The short version: MESH cannot read your messages — they are encrypted on your device before they leave it. We don't know your name, email, or phone number. Our relay stores your public Stellar address, your public encryption keys, your chosen username and (if you allow notifications) a push token — public by design — plus each encrypted message only until it is delivered. The relay does see delivery metadata: which address sends to which, and when.
MESH Protocol is an independent project developed by Mohamed Abdellah. The relay server and website are hosted at meshprotocol.ru.
Contact: contact@meshprotocol.ru · support@meshprotocol.ru
| Data Type | Collected? | Where? |
|---|---|---|
| Your name | ✗ Never | — |
| Email address | ✗ Never | — |
| Phone number | ✗ Never | — |
| IP address | ✓ Only as a one-way hash | Your IP address is used in memory to limit abuse. A short salted hash of it (not the address itself) is kept in our usage log for 90 days to count unique users and spot abuse |
| Usage log entries | ✓ 90 days | Relay server — event type, time, message size, and a salted hash of your address and IP. Never message content, recipients, or the raw address |
| Message content | ✗ Never readable | Encrypted only — held on our relay until delivered, then deleted |
| Stellar public address | ✓ Yes | Relay server — needed to deliver your messages. Also public on the blockchain when you send or receive a payment |
| Public encryption keys (identity key and one-time "prekeys") | ✓ Yes | Relay server — needed for encryption, public by design. Private keys never leave your phone |
| Username (@handle) | ✓ Yes | Relay server — chosen by you, publicly searchable |
| Encrypted message and who it is from and to | ✓ Temporarily | Relay server — deleted as soon as delivery is confirmed, or after 14 days if never collected. Copies can remain in backups for up to about 2 days (see Section 3) |
| Push notification token | ✓ If you allow notifications | Relay server — used only to alert your phone to a new message; sent to the notification service for your device |
Your messages are encrypted on your device before they leave your phone, using a Signal-style scheme (an X3DH key agreement and a Double Ratchet, built from standard primitives: X25519, HKDF-SHA256, HMAC-SHA256 and XSalsa20-Poly1305). Every message uses its own key, which is deleted after use, so a phone compromised later cannot open messages that were already sent (forward secrecy). This design has not yet been independently reviewed. Contacts using an older version of the app fall back to the older format, and the chat says so. The encrypted message is sent to a relay server, which holds it only until your recipient's app confirms it has received it, and then deletes it. A message that is never collected is deleted after 14 days. Ordinary messages are not written to the blockchain.
Our relay server can see who is sending to whom (Stellar addresses) and when, but never the message content, because it never holds your keys. Payments are different: a payment you send is a Stellar transaction, which is public and permanent on the blockchain. Your chat history is stored only on your phone, so a lost phone means lost history; your recovery phrase restores your account, not old chats.
Delete for everyone. You can replace a message you sent with "This message was deleted" on both phones. This only works for messages sent since the feature was added (23 September 2026) — the app doesn't offer it for older messages, since it doesn't have what it needs to notify the other phone. Older messages can still be deleted from your own device only.
Backups. For reliability, the relay's database is backed up to a private storage bucket at Cloudflare (R2). Because of this, an encrypted message that was delivered and deleted from the relay can remain in backup copies for up to about 2 days before they expire. Backups contain only what the relay holds (encrypted messages, usernames, public keys, push tokens), never your private keys and never message content in readable form.
The MESH app stores the following on your device.
In secure storage (Expo SecureStore, backed by the Android Keystore on supported devices):
In the app's local database (a SQLite file in the app's private storage):
Malware running as the app, or a rooted phone, can still reach this data. You can optionally turn on an app lock (fingerprint, face, PIN or pattern), which also blocks screenshots and hides MESH in the app switcher.
None of this is transmitted to us. It lives only on your device. Android's backup is enabled for the app, but its backup rules include only the app's preference files and exclude the secure-storage file, so the message database and your keys are not part of Android backups. If you uninstall the app or use "Clear All Data", the data is deleted. Make sure you have your recovery phrase before doing so.
Permissions. MESH asks for: the camera (to scan QR codes when verifying a contact and to take photos you choose to send); photo access (to choose a photo to send, and to save a received photo to your gallery); notifications; and your phone's fingerprint or screen lock (only for the optional app lock). Camera images stay on your device unless you choose to send a photo, and are then sent encrypted. The current version (0.2.1) does not request microphone, audio-settings or "draw over other apps" access, and has no feature that uses them (voice notes are not built). Version 0.2.0 declared these permissions without using them; upgrade to 0.2.1 to remove them.
MESH uses the following third-party services:
www address, which only redirects to the main site (Cloudflare sees a visitor's IP address for that redirect). The website itself and the messaging relay are served directly, not through Cloudflare.The MESH website (meshprotocol.ru) does not use advertising cookies, tracking pixels, or analytics scripts. The only browser storage used is localStorage to remember your chosen accent color preference.
The MESH mobile app does not use any analytics SDK, crash reporting service, or advertising framework.
You have the right to:
Because we don't know who you are, you'll need to identify yourself by your Stellar public address when making a request.
MESH is not intended for users under 13 years of age. We do not knowingly collect data from children. Because we collect no personal information at all, we have no way to verify age — parental guidance is advised.
We may update this policy as MESH evolves. The "Last updated" date will always be current. Continued use of MESH after changes means you accept the updated policy.
Privacy questions or deletion requests: contact@meshprotocol.ru