Mobile app privacy policy
This policy explains which data the MesaiGo mobile app uses and why, the limits of device permissions, and how to submit access, correction, or deletion requests.
- No tracking No advertising profile or cross-app tracking.
- No GPS tracking Access and attendance decisions do not rely on precise GPS coordinates.
- No biometric templates PIN and biometrics remain inside the device operating system.
Scope and roles
This policy covers the iOS and Android mobile apps published as MesaiGo, their communication with MesaiGo services, and the limited local state held on-device. The broader privacy approach for the corporate website is described on the separate Product Privacy page.
MesaiGo is an enterprise workforce and physical-access product. A user membership is normally created and managed by the user’s employer or another authorized organization. Controller and processor roles depend on the organization’s deployment model, contract, and applicable privacy notice.
Categories of data processed
The app processes only the data categories required for device enrollment, physical proximity verification, access or attendance outcomes, employee visibility, and system security.
- Identity and membership
- The user or employee identifier created by the organization; employee code or display name when provided; organization membership, access-area assignment, and necessary authorization context.
- Device identity and assurance
- An installation-specific opaque identifier; public key or fingerprint information for the on-device key; Android Key Attestation or iOS App Attest context; and device-assurance result. The private key never leaves the device secure boundary.
- iOS App Attest
- On supported versions, the App Attest key identifier, verified receipt context, and limited anti-fraud signals may be associated with the membership. The raw Apple response is not copied into general diagnostic logs.
- Verification and business events
- Organization, access area, entry point, or gateway context; transaction time; a summary of BLE proximity or risk signals; a UWB relative-distance result in enabled and supported High Assurance versions; assurance profile, policy version, decision, and any resulting access or attendance event. This proximity evidence is not a geographic GPS coordinate.
- Product interaction and diagnostics
- Technical records required to operate and protect the service, such as verification stage, app and protocol version, limited error class, and integrity or risk result.
- Limited on-device state
- Enrolled access areas, key aliases, permission cache, pending enrollment or removal steps, and up to five monotonic timestamps used for Android BLE scan rate limiting.
- Authorized gateway setup
- A WiFi network name and password entered only by an authorized installer are sent directly to the gateway over a protected BLE session for configuration. The password is not retained in logs, audit records, QR codes, or analytics.
Data we do not collect or use
MesaiGo physical proximity evidence does not depend on continuous people tracking or advertising profiles.
- Biometric templates
- MesaiGo does not receive, store, or send face images, fingerprints, or other biometric templates to the server.
- Precise GPS location
- Precise GPS coordinates are not collected, background location history is not created, and access or attendance decisions are not based on GPS coordinates.
- Advertising and tracking identifiers
- Advertising identifiers are not collected, and no third-party advertising, behavioral profiling, or cross-app tracking is performed.
- Raw secrets
- Private keys, raw enrollment tokens, and unnecessary protocol secrets are not written to general logs, diagnostics, or audit records.
Device permissions and proximity technologies
Permissions are requested only when the related feature is used and within the operating system permission model. The fact that the operating system displays a permission does not mean MesaiGo collects every type of data that permission could expose.
- Bluetooth and Nearby Devices
- Used to discover a nearby authorized MesaiGo gateway, perform live BLE verification, and run authorized setup or maintenance flows.
- Android location permission
- Some Android versions may display a system location or nearby-device permission for BLE scanning. MesaiGo does not use it to collect precise GPS coordinates or track background location.
- Camera
- Used at the user’s request to scan MesaiGo QR codes for phone enrollment, entry points, gateway setup, or the store-review simulation. It does not create a general photo archive.
- Network access
- Used for device enrollment, authorization and policy queries, server decisions, employee visibility, and secure transfer of security records.
- UWB
- On enabled and supported devices and versions, High Assurance may use UWB to securely verify relative distance between the phone and an authorized gateway. It does not create geographic location history.
- PIN or biometrics
- When required by a supported version and organization policy, the operating system evaluates local user approval for a critical transaction. MesaiGo uses only the result that the cryptographic operation completed after local approval, not the biometric template.
Purposes for using data
Data is used to enroll the user in an authorized organization and access area, protect device identity, evaluate live BLE or secure UWB proximity evidence, display access and attendance outcomes, prevent compromise and replay attempts, troubleshoot failures, and maintain auditability.
Integrity, unusual-signal, or device-assurance results may inform a technical security decision. They do not by themselves produce an employee disciplinary, fraud, or other HR judgment.
Retention and security
Retention for server-side membership, access, attendance, security, and audit records is determined by data category, purpose, organization policy, contract, and applicable legal obligations. Data should not be retained longer than necessary and should be deleted or anonymized in a controlled manner when its period expires.
Pending mobile enrollment state is cleared on result, cancellation, or expiry; access-area state is cleared when removed by the user; Android BLE rate-limit timestamps are cleared after the short rolling window ends. Resetting app data in operating-system settings removes on-device app state but does not automatically delete organization records held on the server.
Data in transit is protected by secure connections. Device-identity keys are held in the operating-system secure key boundary, and server and management access is restricted by role, scope, and audit controls.
Account, access-area, and data-deletion requests
MesaiGo Mobile is not a consumer app in which end users independently create a public account. User or employee membership is provided by an authorized organization. Removing an access area in the app removes its device credential and local state; it does not automatically delete employee, access, attendance, or audit records held by the organization.
To close a membership or request access, correction, deletion, restriction, or objection, contact an authorized administrator at your organization first. If MesaiGo must process the request, use the privacy contact below. After identity and authority verification, the request is handled under applicable law and mandatory retention obligations.
Children’s privacy
MesaiGo is designed for enterprise workforce and physical-access processes and is not a consumer service directed to children. If an organization uses it in a context involving minors, that organization must provide the required legal basis, notice, and protective controls.
Changes to this policy
This policy and its last-updated date are revised when app data practices, third-party components, or legal requirements change. Material changes may also be announced through the app, organization administrator, or relevant store listing when required.
Contact
For privacy, user-rights, or data-lifecycle questions, contact hello@mesaigo.com. Product-security vulnerabilities should be reported to security@mesaigo.com.