Skip to content
MeshTalkerMeshTalker
EnglishFrançaisEspañolItalianoPortuguêsРусский中文日本語Deutschالعربيةहिन्दीRomână
Home

Contents

  • Data controller and scope
  • Data minimization and privacy by design
  • Content of communications
  • Data stored locally
  • Certificates, identifiers and technical metadata
  • Network data and technical logs
  • Store and payment
  • Purposes and legal bases
  • Recipients and service providers
  • International transfers
  • Retention and deletion
  • Security
  • Cookies, trackers and browser storage
  • Your rights
  • Changes to the policy

Privacy Policy

Last updated: August 9, 2026

The French version is the reference version. Translations are provided to facilitate international access; in the event of any difference in interpretation, the French version shall prevail, subject to any applicable mandatory rules.

Data controller and scope

Blocnet SASU, 43 Rue des Picards, 77750 Orly-sur-Morin, France, is the controller for the processing it determines for the MeshTalker website, store and service. Contact: contact@blocnet.fr.

This policy describes the processing identifiable in the store repository as well as the principles communicated for the MeshTalker application and infrastructure. It applies without prejudice to any additional information that may be provided in the application or during a particular operation.

Data minimization and privacy by design

MeshTalker applies a logic of data minimization and protection by design. The architecture is designed without a central archive database of conversations. This does not mean that Blocnet processes no data: technical, cryptographic, network and transactional data may be necessary for operation, security, certificates, payments and legal obligations.

Content of communications

Conversations and exchanged files are designed to be protected by end-to-end encryption and stored on users’ devices, in protected form, rather than in a centralized history used by Blocnet. Blocnet is not intended to access their plaintext content.

Messages or attachments may nevertheless transit, be routed or be temporarily relayed by the infrastructure when delivery requires it. Encryption does not eliminate all technical processing and does not exempt Blocnet from its legal obligations.

Data stored locally

Depending on the features used, messages, attachments, preferences, keys, secrets, certificates, recovery means and histories may remain exclusively on the device. Blocnet does not receive those elements merely because of their local storage.

Deleting the application, losing or compromising the device, or losing a local secret may make encrypted data or access unrecoverable where no available backup or recovery mechanism has been used.

Certificates, identifiers and technical metadata

Depending on the features used, the service processes member, device, intent and issuance identifiers, certificate fingerprints and requests, signatures, room preferences, rights or memberships, download tokens and technical statuses. These elements are not considered anonymous when they can be linked directly or indirectly to a person.

Certain metadata or cryptographic events necessary for identification, security, rights and continuity may appear in immutable technical logs and be replicated between nodes of the distributed infrastructure. This replication does not constitute replication of the plaintext content of conversations.

Network data and technical logs

During Internet requests, Netlify, Hetzner, backend services or network intermediaries may technically receive the IP address, dates and times, request information, security data and information about the application, browser or device, to the extent necessary for providing, diagnosing and protecting the service.

The repository does not make it possible to establish precise retention periods for these logs. They are determined according to operational and security necessity, providers’ configurations and legal obligations, then deleted or made non-identifying when retention is no longer necessary.

Store and payment

The store workflow sends to the MeshTalker backend the technical identifiers, certificate information, room preferences and signed elements necessary for pre-registration. Stripe Checkout processes banking data in its own environment. The code does not show that Blocnet stores full card numbers.

Blocnet receives or transmits the necessary transactional information: payment session and intent identifiers, amount, currency, payment status, payment date, selected package and delivery metadata. Netlify functions do not have a persistent database of their own; they communicate with Stripe and the MeshTalker backend to confirm payment and deliver the certificate.

Purposes and legal bases

Data are processed to provide conversations and rooms, authenticate connections and certificates, manage members and rights, route communications, secure and diagnose the service, perform purchases, deliver products, respond to requests and comply with the law.

Depending on the processing, the legal bases are: performance of the contract or pre-contractual measures; Blocnet’s legitimate interest in securing, maintaining and reasonably improving the service; compliance with a legal obligation, in particular accounting obligations or responses to competent authorities; and consent only where it is expressly requested for a specific processing activity.

Recipients and service providers

Data are accessible only to authorized persons at Blocnet and to service providers that need them for their mission: Netlify for the frontend and store functions, Stripe for Checkout and payment, and Hetzner for backend virtual machines. Each provider also processes certain data under its own responsibility when it determines its own purposes, in accordance with its policy.

Information may be disclosed to authorities or advisers where required by law, to defend rights or to handle an incident. They are not intended to be sold.

International transfers

Given the global scope of the service and the providers used, some data may be accessible or processed outside France or the European Economic Area. Where the GDPR requires it, Blocnet must rely on a recognized transfer mechanism and appropriate safeguards. The precise locations and mechanisms depend on the services and configurations actually chosen by each provider.

Retention and deletion

Operational data are kept for the period necessary for the relevant purpose, security, contractual performance and legal obligations. The repository does not confirm quantified retention periods; accordingly, no specific period is invented in this policy.

A request for erasure is assessed according to the nature and location of the data. Blocnet cannot erase data that remain solely on the user’s device. Certain immutable cryptographic events or legally required supporting records may not be materially deletable; where the law permits, their use may be limited and the associated operational data deleted or dissociated.

Security

MeshTalker implements protections suited to its architecture, including encryption, certificates, authentication of technical communications and limitation of centralized data. The user must also protect their device, secrets and access credentials. No measure guarantees absolute security against every attack, loss or compromise.

Cookies, trackers and browser storage

Review of the repository does not reveal any analytics tool, advertising pixel or marketing tracker, nor any cookie set by the frontend code. No fictitious consent banner is therefore added.

The site uses the browser’s local storage (localStorage) only to remember the selected language under the key “meshtalker_lang”. This functional mechanism is not a cookie and is not used in the code to track the user across services. Stripe and app stores, once visited, apply their own policies and mechanisms.

Your rights

Subject to the legal conditions, you may request access, rectification, erasure, restriction, object to processing, request portability, and withdraw consent at any time without affecting the lawfulness of prior processing. You may also define instructions relating to your data after your death where French law provides for this.

Send your request to contact@blocnet.fr, specifying the right exercised and the information that makes it possible to identify the relevant data. Proportionate proof of identity may be requested in case of reasonable doubt. You may lodge a complaint with the CNIL (cnil.fr) or with the competent authority in your place of residence.

Changes to the policy

This policy may evolve to reflect the service, service providers or applicable law. The update date is displayed at the top of the page. Enhanced notice will be provided when the nature of a change requires it.

Legal NoticePrivacy PolicyTerms of Service
© 2026 MeshTalker. All rights reserved.Legal NoticePrivacy PolicyTerms of Service