needed to provide Services. Specific retention periods:
• Account data: Retained for the life of your account plus 90 days after deletion
• Usage logs: 12 months rolling
• Node telemetry: 24 months rolling (aggregate), 30 days (granular)
• Support tickets: 3 years
• Legal/compliance records: 7 years or as required by law
When you request account deletion, we will delete or anonymize your personal data within 45 days, except where retention is required by law or for legitimate business purposes (fraud prevention, dispute resolution, legal obligations).
SECURITY
7. Security
We implement industry-standard and beyond-standard security measures:
• Post-quantum encryption for all mesh communications (lattice-based key encapsulation)
• TLS 1.3 minimum for all data in transit
• AES-256 encryption for data at rest
• Zero-trust architecture: every request is authenticated and authorized independently
• SOC 2 Type II controls for our infrastructure
• Regular third-party penetration testing
• Bug bounty program (support@dosfi.ai)
• Access controls: principle of least privilege for all internal systems
No security system is perfect. If you discover a vulnerability, please report it responsibly to support@dosfi.ai.
CALIFORNIA
8. California Residents — CCPA/CPRA
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights:
YOUR RIGHTS:
• Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the third parties with whom we share it.
• Right to Delete: Request deletion of your personal information, subject to certain exceptions.
• Right to Correct: Request correction of inaccurate personal information.
• Right to Opt-Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioral advertising. No opt-out needed, but you may submit one at any time.
• Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes other than providing our Services.
• Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
CATEGORIES OF PERSONAL INFORMATION COLLECTED (last 12 months):
• Identifiers (name, email, IP address)
• Internet/network activity (usage logs, device info)
• Geolocation data (city/region only, from IP)
• Professional/employment info (for enterprise users)
• Inferences drawn from the above for service improvement
TO EXERCISE YOUR RIGHTS: Email support@dosfi.ai or use the online request guide at dosfi.ai/privacy-guide. We will respond within 45 days. We may verify your identity before fulfilling requests.
AUTHORIZED AGENTS: You may designate an authorized agent to submit requests on your behalf with written authorization.
STATE-RIGHTS
9. Other U.S. State Privacy Rights
Residents of the following states have privacy rights similar to California under their respective laws:
VIRGINIA (VCDPA): Rights to access, correct, delete, obtain a copy, and opt out of targeted advertising and profiling. Submit requests to support@dosfi.ai.
COLORADO (CPA): Rights to access, correct, delete, data portability, and opt out of targeted advertising, profiling, and sale. Submit requests to support@dosfi.ai.
CONNECTICUT (CTDPA): Rights to access, correct, delete, portability, and opt out of targeted advertising and profiling. Submit requests to support@dosfi.ai.
UTAH (UCPA): Rights to access, delete, obtain a copy, and opt out of sale and targeted advertising. Submit requests to support@dosfi.ai.
TEXAS (TDPSA): Rights to access, correct, delete, portability, and opt out of targeted advertising, profiling, and sale. Submit requests to support@dosfi.ai.
FLORIDA (FDBR): Rights to access, delete, correct, portability, and opt out of sale and targeted advertising for consumers with annual revenue thresholds. Submit requests to support@dosfi.ai.
MONTANA (MCDPA): Rights to access, correct, delete, portability, and opt out. Submit requests to support@dosfi.ai.
OREGON (OCPA): Rights to access, correct, delete, portability, and opt out. Submit requests to support@dosfi.ai.
NEVADA: Right to opt out of the sale of personally identifiable information. We do not sell personal information. Submit opt-out requests to support@dosfi.ai.
PENNSYLVANIA: See Section 9A below for Pennsylvania-specific rights and disclosures.
Response time: We respond to all state privacy rights requests within 45 days, extendable by an additional 45 days with notice. We do not charge a fee for reasonable requests.
PENNSYLVANIA
9A. Pennsylvania Residents
Pennsylvania does not yet have a comprehensive consumer privacy statute, but several state and federal laws protect Pennsylvania residents' personal information:
PENNSYLVANIA BREACH OF PERSONAL INFORMATION NOTIFICATION ACT (73 P.S. § 2301 et seq.):
If we discover a breach of the security of your personal information, we are required to notify you in the most expedient time possible and without unreasonable delay. Under Pennsylvania law, "personal information" includes:
• Name combined with Social Security number
• Name combined with driver's license or state ID number
• Name combined with financial account numbers plus access credentials
• Name combined with medical information
• Name combined with username/email and password
HOW WE WILL NOTIFY YOU:
Notification will be provided by written notice to your last known mailing address, electronic notice to your email address on file, or — if the breach affects more than 100,000 Pennsylvania residents — by statewide media and posting on our website. We will also notify the Pennsylvania Attorney General's office as required.
PENNSYLVANIA UNFAIR TRADE PRACTICES AND CONSUMER PROTECTION LAW (UTPCPL):
We do not engage in unfair, deceptive, or fraudulent trade practices in connection with the collection or use of your personal information. If you believe we have violated the UTPCPL in our data practices, you may file a complaint with the Pennsylvania Attorney General's Bureau of Consumer Protection at:
• Online: attorneygeneral.gov
• Phone: 1-800-441-2555
• Mail: Pennsylvania Office of Attorney General, Bureau of Consumer Protection, 15th Floor, Strawberry Square, Harrisburg, PA 17120
FEDERAL PROTECTIONS APPLICABLE TO PENNSYLVANIA RESIDENTS:
• FTC Act (Section 5): Prohibits unfair or deceptive data practices — we adhere strictly to our stated data practices.
• CAN-SPAM Act: All marketing emails include unsubscribe mechanisms; we honor opt-out requests within 10 business days.
• COPPA: We do not knowingly collect data from children under 13.
YOUR PRACTICAL RIGHTS AS A PENNSYLVANIA RESIDENT:
Even without a state-specific comprehensive privacy law, you may:
• Request to know what personal information we hold about you — email support@dosfi.ai
• Request correction of inaccurate information — email support@dosfi.ai
• Request deletion of your account and associated data — email support@dosfi.ai
• Opt out of any marketing communications at any time
We will respond to all Pennsylvania resident requests within 30 days. We treat Pennsylvania residents with the same respect and transparency as residents of states with comprehensive privacy laws.
INTERNATIONAL
10. International Users
DOSFI is operated from the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following legal bases for processing:
• Performance of a contract (account and service delivery)
• Legitimate interests (security, fraud prevention, service improvement)
• Legal obligation (compliance with applicable law)
• Consent (where explicitly obtained)
You may have rights under GDPR or UK GDPR including access, rectification, erasure, restriction, portability, and objection. Contact support@dosfi.ai with GDPR requests.
CHILDREN
11. Children's Privacy
The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will promptly delete it. If you believe we have inadvertently collected such information, contact us at support@dosfi.ai.
COOKIES
12. Cookies & Tracking
We use cookies and similar technologies to:
• Maintain your session and authentication state
• Remember your preferences (e.g., theme selection)
• Analyze usage patterns (analytics cookies — anonymized)
• Prevent fraud and ensure security
We do NOT use third-party advertising cookies or behavioral tracking for ad targeting.
You may control cookies through your browser settings. Disabling all cookies may affect certain features of the Services (e.g., staying logged in).