MeshHold
Solutions Docs Community Support
Download

Privacy Policy

How Iurii Iakovlev handles personal data collected through this website and forum.

Version 2026-09-04 · effective 2026-09-04
  • 1. Who is responsible
  • 2. What data we process
    • When you visit the public site
    • When you register an account on the forum
    • When you use the forum
    • What we explicitly do NOT collect
  • 3. Why we process it (legal bases)
  • 4. How long we keep it
  • 5. Who else sees it (processors)
  • 6. International transfers
  • 7. Your rights
  • 8. Cookies and similar
  • 9. Security
  • 10. Changes to this policy
  • 11. Complaints

1. Who is responsible

MeshHold is a personal open-source project, operated as a private project by Iurii Iakovlev, a natural person resident in Novi Sad, Serbia. There is no corporate entity behind this site at the time of writing.

Under GDPR Article 4(7), the data controller is therefore the individual operator listed above. Contact for all data-protection matters: meshhold@gmail.com. No formal Data Protection Officer is appointed — our processing scale does not require one under Article 37 GDPR, and the contact email routes directly to the operator.

2. What data we process

When you visit the public site

  • Your IP address (kept in webserver access logs).
  • Your browser's User-Agent string.
  • The URL you requested, the timestamp, and the HTTP status returned.
  • Your language preference (set via the language switcher) — stored in a cookie so the site remembers it.
  • Visit statistics, counted on this server. When a page loads, a small script on this site reports the page path, the referring site, your browser's language preference, and nothing else. From your IP address we derive a country using a database held locally on our own server, and the address itself is then discarded — it is never written down. The same is true of your User-Agent: we keep only a coarse family ("mobile", "firefox", "linux"), never the string. These become daily totals, so no record of an individual page load survives. Nothing is stored on your device, no third party is involved, and DNT/Sec-GPC are honoured — send either and nothing at all is counted.

When you register an account on the forum

  • Your email address — required for account verification and password reset.
  • Your chosen username — displayed publicly with your posts.
  • A salted hash of your password — we never see the plain password.
  • The date you accepted the Privacy Policy and Terms of Service, and the version you accepted (audit log of consent).
  • Optionally: a short bio and an avatar URL, if you choose to add them.

When you use the forum

  • The content you post (threads, replies, edits).
  • Likes you give or receive.
  • Notifications addressed to you (replies, mentions).
  • Your trust level, post count, last-seen timestamp — derived from your activity.
  • If you upload files as attachments: the file content and filename.

What we explicitly do NOT collect

  • No third-party analytics. Visit statistics are counted by this server and leave it for nobody. We used Google Analytics until September 2026 and removed it.
  • No advertising trackers, no ads, no Facebook Pixel, no Hotjar, no session recording.
  • No analytics cookie and no analytics identifier on your device. Whether two page loads came from the same visitor is decided on our server from a value salted with a random number that is destroyed after two days, which makes yesterday's visitors unlinkable to today's — by us as much as by anyone else.
  • No cross-site tracking of any kind. The cookies we use are listed on the Cookies page, and none of them is for analytics.

3. Why we process it (legal bases)

Purpose Legal basis (GDPR Article 6)
Providing the forum service to you 6(1)(b) — performance of a contract you entered into by registering
Sending account-related email (verification, password reset, reply notifications) 6(1)(b) — performance of a contract
Keeping webserver access logs for security and abuse investigation 6(1)(f) — legitimate interest in service integrity
Storing your consent decisions (audit log) 6(1)(c) — compliance with our own GDPR obligation to demonstrate consent
Optional bio / avatar fields you choose to fill in 6(1)(a) — your consent (you can blank them at any time)
Counting visits in daily aggregate, with no identifier stored on your device 6(1)(f) — legitimate interest in knowing which pages are read. No consent is sought because nothing is stored on or read from your device; you can object under Art. 21, and sending DNT or Sec-GPC is treated as doing so

4. How long we keep it

Data Retention
Account profile + posts For the lifetime of your account. You can request deletion at any time (see your rights below).
Webserver access logs 30 days, then rotated and discarded.
Consent records For the lifetime of your account (the IP and User-Agent on the record are scrubbed after 90 days; the consent decision itself remains for legal-proof purposes).
Account marked for deletion Soft-deleted immediately; hard-deleted 30 days later. During the grace period you can log back in to cancel the deletion.
Database backups Encrypted, rotated weekly, kept for 28 days, then destroyed. A deleted account disappears from backups within the rotation window.

5. Who else sees it (processors)

We use the following third-party processors. Each is bound by a data-processing agreement (DPA) under GDPR Article 28.

  • netcup GmbH — Emmy-Noether-Str. 10, 76131 Karlsruhe, Germany. Hosting infrastructure (server, storage, network) located within the European Union. They do not access your data; they provide the hardware. Data Processing Agreement signed under GDPR Article 28. That is the entire list. There is no analytics processor: visit statistics are counted by the same server that serves the page.

We do NOT sell your data or share it with advertisers, and we do not share it with third parties for marketing. If we ever add another processor (e.g., a transactional-email service), we will update this list before doing so.

6. International transfers

Core processing — hosting, the forum database, and server logs — takes place inside the European Union on netcup GmbH infrastructure in Germany. The data controller (the operator) is resident in Serbia; under GDPR this is treated as processing within the EU/EEA framework via the adequacy decisions and Standard Contractual Clauses where applicable.

There are no transfers outside the EU/EEA. Until September 2026 visit statistics went to Google LLC in the United States; that was removed, and with it the only transfer this site made. If core processing ever moves to a third country without an adequacy decision, we will rely on Standard Contractual Clauses and update this policy.

7. Your rights

As a data subject under GDPR, you have the following rights:

  • Access (Art. 15) — see what data we hold on you. The Your data page in your account shows it directly.
  • Portability (Art. 20) — download a machine-readable export of your data. Available at Export your data.
  • Rectification (Art. 16) — correct inaccurate data. Edit your profile from the forum settings; for data you cannot edit yourself, email us.
  • Erasure (Art. 17) — delete your account and associated data. Use Delete your account or email us.
  • Restriction (Art. 18) — ask us to suspend processing of your data while a dispute is resolved.
  • Objection (Art. 21) — object to processing based on legitimate interest (item 6(1)(f) in the table above).
  • Withdraw consent (Art. 7(3)) — for processing based on consent (item 6(1)(a)), without affecting prior processing's lawfulness.

For any of these requests, email meshhold@gmail.com. We respond within 30 days (extendable by 60 days for complex requests, with notice).

8. Cookies and similar

We use strictly-necessary cookies only: session, CSRF, and your language preference. No analytics cookies, no advertising or social-media cookies, and nothing that needs a consent banner — which is why this site no longer shows one. Full list: Cookie Policy.

9. Security

Technical and organisational measures (TOMs) in place:

  • HTTPS-only (HSTS, modern TLS).
  • Passwords stored as PBKDF2 hashes (Django default), never plaintext.
  • CSRF tokens on every state-changing form.
  • Database backups encrypted at rest.
  • Access to production infrastructure restricted to operators with multi-factor authentication.
  • Security updates applied promptly; we follow CVE feeds for Django and Python.

If you discover a security issue, please email meshhold@gmail.com before disclosing publicly. We commit to acknowledge within 72 hours.

10. Changes to this policy

The current version is 2026-09-04. When we change anything material, we bump the version, update the effective date at the top, and notify registered users by email. The next time you log in, you will be asked to acknowledge the new version before continuing.

11. Complaints

You always have the right to lodge a complaint with a supervisory authority (GDPR Art. 77). Our lead supervisory authority is Commissioner for Information of Public Importance and Personal Data Protection (Poverenik). EU residents may also file a complaint with their local data-protection authority.

Plain-language summary: We collect what we need to run a forum (email, username, password hash, your posts). We don't share it with anyone. We count how many people read which page, on our own server, in daily totals with your address thrown away and nothing stored on your device — so there is nothing to consent to and no banner to click. You can see, export, or delete your data at any time from your account page, or by emailing meshhold@gmail.com.


Questions about this document? Email meshhold@gmail.com.

MeshHold

A decentralized, self-hosted private cloud and mesh network. AGPL-3.0.

Product

  • Downloads
  • System requirements
  • Release archive
  • Documentation
  • Solutions
  • For Business

Resources

  • Comparisons
  • FAQ
  • Roadmap
  • Blog

Community

  • Forum
  • Blog

Company

  • About
  • Contact
  • Partners
  • Support
  • Security

Project

  • Architecture spec
  • Report a vulnerability
  • License (AGPL-3.0)

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use
  • Imprint
© 2026 MeshHold contributors.
Built with libp2p, Go, and a refusal to centralise.