Privacy Policy
Effective date: 2026-07-25 · Last updated: 2026-07-25 (Public Beta)
MsgMesh ("the Service") is a hosted, multi-tenant "persistent event bus" built on top of Kafka, enabling developers and teams to plug into real-time messaging and event streams with minimal setup (via HTTP, SSE, WebSocket, MCP, and SDK interfaces). The Service is currently in public beta and is operated by a small independent team.
This Privacy Policy explains what personal data we collect when you use the Service, how we use and protect it, and the rights you have regarding your personal data. By using the Service, you acknowledge that you have read and understood this Policy. If you have any questions, please contact us at [email protected].
1.What Data We Collect
We collect only the data necessary to provide and operate the Service. This mainly falls into the following categories:
- Account data: When you register with email, we collect your email address (required) and password. Passwords are stored hashed using the argon2id algorithm; we never store your password in plaintext. If you choose third-party sign-in, we receive: from Google (your email and name) or from Telegram (your Telegram id and username), used solely to verify your identity.
- Service data: The messages and event content you publish or receive through the Service, the topics you create, the API keys you generate (stored in hashed form), and usage metering data (such as message counts and byte counts) used for quota enforcement and (future) billing.
- Analytics data: We use a self-hosted Matomo instance for website analytics, configured with privacy-first settings (see "Cookies and Analytics" below).
- Technical logs: Standard server logs, which may include IP addresses and timestamps, used for security and operations.
2.How We Use Your Data
We use the data described above for the following purposes:
- Providing and operating the Service: creating and managing your account, verifying your identity, delivering and storing your messages and events, and managing topics and API keys.
- Quota and metering: enforcing quotas based on usage metering. The Service is free during beta; if billing is enabled in the future, metering data will serve as the basis for billing (we will update this Policy accordingly).
- Notifications and verification: sending account verification emails and necessary service notifications.
- Security and operations: detecting, preventing, and addressing abuse, fraud, or technical issues, and maintaining the stability and security of the Service.
- Improving the Service: understanding overall usage through aggregated, anonymized analytics to improve the product.
We do not use the message and event content you transmit through the Service for any purpose beyond operating and securing the Service, and we do not sell your personal data for advertising purposes.
For any third-party personal data contained in the content you transmit through the Service, we process such content on your (the user's) instructions solely to provide, deliver, and store it according to the applicable retention period; in this respect you are the data controller and the Service acts as a data processor. You are responsible for ensuring you have a lawful basis to collect, use, and transmit such content.
3.Third Parties and Data Processors
To provide the Service, we rely on the following third parties for specific functions. We share data only to the extent necessary, and they process it under their own privacy and security policies:
- Resend: sends account verification and notification emails; the recipient's email address is passed to it.
- Google / Telegram: used only when you choose to sign in with a third-party account, to verify your identity.
- Cloudflare: provides CDN, DNS, and edge network services (static site hosting and traffic proxying).
Payment data: The Service is entirely free during beta and no payment processing is currently enabled; we therefore do not currently collect any payment data. If we begin charging in the future, we will update this Policy and describe the relevant payment processor.
Except as described above, or where required by law or necessary to protect the legitimate rights of the Service and its users, we do not share your personal data with other third parties.
5.Data Retention
We retain your data only for as long as necessary to fulfill the purposes described in this Policy:
- Messages and events: retention depends on your plan. For example, the free tier retains messages for about 1 day, and the metered tier for about 30 days; messages past their retention period are deleted automatically. Actual retention is governed by each plan's description and may change before general availability.
- Account data: retained for the life of your account; when you delete your account, we delete or anonymize the associated personal data (except where retention is required by law).
- Technical logs: server logs are kept only for a reasonable period for security and operations.
Beta reminder: we may reset test-environment data during beta, so do not store your only or critical copy of any data solely on the Service.
6.Where Your Data Is Stored
Your personal data and service data are primarily stored and processed in Taiwan. However, when you use third-party sign-in, when we send you emails, or when traffic is proxied through an edge network, limited related data (such as your email address) may be processed outside Taiwan by Resend, Google, Telegram, or Cloudflare, subject to their respective privacy policies. Apart from the foregoing, we do not intentionally transfer your personal data outside Taiwan for long-term storage; if other cross-border transfers become necessary for operational reasons in the future, we will update this Policy and take appropriate safeguards.
7.Your Rights and How to Exercise Them
With respect to the personal data we hold about you, you may exercise the following rights:
- Access: request to review or obtain a copy of your personal data.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your personal data, or deletion of your entire account.
To exercise these rights, please contact us at [email protected]. To protect your data, we may need to verify your identity before acting on your request. Some data may need to be retained due to legal obligations or for operational and security reasons.
8.Data Security
We take reasonable technical and organizational measures to protect your data, including:
- encrypting data in transit using TLS;
- storing passwords hashed with argon2id and API keys in hashed form, never in plaintext;
- applying necessary access controls and monitoring to our systems.
Please note that no method of transmission over the Internet or method of storage is completely secure. The Service is currently in beta, and we cannot provide any absolute guarantee of data security or service availability. Please keep your account credentials safe and avoid storing your only or highly sensitive data on the Service.
9.Important Public Beta Notice
The Service is currently in public beta. Please note the following before using it:
- The Service is provided "as-is"; during beta we make no guarantee of any service level agreement (SLA), availability, or uninterrupted operation.
- We may reset test-environment data during beta; do not store your only or critical data solely on the Service.
- The Service is free during beta; future pricing and plans are planned directions and may change before general availability.
- Message retention periods for each plan (see "Data Retention") may likewise change before general availability.
10.Children
The Service is designed for developers and teams and is not directed at children. We do not knowingly collect personal data from children or from anyone under the age of consent applicable in their jurisdiction. If you believe a minor has provided us with personal data without appropriate consent, please contact us at [email protected], and we will take reasonable steps to delete it.
11.Governing Law, Jurisdiction, and Severability
This Policy, and any dispute arising out of the Service or this Policy, is governed by the laws of the Republic of China (Taiwan), with the courts of Taiwan as the competent forum. If any provision of this Policy is held to be invalid or unenforceable by a court of competent jurisdiction, the remaining provisions shall remain in full force and effect, and the affected provision shall be interpreted, to the extent permitted by law, in a manner that most closely reflects its original intent. We strive to follow applicable personal-data protection principles; however, this Policy does not constitute a claim of certification under any particular regulation.
12.Changes to This Policy
As the Service evolves—particularly during beta—we may revise this Policy from time to time. For material changes, we will post a notice on our website (msgmesh.alderflux.com) or notify you by other appropriate means. The revised Policy takes effect on the effective date stated in the notice; your continued use of the Service after the change takes effect constitutes acceptance of the revised Policy.
13.Contact Us
If you have any questions or requests regarding this Privacy Policy, your personal data, or the rights described above, please contact us:
- Email: [email protected] (currently our only contact channel, or any other channel announced by the Service)
- Website: msgmesh.alderflux.com
We will respond to your message within a reasonable time.