Privacy policy
Last updated: 2 October 2026
This policy explains what personal data Meshsmith collects, why we collect it, who we share it with, how long we keep it and what your rights are. It covers the website at meshsmith.xyz and the Meshsmith service.
Who we are
Meshsmith is a trading name of William March, a sole trader based in the UK. Business address: 4a Victoria Grove, Bridport, DT6 5AW.
We are the controller of the personal data described in this policy.
For any privacy question or request, email info@finterm.xyz or write to the address above. We have not appointed a Data Protection Officer because the law does not require one for our activities.
What we collect and why
Account details
When you create an account, we collect your email address and a password. We store only a scrambled (hashed) version of your password, never the password itself. If you sign in with GitHub, Google or X, that provider sends us your email address, name and profile picture with your permission. We do not receive your password for that provider. When you sign up with email, we send you a verification code to confirm the address is yours.
We use these details to create your account, keep it secure and let you sign in. Lawful basis: contract.
Prompts, photos and models
We collect the text prompts you type and the photos you upload, and we store the 3D models and concept images the service generates for you. We use them to generate your models and keep them in your account. Lawful basis: contract.
We do not use your prompts, photos or models to train AI models.
Please do not upload photos of other people without their permission, or photos that show sensitive information. We do not use photos to identify anyone, and we do not ask for special category data (such as health, ethnicity or biometric data).
IP addresses
We use your IP address to apply the daily limit on free drafts, to slow down repeated failed sign-in attempts and to protect the service from abuse. Lawful basis: legitimate interests, which are keeping the service secure and the free tier fair.
Product usage logs
When you use the service, our servers record events such as a generation starting or finishing. Each log holds your account ID, the type of event, your plan, the quality tier used, and your country. We work out the country from your IP address, but we do not store the IP address in these logs. Cloudflare stores the logs for us. We use them to understand how the service is used, find faults and plan capacity. Lawful basis: legitimate interests, which are running and improving the service.
Payment and subscription details
Payments are taken by Stripe on its checkout page. We never see or store your full card number. We keep your Stripe customer ID and subscription ID, your plan, your credit balance and your billing history. We use these to manage your subscription and credits and to keep accounting records. Lawful bases: contract, and legal obligation (tax and accounting records).
Messages you send us
If you email us, we keep your message and our reply so we can help you. Lawful basis: legitimate interests, which are responding to enquiries; or contract, where the message is about your account.
Website analytics without cookies
We use Cloudflare Web Analytics to count page views and measure how fast pages load. It does not use cookies, does not fingerprint your device and does not track you across sites. Lawful basis: legitimate interests, which are keeping the website working well.
Advertising and analytics with your consent
If you accept advertising and analytics cookies, Google Ads and Google Analytics collect cookie identifiers, the pages you visit, ad click IDs and device and approximate location information. We use this to measure which ads bring visitors, understand how the site is used and show Meshsmith ads to people who have visited before.
If you have given consent and you sign up or buy a plan, we also send Google a hashed version of your email address so it can match the sign-up or purchase to an ad ("enhanced conversions"). Lawful basis: consent. We do none of this unless you click Accept in our cookie banner.
Automated decisions
We do not make decisions about you by automated means alone that have legal or similarly significant effects on you. The daily free-draft limit and sign-in throttling are automated, but they do not have that kind of effect.
Who we share data with
We use the following service providers, called processors. They handle personal data on our behalf, under contracts that require them to protect it and use it only on our instructions.
- Cloudflare, Inc. hosts the website, database and file storage (your photos and models) and provides our usage logs and Web Analytics. It handles all account data, prompts, photos, models and IP addresses. Its global network includes the US.
- Runpod, Inc. provides the GPU servers that generate models. It handles prompts, uploaded photos and generated models, in datacentres in the US and the EU.
- Stripe Payments Europe, Limited and Stripe, Inc. process payments and subscriptions. They handle your email, name, payment details and subscription data. Stripe also acts as a separate controller for some data it needs to prevent fraud and meet its own legal obligations, and its own privacy policy covers that data.
- Resend (Plus Five Five, Inc.) sends account emails, such as verification codes. It handles your email address and the content of those emails, in the US.
- Google Ireland Limited provides Google Ads and Google Analytics, only if you consent. It handles cookie identifiers, browsing activity on our site, ad click IDs and, for enhanced conversions, your hashed email address. Data may be processed in the US.
GitHub, Google and X are separate controllers for the data they hold about you when you use them to sign in. Their own privacy policies apply to that data.
We may also share data:
- with professional advisers, such as lawyers and accountants, under confidentiality;
- with the police, regulators or courts when the law requires it;
- with a buyer, if the business is sold. We would tell you first.
We do not sell your personal data.
International transfers
Some of our providers process data outside the UK, mainly in the US. When personal data leaves the UK, we rely on one of these safeguards:
- the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified under it;
- otherwise, the ICO's International Data Transfer Addendum to the EU Standard Contractual Clauses.
Transfers to EU countries, including Runpod's EU datacentres, are covered by UK adequacy regulations.
You can ask for a copy of the relevant safeguards by emailing info@finterm.xyz.
How long we keep data
| Data | How long we keep it |
|---|---|
| Account details and the models in your account | While your account is open; deleted within 30 days after you close it |
| Models made without an account | Up to 12 months |
| IP addresses used for free-draft limits and sign-in throttling | Up to 30 days |
| Product usage logs | Up to 90 days |
| Email verification codes | They expire after 15 minutes |
| Stripe IDs, invoices and billing records | 6 years, as HMRC requires |
| Support emails | 2 years |
| Google Analytics data | 14 months |
We may keep data for longer if we need it to deal with a legal claim, or if the law requires it.
Your rights
Under UK data protection law, you have the right to:
- get a copy of the personal data we hold about you;
- have data that is wrong or incomplete corrected;
- have your data deleted, in some circumstances;
- restrict how we use your data, in some circumstances;
- receive the data you gave us in a machine-readable format, or have it sent to another provider;
- object to our use of your data where we rely on legitimate interests;
- withdraw your consent at any time where we rely on consent, for example for advertising cookies. Use the "Cookie settings" link in the footer. Withdrawing consent does not affect anything we did before you withdrew it.
To use any of these rights, email info@finterm.xyz from the address on your account. We may ask you to confirm your identity. We will reply within one month. If your request is complex, we can take up to two more months, and we will tell you if we need to.
Deleting your account: email info@finterm.xyz from the address on your account and ask us to delete it. We will delete your account and its models within 30 days. Download any models you want to keep first. Billing records are kept for 6 years, as HMRC requires.
Cookies
We use a small number of cookies.
Strictly necessary cookies are always on, because the site cannot work without them. They are:
mk_session, which keeps you signed in;mk_oauth, a short-lived cookie used only during GitHub, Google or X sign-in;mk_consent, which remembers your cookie choice.
Advertising and analytics cookies are set by Google (_gcl_au, _gcl_aw, _gcl_gb, _ga and _ga_*). We set them only if you click Accept in our cookie banner. If you reject them or make no choice, Google's tags run in a restricted mode that does not store or read these cookies on your device.
Cloudflare Web Analytics does not use cookies.
You can change your choice at any time with the "Cookie settings" link in the footer. Our Cookie Policy gives the full details, including how long each cookie lasts.
Security
We protect your data with encrypted connections (HTTPS), hashed passwords, HttpOnly and Secure session cookies, limits on repeated sign-in attempts, and access controls on our systems. No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will report it to the ICO within 72 hours of becoming aware of it. If the risk to you is high, we will also tell you without undue delay.
Children
Meshsmith is not intended for children. You must be 18 or over to create an account or buy a plan. If we learn that we hold data about someone under 18, we will delete it.
Changes to this policy
If we make significant changes, we will tell account holders by email or with a notice on the site before the changes take effect. The date at the top shows when this policy last changed.
Complaints
Please contact us first at info@finterm.xyz so we can try to put things right. You also have the right to complain to the Information Commissioner's Office, the UK data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.