Privacy Policy
Effective date: 7 August 2026
This Privacy Policy explains how Meshlyr ("we", "us", "our") collects, uses, stores and discloses personal information, and how we handle the cloud configuration metadata we discover from the AWS accounts and GCP projects you connect. We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
Meshlyr is operated by Whakaata Pty Limited (ABN 42 666 915 555).
1. What we collect
Account and identity information
Your name, email address, a securely hashed password (managed by AWS Cognito), and your organisation or tenant and role within Meshlyr.
Cloud environment metadata
When you connect an AWS account or a GCP project or organisation, Meshlyr performs read-only discovery of the configuration and metadata of the resources in that environment. This includes networking, compute, container, storage, database, identity structure, DNS, edge and security configuration, infrastructure-as-code stacks, security findings, cost and billing data, and the relationships between resources. We also store point-in-time snapshots and change or drift history so the map stays current over time.
Usage and technical data
IP address, browser and device information, log data, and interaction analytics collected through Google Analytics (via Google Tag Manager). Our analytics uses generic view names only and does not include resource identifiers, account contents or personal data.
Communications
Records of enquiries you submit (such as name, email, mobile number and message), account access requests, and support correspondence.
Payment card details, if and when paid plans are offered, are handled by a third-party payment processor and are not collected or stored by us directly.
2. What we do not access
Meshlyr is a metadata and configuration tool. When discovering your connected cloud accounts, we do not:
- read the contents of your data stores (no object or file contents, no database rows, no message payloads);
- read secret values (we never retrieve Secrets Manager or Parameter Store values, private keys, or credentials);
- access your application or end-user data.
Configuration values that look like secrets are masked before they are stored or displayed. Our access is read-only, and we never modify resources in your cloud.
3. How we use it
We use the information above to operate and provide the service, which includes discovering and mapping your resources and computing derived views such as blast radius, cost attribution, drift and business impact; to authenticate you and secure the platform; to send transactional and service notifications; to respond to your enquiries; to maintain, troubleshoot and improve the service; and to meet our legal obligations. We do not sell your personal information.
4. AI features and processing
Some optional features (the in-app assistant, the cost advisor, and relationship review) use a third-party AI model to generate advisory suggestions. When these features are enabled by your operator, Meshlyr sends a compact, pre-computed summary of resource configuration, cost and topology to Anthropic (the provider of Claude) to produce those suggestions. Configuration values that look like secrets are masked before they are sent, and only resource identifiers and configuration already present in your graph are included. These features are optional, advisory, and never take action on your cloud automatically. Anthropic acts as a subprocessor and may process this data outside Australia (for example, in the United States).
5. Cookies and analytics
We use a strictly necessary session cookie to keep you signed in. We also use Google Analytics and Google Tag Manager to understand aggregate usage; you can block these with browser controls or an ad or tracker blocker without affecting core functionality.
6. Where your data is stored
Your account data, discovery snapshots and registry are hosted on Amazon Web Services in the Asia Pacific (Sydney) region, in Australia. Some limited processing occurs internationally through the subprocessors listed below (for example, AI processing by Anthropic and analytics by Google).
7. Sharing and subprocessors
We share data only with service providers who help us run Meshlyr, under confidentiality obligations, and only as needed to provide the service:
- Amazon Web Services: hosting, storage, authentication (Cognito) and email delivery (SES).
- Anthropic: optional AI features, as described above.
- Google: website analytics.
We may also disclose information where required by law or to respond to a valid request from law enforcement or a regulator. We do not sell your personal information.
8. Security
We integrate with your cloud using least-privilege, read-only access: AWS via a role you create that trusts only our control plane and is scoped with a unique ExternalId (guarding against confused-deputy misuse), and GCP via keyless Workload Identity Federation, so no long-lived service-account keys are created or stored. We do not read secret values. We encrypt data in transit and at rest, hash passwords, isolate tenants, and apply access controls. You can revoke our access at any time by removing the read-only role or the federation configuration, which stops further discovery. No system is completely secure, and we cannot guarantee absolute security.
9. Retention and deletion
We retain your account data and discovery snapshots for as long as your account is active and as needed to provide the service. Change and drift history is pruned on a rolling basis (by default, to 90 days). When you close your account or disconnect an environment, we delete the associated discovered data within a reasonable period, after which residual copies cycle out of routine backups. We may retain limited records where required for legal compliance.
10. Your rights
You may request access to, or correction or deletion of, the personal information we hold about you by contacting us at support@meshlyr.com. We will respond within a reasonable time.
11. Complaints
If you have a privacy concern, please contact us first and we will try to resolve it. If you are not satisfied, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
12. Changes
We may update this Privacy Policy from time to time. Material changes take effect when the updated policy is posted on this page, and we will update the effective date above.
13. Contact
Questions about this policy or your data can be sent to support@meshlyr.com.