Privacy policy
Effective 2026-10-05. Operator: The Fire Dev LLC (MeshVault). Contact: tanner@meshvault.ai.
What we collect
- Email address, when you create a free key or subscribe. Used for your key, receipts and service notices.
- API key hash. We store a SHA-256 hash of your key, its plan and status. We cannot read your key back.
- Usage counters. Number of tool calls per key per day. For anonymous calls, a salted hash of your network address, not the address itself.
- Billing data is held by Stripe. We store your Stripe customer and subscription ids and never see your card number.
What we do not collect
We do not store the questions you send or the results returned. Tool arguments pass through to the public data sources below and are not logged by us beyond standard platform request logs (path, status, timing). Do not put patient-identifying information or confidential case details into tool arguments.
Who receives data
Your tool arguments are sent to the source each tool uses: Protocol Guide (protocol-guide.com), JudgeFinder (judgefinder.vercel.app), CMS NPPES (npiregistry.cms.hhs.gov), FDA openFDA (api.fda.gov) and Hugging Face (huggingface.co). Hosting is on Vercel; payments on Stripe. We do not sell data or use it for advertising.
Retention and your choices
Key and billing records are kept while your key is active and for tax and fraud records after. Usage counters are kept for operations and abuse prevention. Email tanner@meshvault.ai to delete your key record or ask what we hold.
Security
Keys are hashed at rest, OAuth tokens are short-lived and signed, traffic is encrypted in transit. No system is perfect; report issues to the address above.
Changes
We will post changes here and update the effective date.