Privacy Policy
This Privacy Policy explains how Meshive, operated by Steppod, LLC, collects, uses, discloses, and otherwise processes information when you use meshive.ai, our GPU compute, serverless inference, storage, and related services.
This Privacy Policy explains how Steppod, LLC, doing business as Meshive (“Meshive,” “we,” “us,” or “our”), collects, uses, discloses, and otherwise processes personal information when you access or use meshive.ai and any related websites, consoles, dashboards, command-line tools, SDKs, APIs, gateways, workspace features, support channels, or other services that link to this Privacy Policy (collectively, the “Services”). By using the Services, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy should be read together with our Terms of Service.
1. Who We Are (Controller)
For the purposes of the EU/UK GDPR, Steppod, LLC is the controller of personal information processed about account holders and website visitors. For User Content that you process through the Compute and Serverless Services, Meshive generally acts as a processor acting on your instructions (see Sections 4 and 7).
2. Scope
This Privacy Policy applies to personal information we process in connection with the Services. It does not apply to third-party websites, services, models, or datasets that we do not operate, even if integrated with or linked from the Services. Where you use the Services on behalf of an organization, that organization is responsible for its own privacy obligations to its personnel and end users.
3. Information We Collect
We collect the categories below. We distinguish between personal information / account data and the technical and content data generated by operating the infrastructure.
A. Information you provide directly (account and identity)
- Email address (your primary account identifier)
- Name / username
- Password, stored only as a salted cryptographic hash (we never store your plaintext password); accounts created via Google login may not have a password
- Phone number, where you provide it
- Referral information, such as a referral code you use or that is assigned to you
- Communications you send us (support requests, inquiries, and related content)
B. Authentication data
- When you sign in with Google, we receive limited profile/account information from Google (such as your email and basic profile data) as needed to authenticate you and create or link your account
- Session tokens, API keys, and SSH credentials we issue and manage; for API keys we store only a hash and a short non-secret prefix — never the plaintext key
C. Payment and payout data
- Card payments are processed by Stripe. We do not receive or store full card numbers. We store payment-method metadata (such as card brand and last four digits), Stripe customer/payment tokens, payment-intent identifiers, receipt/invoice references, and your billing and credit history (top-ups, charges, balances)
- Hosts who receive payouts complete Stripe Connect onboarding; Stripe collects the identity, bank/payout, and tax information required to pay you. We store the resulting Connect account identifier, associated email, and status, and your earnings and settlement records
D. Technical, usage, and log data
- IP address, browser type, device and operating-environment information, and technical identifiers
- Access dates/times and session information
- API, CLI/SDK, and platform request logs, including request metadata and (subject to size limits) request/response bodies retained for debugging and abuse prevention
- Resource and consumption data — GPU type and count, compute/CPU, memory, storage, GPU-time, and other usage metering used to calculate charges and earnings
- Operational metrics, diagnostics, and error information for the Services and, for Hosts, for the machines you connect (e.g., hardware/capacity telemetry, reachability and port checks, health metrics)
- Webhook delivery logs (target, status, attempts, errors) for event notifications you configure
E. User Content and workloads
- Compute Service: the data, files, model weights, datasets, container images, and code inside your Instances and on your volumes
- Serverless Service: model registrations and metadata; inference request inputs and outputs (for example, prompts, images, and generated artifacts), which may be transiently stored to track request status, deliver results, retain artifacts, and assist debugging; and any third-party access tokens you provide for gated models
- Connected storage credentials for your own buckets (e.g., Amazon S3, Cloudflare R2, Google Cloud Storage), which we store in encrypted form to deliver outputs where you direct
F. Cookies, analytics, and similar technologies
We use cookies and similar technologies to keep you signed in, maintain sessions, remember settings, secure the Services, and measure usage. We use Google Analytics to understand usage patterns and improve the Services. You can manage choices through your browser settings.
4. Content Privacy and Non-Use of Your Data
We treat the contents of your workloads as yours. Specifically:
- No ownership transfer. You retain ownership of your User Content.
- No selling. We do not sell your User Content or personal information for money.
- No model training on your content. We do not use your User Content — including the data, models, prompts, inputs, or outputs you process through the Services — to train, fine-tune, or improve Meshive’s or any third party’s AI/ML models.
- Compute Instances. Your Instances are your environment. In the ordinary course we do not access the contents of your Instances or volumes. We access or disclose such contents only where reasonably necessary to operate, secure, and maintain the infrastructure; investigate suspected violations of the Terms or AUP; respond to a valid legal request; or protect the rights, safety, and integrity of the Services, our users, Hosts, and third parties.
- Serverless Service. The Serverless gateway necessarily processes your request inputs and outputs to route them, return results, and operate the service, and it may transiently store request and result payloads, artifacts, and limited request bodies for status tracking, delivery, retention, and debugging (see Sections 3.E and 10). We also apply automated safety/abuse filtering (including NSFW/CSAM detection) to certain Serverless workloads. We do not represent that Serverless content is invisible to the system; we represent that we do not sell it or use it to train models, and that access is limited as described above.
- LLM inference and shared models. For text (LLM) inference served through our gateway — including shared model endpoints — prompts and completions are processed transiently to serve the request and are not logged by the serving engine on shared deployments. The gateway retains only usage metadata (such as token counts, model identifier, timing, and status) for billing, settlement, and abuse prevention — not the content of your prompts or outputs.
Meshive is an infrastructure provider, not an “end-to-end encrypted” or “zero-knowledge” product. Operating GPU infrastructure requires the system to handle your workloads. The commitments above (no sale, no training on your content, least-privilege access) are the accurate description of how your content is protected.
5. How We Use Information
- provide, operate, maintain, secure, and improve the Services;
- create, authenticate, and manage accounts, Workspaces, API keys, and sessions;
- provision and operate GPU/compute, storage, deployment, model serving, and related functionality;
- meter usage, calculate charges, manage Credits and auto-recharge, process payments, and calculate and pay Host earnings;
- send transactional and administrative communications (e.g., verification, billing, low-balance and deletion-warning notices, service notices, and support responses);
- monitor, troubleshoot, and maintain performance, reliability, and security;
- detect, investigate, prevent, and respond to fraud, abuse, AUP violations, security incidents, and unlawful activity, and to enforce our Terms;
- perform analytics, reporting, and internal business operations; and
- comply with legal obligations and respond to lawful requests.
6. Legal Bases (EEA/UK/Switzerland)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Services you request); legitimate interests (to secure, improve, and protect the Services and prevent abuse, balanced against your rights); compliance with legal obligations (e.g., tax, accounting, and lawful requests); and consent where required (e.g., certain cookies/analytics), which you may withdraw at any time.
7. How We Share Information; Sub-Processors
We share information only as described here. We do not sell personal information.
A. Service providers and infrastructure sub-processors
We use third-party vendors and service providers that process personal information on our behalf to help us operate, provide, secure, and improve the Services — for example, payment processing, cloud hosting and infrastructure, storage, networking, communications and email delivery, and analytics. They may access personal information only as needed to perform services for us, under contractual confidentiality and security obligations.
We do not list individual sub-processors in this Privacy Policy. A current sub-processor list is available to customers under a Data Processing Addendum on request (see Section 8).
B. Hosts and Workspaces
Customer workloads — including Serverless and shared-model inference — may run on GPU Capacity supplied by third-party Hosts; Hosts are contractually restricted from accessing Customer workloads/data except as necessary to operate their hardware, and inference content is not written to Host-accessible logs on shared deployments (see Section 4). Within a Workspace, account, usage, billing, and content metadata may be visible to the Workspace owner, billing member, administrators, and authorized collaborators.
C. Legal, safety, and corporate transactions
We may disclose information to comply with law or lawful requests; to enforce our Terms; to detect, prevent, or address fraud, abuse, security, or technical issues; to protect the rights, property, and safety of Meshive, our users, Hosts, and others; and in connection with a merger, acquisition, financing, restructuring, sale of assets, or bankruptcy.
D. With your direction or consent
We share information where you direct us to (for example, delivering outputs to your own storage) or where you otherwise consent.
8. Data Processing Addendum (DPA)
Where Meshive processes personal information as a processor on your behalf (for example, personal data contained in your User Content or end-user data you process through the Services), our processing is governed by a Data Processing Addendum. Business and EEA/UK customers who require a signed DPA (incorporating the EU Standard Contractual Clauses and UK Addendum where applicable) may request one at [email protected].
9. International Data Transfers
Meshive is operated from the United States, and we and our sub-processors may process your information in the United States and other countries. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (and, where applicable, certification under the EU-U.S./UK/Swiss Data Privacy Framework). You may request more information about these safeguards using the contact details below.
10. Data Retention
We retain personal information for as long as reasonably necessary for the purposes in this Privacy Policy, and then delete or de-identify it. Notable retention behaviors include:
- Account data: retained while your account is active and for a reasonable period afterward for legal, billing, dispute-resolution, fraud-prevention, audit, and security purposes
- Compute data on credit depletion: when your balance reaches zero, workloads are stopped and ephemeral storage is discarded; persistent volumes are deleted after a grace period of approximately seven (7) days (with a warning email at ~3 days) — see Terms of Service, Section 8
- Managed Serverless artifacts: retained for a limited default period (approximately ten (10) days) and then automatically deleted; content you direct to your own storage is retained by you
- Inference request/result records: retained to provide request tracking and delivery, subject to operational limits (e.g., limited stored request-body size, capped delivery logs)
- LLM inference content (including shared models): prompts and completions for synchronous text inference are not persisted after the request completes; per-request usage metadata (token counts, model, timing, status) is retained for billing, settlement, and audit
- Playground/temporary keys: short-lived (e.g., approximately 30 minutes)
- Abuse-prevention records: to prevent repeat abuse of sign-up bonuses and referral rewards, we may retain a minimal record (such as an email address and grant timestamp) even after account deletion
- Billing/tax records: retained as required by applicable financial and tax law
11. Your Rights and Choices
Depending on where you live, you may have some or all of the following rights, subject to legal limits and verification:
- Access the personal information we hold about you, and obtain a copy
- Rectify inaccurate or incomplete information
- Delete personal information (“right to be forgotten”)
- Restrict or object to certain processing (including processing based on legitimate interests)
- Data portability for certain information
- Withdraw consent where processing is based on consent
- Opt out of certain communications and of analytics/cookies
- Lodge a complaint with a competent supervisory authority
To exercise rights, contact us at [email protected]. We may verify your identity before responding and may decline or limit requests where permitted by law. We will not discriminate against you for exercising your rights.
12. U.S. State Privacy Rights (including California)
If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have rights to know/access, correct, delete, and obtain a portable copy of your personal information, and to appeal a denial. The categories of personal information we collect, and the purposes for which we use and disclose them, are described in Sections 3, 5, and 7.
We do not “sell” personal information for monetary consideration, and we do not use or disclose sensitive personal information for purposes that require an opt-out. To the extent any “sharing” for cross-context behavioral advertising occurs through analytics cookies, you may opt out via your cookie/browser controls. You may designate an authorized agent to make a request on your behalf, and we will not discriminate against you for exercising your rights.
13. Notice for the EEA, UK, and Switzerland
If you are in the EEA, UK, or Switzerland, the controller is Steppod, LLC (Section 1). Our legal bases are described in Section 6, and your rights (including the right to lodge a complaint with your local supervisory authority) in Section 11. International transfer safeguards are described in Section 9.
14. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including encryption of stored secrets such as connected storage credentials, hashing of passwords and API keys, access controls, and tenant isolation. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and keys and the content you upload, and for maintaining your own backups (see Terms of Service, Section 11).
15. Children's Privacy
The Services are not directed to children and are not intended for individuals under 18. We do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided us personal information, contact [email protected] and we will take appropriate steps to delete it.
16. Third-Party Services
The Services integrate with third-party services (authentication, payments/payouts, analytics, infrastructure, storage, networking, model hubs, and compute providers). We are not responsible for the privacy practices of third parties, and we encourage you to review their policies. Third-party model and dataset licenses and privacy terms are your responsibility.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on meshive.ai and revise the “Last Updated” date, and we may notify you of material changes through the Services. Your continued use after the effective date constitutes acknowledgment of the updated Privacy Policy.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
