HotMesh18+
← Back to HotMesh

Privacy Policy

What we collect, why we keep it, and what you can ask us to do with it.

Last updated 24 September 2026

1. Controller

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], is the data controller. Privacy questions and rights requests: privacy@hotmesh.app

2. What we collect

Account data: email address and a hashed password. We never store your password in readable form.

Usage data: prompts, generation parameters, job records, credit transactions, API key activity, and the dates and times of those actions.

Uploads: any reference image you provide, together with the record that you provided it.

Technical data: IP address, browser and device information, and the timestamp of your age confirmation and acceptance of these policies.

Payment data: handled by our payment provider. We receive a transaction reference and the plan purchased. We do not see or store your full card number.

3. Why we process it, and on what basis

To provide the service you asked for, and to bill you for it: performance of a contract.

To keep the platform safe and lawful, including abuse review, age assurance, and detecting prohibited content: our legitimate interests and our legal obligations.

To meet record-keeping, tax and law-enforcement obligations: legal obligation.

We do not sell personal data, and we do not train models on customer prompts or uploads.

4. How long we keep it

Account data: while your account exists, then up to 30 days.

Generation and prompt logs: 12 months, for abuse review and dispute resolution.

Billing records: as long as tax law requires, typically 6 to 7 years.

Compliance records relating to age and consent: as long as the applicable record-keeping rules require.

Deleting your account does not delete records we are legally required to retain.

5. Who else sees it

Infrastructure and hosting providers, our payment processor, our email provider, and model-inference providers where a generation runs on their hardware. Each acts under contract and only on our instructions.

Law enforcement, where we are legally compelled, or where we are reporting content we are obliged to report.

6. Your rights

Depending on where you live, you may request access to your data, correction, deletion, a portable copy, restriction of processing, or object to processing. Write to privacy@hotmesh.app and we will respond within 30 days.

If you are in the EEA or UK you may also complain to your local supervisory authority. If you are in California you may exercise CCPA rights, including the right not to be discriminated against for doing so.

7. Cookies

We use strictly necessary cookies to keep you signed in and to remember your age confirmation. These cannot be switched off without breaking the service.

We do not use advertising cookies or third-party trackers on the adult surfaces of the site.

8. Security and transfers

Passwords are hashed with bcrypt, sessions are signed and transmitted over HTTPS only, and API keys are stored as hashes rather than in readable form.

Data may be processed outside your country. Where that happens we rely on appropriate safeguards such as standard contractual clauses.

No system is perfectly secure. If a breach affects you, we will notify you and the relevant regulator as the law requires.

Other policies