Privacy Policy
Last updated: August 2, 2026
On this page
IndexMesh Private Limited (CIN U62013KL2026PTC105133) is incorporated as a private limited company in India, based in Kochi, Kerala. This policy covers the website at indexmesh.ai and IndexMesh for WordPress, our free plugin. We are a two-person team, and we have written this policy to say plainly what that small a team actually collects and does, rather than describing processes we don't run.
The short version
We collect very little, we sell nothing, and the WordPress plugin is designed to send us no data at all.
This website
For everything in this section, IndexMesh is the controller: we decide why and how the data is used. The only personal information the website could collect is what you choose to give us, an email address and whatever you write (the contact form also takes your name, a subject if you choose one, and the page you wrote from), through the contact form, the notify list, or a direct email. We collect it so we can reply to you and, for the notify list, so we can tell you when there is something to notify you about. Everything else below (analytics, server logs) is aggregate and not collected to identify you.
Forms
Two vendors touch a form submission: Cloudflare, which runs the worker that receives it, and Brevo (France), which sends the email and, for the notify forms, holds your address.
Notify forms, get notified about the closed beta, get notified when Mesh AI opens, and get IndexMesh for WordPress release news, use double opt-in. Submitting one sends a confirmation email and adds nothing anywhere. Only clicking the link in it adds your address to the list; that click is your consent record. Unsubscribing removes you, and Brevo does not let us reinstate an unsubscribed or blocklisted address.
The contact form is different: it collects your name, your email address, the subject you choose if you choose one, your message, and the page you sent it from. It is relayed once, through Brevo, to our inbox, your address set as reply-to, so we can reply and keep a record of the conversation. No Brevo contact is created and nothing is added to any list.
Both also check for spam using a salted hash of your IP address, never the address itself, held up to an hour (notify) or a day (contact), then gone.
Analytics
We use Cloudflare Web Analytics. A short script served from Cloudflare's own domain counts page visits without setting cookies, without following you across other websites, and without building a profile of you. We also use Google Search Console, which reports how our pages perform in Google search results and collects nothing from you as a visitor.
We do not use Google Analytics, Google Tag Manager, advertising pixels, or any behavioural tracking. That is a deliberate choice, not an oversight.
Cookies
This site sets no cookies. There is no consent banner because there is nothing to consent to.
Server logs
Our host, Cloudflare, records standard request logs including IP address, in the ordinary course of serving the site, separately from the analytics script above. We do not use either to identify or track individuals.
The IndexMesh WordPress plugin
The plugin is designed to run entirely on your own WordPress site. By design, it does not send data to IndexMesh or to any third party. There is no account, no API key and no external service. Because nothing comes to us, we are not a controller or a processor of your site visitors' data today, and there is no data flow here for a rights request to reach.
The plugin does make network requests, and it is worth being precise about them. It requests your own robots.txt, llms.txt, sitemap and homepage, the same way a search crawler would, so it can confirm those files are actually being served. Those requests go to your own domain and nowhere else.
Settings and diagnostics are stored in your own WordPress database. Uninstalling removes them.
If that ever changed, and the plugin sent any data to us, our role toward your site visitors' information would be as a processor acting on your instructions as the site owner, not as a controller in our own right, and we would say so plainly here before it shipped rather than after.
Vendors and subprocessors
For the website data described above, here is every vendor and every third-party destination we use, by purpose:
- Cloudflare — hosting, edge analytics, the spam-limiting hash above.
- Brevo (France) — double opt-in and list for the notify forms, relay for the contact form.
- Google Workspace — the mailbox a relayed contact message, or an email you send us directly, lands in.
- Google Search Console — search-performance reporting for us as the site operator. It does not collect anything from you as a visitor, and it is not a processor of anything you submit through a form.
We also link to WhatsApp and Telegram from the phone number on this page. Both are independent messaging services. If you write to us through either, that conversation runs on that service's own systems, under its own terms, not this policy.
We do not use a CRM beyond the notify lists above, an advertising vendor, or an error-monitoring service today. If that changes, the new vendor will be named here in the same commit that connects it.
The WordPress plugin does not use any vendor on your behalf, because it does not send your site's data anywhere, including to us.
International data transfers
IndexMesh is based in India. Cloudflare's edge network serves this site from whichever location is closest to you, so request logs are generated wherever that happens to be. Brevo, our vendor for the notify and contact forms, hosts its databases in the EU; we access that database from India. A contact-form relay or a direct email also reaches Google Workspace. We're still filling in subprocessor and support-access facts for each vendor in our internal register, and we treat the EU as its own transfer regime. We haven't put a transfer safeguard like Standard Contractual Clauses in place, because none is needed yet. If that changes, we'll put one in place first and say so here.
How long we keep it
We do not currently have a formal data-retention schedule with fixed periods for each category, and we would rather say that plainly than invent a number of days that doesn't reflect how a two-person team actually operates. In practice: a notify-form address is kept on the relevant Brevo list until you unsubscribe or ask us to delete it. A contact-form message is kept as email correspondence for as long as it remains a useful record, and deleted when it no longer is. Brevo, which relays the form, keeps a delivery log of each relay, showing the recipient, subject and time but not the message text, for 12 months and then deletes it automatically. The salted IP hash used for spam limiting expires automatically within a day at most and is never extended. Aggregate analytics and server logs are not linked to individuals, so we do not set an individual retention period for them. Settings the plugin stores live in your own WordPress database, under your control, until you uninstall it.
Security
We take reasonable technical and organisational steps to protect the little information we hold, including relying on our host's infrastructure security rather than running our own servers. No method of transmission or storage is completely secure, and we are not going to promise otherwise. If we become aware of a security incident affecting information we hold about you, we will tell you and report it to the relevant Indian authorities as required by law.
Your rights
You can ask what personal data we hold about you, ask us to correct it, or ask us to delete it. Email hello@indexmesh.ai and we will respond within thirty days. If you are on a notify-form list and only want to stop hearing from us, the unsubscribe link in any email from us does that immediately, without needing to write in.
If you are in India: the Digital Personal Data Protection Act, 2023 was notified in November 2025, and its core operative provisions, notice, consent and the rights described above, are scheduled to commence on 13 May 2027. Until then, we offer these rights as a matter of company practice, not yet as an obligation the Act itself enforces. This same email address also serves as our grievance and redressal contact for Indian visitors. We are a two-person team without a separately designated grievance officer, but every message sent there reaches us directly, and we aim to acknowledge it within a few days.
If you are in the EU: whether GDPR applies to us depends on facts that are still moving, like where our plugin actually gets used, so we're not making that call either way right now. We'll revisit it as that picture becomes clearer. In the meantime we'll honour a GDPR-style request the same way we handle any other: you want to know what we hold and control it, and that's worth answering no matter which law is doing the asking.
Full detail, including lawful basis, retention and how to complain, is on your data rights.
Children's privacy
This site and the plugin are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has sent us data, for example by emailing us, contact us and we will delete it.
Changes
If this policy changes we will update the date above. If a change is significant, particularly connecting the forms to a provider, we will say so plainly rather than quietly editing.
