Legal
Privacy Policy
Last Updated: August 18, 2026
IOMESH Technology Ltd. (“I/O Mesh,” “we,” “us,” or “our”) operates the website iome.sh, the I/O Mesh console at console.iome.sh, and the related hosted services (collectively, the “Services”). This Privacy Policy describes how we collect, use, disclose, and protect personal information in connection with the Services.
This Policy applies to the website and the hosted Services. Our open-source local tools (including iomesh-tui, the memory kernel, client SDKs, and related components) run on infrastructure under your control. Data that remains entirely local is governed by you and is outside the scope of this Policy.
We are based in Vancouver, British Columbia, Canada.
1. Who is responsible for your information?
IOMESH Technology Ltd. is the controller of personal information that we collect about account holders, website visitors, and for our own business operations (account, billing, support, and usage data).
For Customer Content—the operational events, knowledge, documents, metrics, and other data that you or your organization publish into the mesh via connectors, APIs, or the console—we act as a processor (or service provider) on your behalf under the applicable customer agreement and, when executed, a Data Processing Addendum (DPA) available upon request or as part of the commercial agreement. You remain the controller of that data and determine the purposes and means of its processing. This site does not publish a live DPA.
Privacy inquiries: privacy@iome.sh
Security vulnerability reports: security@iome.sh
2. Information we collect
Account and profile information
When you create an account, subscribe, or communicate with us we collect name, email address, company or organization name, role or title, account preferences, and related contact details.
Billing and payment information
We collect the information necessary to process subscriptions and invoices. Payment card details are handled by our third-party payment processor; we receive limited confirmation, invoice, and billing-contact data.
Technical and usage data
We automatically collect IP address, browser and device information, approximate location derived from IP address, log data (access times, pages or features viewed, errors), and usage metrics required for billing and operation (storage volume, publish/pull volume, event counts, MCP invokes, and similar meters).
Customer Content
When you connect sources (for example GitHub or other tools via OAuth) or publish data to streams, we process the operational data, events, documents, and metadata that you choose to send. This data may contain personal information of your employees, customers, or other individuals that appears in tickets, incidents, deploys, runbooks, or related records. We process Customer Content solely to provide the Services under your instructions and configuration.
Communications
Support requests, feedback, and other correspondence you send to us.
Cookies and similar technologies
We use cookies and similar technologies that are necessary for authentication, security, and core functionality. We do not currently operate a published analytics-pixel inventory or a Cookie Notice. If we add non-essential analytics cookies, we will update this Policy to describe them.
We do not knowingly collect personal information from children under 16 years of age (or the applicable age of digital consent in the relevant jurisdiction).
3. How we use information
We use personal information to:
- Provide, operate, maintain, secure, and improve the Services;
- Process payments, manage subscriptions, and enforce usage limits;
- Authenticate users, enforce access controls, maintain department-scoped tenancy, and apply policy gates (including for MCP tools);
- Monitor security, detect and prevent fraud or abuse, and protect the integrity of the platform;
- Respond to support requests and communicate with you about the Services;
- Comply with legal obligations and enforce our agreements; and
- Analyze aggregated or de-identified usage data to improve the product.
We do not sell personal information in the ordinary sense of exchanging it for money. This Policy is not a CCPA/CPRA “Do Not Sell or Share” module. We do not use Customer Content to train general-purpose or shared foundation models.
4. Legal bases for processing
We are based in Canada. Where Canadian privacy law applies (including PIPEDA and BC PIPA), we collect, use, and disclose personal information for the purposes described in this Policy, with your knowledge and for purposes that a reasonable person would consider appropriate in the circumstances.
PIPEDA is not a “legitimate interests” statute. GDPR Article 6 vocabulary and CCPA/CPRA modules apply only if and when those laws apply to us (for example, if we offer the Services to people in the EEA/UK or meet a U.S. state “business” threshold). Until then, this section is Canada-first and is not a live GDPR or CCPA notice pack.
- Canadian law: identified purposes, knowledge and consent (including implied consent where appropriate), and legal obligation;
- If GDPR applies later: the additional bases required in that jurisdiction (which may include contract, legitimate interests, consent, or legal obligation); and
- If a U.S. state privacy law applies later: the rights and notices that law requires.
5. How we share information
We share personal information only as necessary and under appropriate safeguards:
- With service providers and processors that assist us in operating the Services (cloud infrastructure and hosting, payment processing, email delivery, and security tooling). These parties are bound by contracts that limit their use of the data to the services they perform for us.
- With our payment processor for subscription billing. We do not store full payment-card numbers.
- With professional advisors, auditors, or in connection with a corporate transaction, subject to confidentiality obligations.
- When required by law, legal process, or to protect the rights, safety, or security of I/O Mesh, our users, or the public.
- With your direction or consent.
Customer Content is isolated by tenancy and policy controls and is not shared across customers.
6. International transfers
We may process personal information in Canada, the United States, or other countries where our service providers operate. Where a transfer restriction applies, we will use a lawful transfer mechanism appropriate to that transfer. This Policy does not claim that Standard Contractual Clauses are already executed with every processor.
Personal information hosted with those providers may be subject to the laws of the countries where they operate, including access by foreign courts or law-enforcement authorities. This Policy does not publish a subprocessor list, named hosting regions, or a live Data Processing Addendum.
7. Retention
We retain Account and billing information for as long as your account remains active and thereafter as needed for billing, legal, tax, or security purposes. Technical and usage logs are retained for shorter operational periods. Customer Content is retained according to your configuration and the terms of the applicable agreement; upon termination or verified request we delete or return it within a commercially reasonable period, subject to backup cycles and any legal holds.
8. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest, department-scoped tenancy and policy-gated access, role-based access controls, audit logging, monitoring, secure development practices, and vulnerability management. Enterprise options include customer-controlled encryption keys (BYOK) on supported paths. We do not process protected health information (PHI) without a signed Business Associate Agreement.
No method of transmission or electronic storage is completely secure. Additional detail is available on our Security page.
9. Your rights and choices
Depending on your location, you may have the right to:
- Access, correct, or delete personal information we hold about you;
- Receive a portable copy of certain data;
- Restrict or object to certain processing;
- Withdraw consent where processing is based on consent; and
- Lodge a complaint with a supervisory authority (for example, the Office of the Privacy Commissioner of Canada or your local data-protection authority).
To exercise these rights, contact privacy@iome.sh. We will verify your identity and respond within 30 calendar days of a verified request, or a longer period permitted by applicable law if we notify you of the extension. Requests concerning Customer Content should be directed first to the relevant customer organization, which acts as controller; we will assist under the customer agreement and any executed DPA.
You may update many account details directly in the console.
10. Changes to this Policy
We may update this Privacy Policy from time to time. The revised version will be posted with an updated “Last Updated” date. For material changes, including new purposes, we will provide additional notice (for example, by email or in-console notification). Continued use is not treated as consent to a new purpose.
11. Contact
Privacy questions and data-subject requests: privacy@iome.sh
Security vulnerability reports: security@iome.sh
IOMESH Technology Ltd. Vancouver, British Columbia, Canada
Enterprise customers may obtain a Data Processing Addendum upon request or as part of the commercial agreement.