Skip to main content
MESAIGO
Platform
MesaiGo Platform

The phone, gateway, and server check together. Access and attendance decide separately.

Explore →
MesaiGo Platform Mobile, gateway, and server verify together How it works See how a transaction is verified in eight steps Standard profile Live BLE verification High Assurance Secure UWB and transaction approval Mobile app An enrolled phone with a focused experience Management platform Rules, devices, and reports for HR, security, IT, and managers
Solutions
Three solutions, shared verification

Manage access, attendance, and critical spaces on one platform.

Explore →
All solutions Choose the right product and gateway model for your needs Access control Doors, turnstiles, and controlled spaces Time and attendance From verified arrivals and departures to time records High-security spaces Vaults, server rooms, and critical zones
Hardware
Gateway family

The same protection rules from BLE to secure UWB.

Explore →
All gateway models Verify, Access Lite, Access, and Pro Verify WiFi + BLE verification point Access Lite WiFi, BLE, and field I/O Access Ethernet, NFC, and access I/O Access Pro Secure UWB High Assurance
Security
Security controls that are actually applied

We explain security through the controls in place, not badges.

Explore →
Security controls Attacks, applied controls, and server decisions for security teams Trust Center Security, data use, and service status Data and privacy No biometric templates or GPS tracking
Resources
Self-guided evaluation

Understand the system before requesting a demo.

Explore →
Resource center Technical overviews and buying guides Integrations API, webhooks, HR, and physical-system connections for IT teams Documentation Installation, usage, and troubleshooting Product consultation Evaluate your needs and installation site with us
EN
EN English TR Türkçe
Sign in Product consultation
Menu
Current language
EN English TR Türkçe
Platform
MesaiGo Platform Mobile, gateway, and server verify together How it works See how a transaction is verified in eight steps Standard profile Live BLE verification High Assurance Secure UWB and transaction approval Mobile app An enrolled phone with a focused experience Management platform Rules, devices, and reports for HR, security, IT, and managers
Solutions
All solutions Choose the right product and gateway model for your needs Access control Doors, turnstiles, and controlled spaces Time and attendance From verified arrivals and departures to time records High-security spaces Vaults, server rooms, and critical zones
Hardware
All gateway models Verify, Access Lite, Access, and Pro Verify WiFi + BLE verification point Access Lite WiFi, BLE, and field I/O Access Ethernet, NFC, and access I/O Access Pro Secure UWB High Assurance
Security
Security controls Attacks, applied controls, and server decisions for security teams Trust Center Security, data use, and service status Data and privacy No biometric templates or GPS tracking
Resources
Resource center Technical overviews and buying guides Integrations API, webhooks, HR, and physical-system connections for IT teams Documentation Installation, usage, and troubleshooting Product consultation Evaluate your needs and installation site with us
Product consultation Sign in to platform
  1. Home /
  2. MesaiGo Platform /
  3. Mobile app /
  4. Mobile app privacy
iOS and Android

Mobile app privacy policy

This policy explains which data the MesaiGo mobile app uses and why, the limits of device permissions, and how to submit access, correction, or deletion requests.

  • No tracking No advertising profile or cross-app tracking.
  • No GPS tracking Access and attendance decisions do not rely on precise GPS coordinates.
  • No biometric templates PIN and biometrics remain inside the device operating system.
Last updated: August 1, 2026
On this page Who this policy covers and who is responsible Categories of data processed Data we do not collect or use Device permissions and proximity technologies Purposes for using data Sharing, service providers, and transfers Retention and security Account, access-area, and data-deletion requests Children’s privacy Changes to this policy Contact

Who this policy covers and who is responsible

This policy covers the iOS and Android mobile apps published as MesaiGo, their communication with MesaiGo services, and the limited information stored on the phone. The corporate website explains its data use and privacy details on the separate Data Use and Privacy page.

MesaiGo is an enterprise workforce and physical-access product. A user membership is normally created and managed by the user’s employer or another authorized organization. The customer agreement and privacy notice state which organization is the data controller and which service acts as the data processor for that setup.

Categories of data processed

The app processes only the data categories required for device enrollment, physical proximity verification, access or attendance outcomes, employees’ access to their own records, and system security.

An organization-defined entry point or gateway can identify an exact physical workplace point. For App Store privacy disclosure, MesaiGo therefore treats entry-point information linked to a user as Precise Location, even though the app does not request iOS Location Services, collect GPS coordinates, or create background location history.

Identity and membership
The user or employee identifier created by the organization; employee code and display name when provided; organization membership, enrolled access areas, and the permissions the user needs.
Phone and app-installation verification
A random identifier unique to this app installation; the public part or fingerprint of the key created on the phone; and the Android Key Attestation or iOS App Attest check result. The private key never leaves the phone’s secure storage.
iOS App Attest
On supported versions, the App Attest key identifier, Apple-verified App Attest result, and limited anti-fraud signals may be associated with the membership. Apple’s raw response is not copied into general error logs.
Access and attendance records
Organization, access-area, entry-point, and gateway identifiers; transaction time; a summary of BLE proximity or suspicious signals; a UWB relative-distance result in supported High Assurance versions; verification level, rule version, decision, and any resulting access or attendance record. This proximity information is not a geographic GPS coordinate.
Security and error records
Limited technical records required to operate and protect the service, such as the verification step reached, app and communication version, error type, phone-security check, or suspicious-signal result.
Limited information stored on the phone
Enrolled access areas, secure-key names, previously granted permission status, incomplete enrollment or removal steps, and at most the five most recent scan times used to enforce Android’s Bluetooth scanning limit.
Authorized gateway setup
A WiFi network name and password entered only by an authorized installer are sent directly to the gateway over a protected BLE session for configuration. The password is not retained in logs, transaction history, QR codes, or analytics.

Data we do not collect or use

MesaiGo’s live phone-to-gateway proximity check does not depend on continuous people tracking or advertising profiles.

Biometric templates
MesaiGo does not receive, store, or send face images, fingerprints, or other biometric templates to the server.
Precise GPS location
Precise GPS coordinates are not collected, background location history is not created, and access or attendance decisions are not based on GPS coordinates.
Advertising and tracking identifiers
Advertising identifiers are not collected, and no third-party advertising, behavioral profiling, or cross-app tracking is performed.
Private keys and enrollment keys
Private keys, raw enrollment keys, and unnecessary communication secrets are not written to general error logs, diagnostics, or transaction history.

Device permissions and proximity technologies

Permissions are requested on the phone’s own permission screen only when the related feature is opened. The fact that the phone displays a permission does not mean MesaiGo collects every type of data that permission could expose.

Bluetooth and Nearby Devices
Used to find a nearby authorized MesaiGo gateway, perform live BLE verification, and complete authorized setup or maintenance tasks.
Android location permission
Some Android versions may display a system location or nearby-device permission for BLE scanning. MesaiGo does not use it to collect precise GPS coordinates or track background location.
Camera
Used at the user’s request to scan MesaiGo QR codes for phone enrollment, entry points, gateway setup, or the store-review simulation. It does not create a general photo archive.
Network access
Used for phone enrollment, checking user permissions and organization rules, receiving the server decision, showing employees their own records, and securely transferring security records.
UWB
On enabled and supported devices and versions, High Assurance may use UWB to securely verify relative distance between the phone and an authorized gateway. It does not create geographic location history.
PIN or biometrics
When required by the supported app version and organization rule, a critical transaction is approved with the phone PIN or biometric check. MesaiGo receives only the result that the phone verified the user, never face or fingerprint data.

Purposes for using data

Data is used to enroll the user in an authorized organization and access area, protect the phone key, perform live BLE or secure UWB proximity checks, display access and attendance results, block forged or repeated requests, troubleshoot failures, and keep a transaction history.

Phone-security checks, suspicious signals, or unusual device results may inform a technical security decision. They do not by themselves produce an employee disciplinary, fraud, or other HR judgment.

Sharing, service providers, and transfers

MesaiGo does not sell personal data or share it with third parties for advertising. As of the last-updated date, the mobile app does not enable third-party advertising, behavioral analytics, or general-purpose crash-analytics providers.

Data may be visible only to people in the user’s organization who have the required permission. When iOS device security verification is enabled, an App Attest/DeviceCheck verification request may be sent from the server to the relevant Apple service. If another service provider is used for hosting, security, or support, it may access only the data required to provide the contracted service. Data region, subprocessors, and any international-transfer conditions are disclosed in the applicable service agreement and organization privacy notice.

Every service provider that processes personal data for MesaiGo is required, through written data-protection and confidentiality terms, to provide the same or an equivalent level of protection, process the data only on documented instructions and for the disclosed purpose, apply appropriate security safeguards, and delete or return the data when the service ends, subject to applicable retention obligations.

Retention and security

How long server-side membership, access, attendance, security, and transaction-history records are kept depends on the data type, purpose, organization rule, contract, and applicable legal obligations. Data must not be kept longer than necessary. When its retention period ends, it must be deleted securely or changed so it can no longer be linked to a person.

An incomplete phone enrollment is deleted when it succeeds, is cancelled, or expires. When a user removes an access area, the phone enrollment for that area is cleared. Recent scan times stored for Android’s Bluetooth scanning limit are deleted after the short limit period. Resetting app data in phone settings removes information held on the phone but does not automatically delete organization records held on the server.

Data in transit is protected by secure connections. Phone keys are stored in the operating system’s secure key storage. Only explicitly authorized users whose jobs require it can access server and management screens, and access is recorded.

Account, access-area, and data-deletion requests

MesaiGo Mobile is not a consumer app in which end users independently create a public account. User or employee membership is provided by an authorized organization. Removing an access area in the app removes the phone identity and information stored on the phone for that area; it does not automatically delete employee, access, attendance, or transaction-history records held by the organization.

To close a membership or request access, correction, deletion, restriction, or objection, contact an authorized administrator at your organization first. If MesaiGo must process the request, use the privacy contact below. After the requester’s identity and right to make the request are verified, it is handled under applicable law and mandatory retention obligations.

Submit a privacy or data-deletion request →

Children’s privacy

MesaiGo is designed for companies managing employees and physical access; it is not a consumer service directed to children. If an organization uses it for minors, that organization must provide the required legal basis, notice, and protective measures.

Changes to this policy

This policy and its last-updated date are revised when app data practices, third-party components, or legal requirements change. Material changes may also be announced through the app, organization administrator, or relevant store listing when required.

Contact

For privacy, user-rights, data-retention, or deletion questions, contact hello@mesaigo.com. Product-security vulnerabilities should be reported to security@mesaigo.com.

Contact the privacy team → Submit a security report →
Related information

Explore the details relevant to your needs.

01 Mobile app

Mobile verification, permissions, and store experience.

Open page →
02 Data use and privacy

Which data the MesaiGo product family uses and why.

Open page →
03 Security controls

Device identity, App Attest, and verification security.

Open page →
MESAIGO

It does not track people. It verifies presence.

Platform

  • MesaiGo Platform
  • How it works
  • Standard profile
  • High Assurance
  • Management

Products

  • Access control
  • Time and attendance
  • Gateway family
  • Mobile app
  • Integrations

Trust

  • Security controls
  • Trust Center
  • Data use and privacy
  • Mobile app privacy
  • Terms of use

Get started

  • Resources
  • Support
  • Product consultation

© 2026 MesaiGo. All rights reserved.

security@mesaigo.com