Mobile app privacy policy
This policy explains which data the MesaiGo mobile app uses and why, the limits of device permissions, and how to submit access, correction, or deletion requests.
- No tracking No advertising profile or cross-app tracking.
- No GPS tracking Access and attendance decisions do not rely on precise GPS coordinates.
- No biometric templates PIN and biometrics remain inside the device operating system.
Who this policy covers and who is responsible
This policy covers the iOS and Android mobile apps published as MesaiGo, their communication with MesaiGo services, and the limited information stored on the phone. The corporate website explains its data use and privacy details on the separate Data Use and Privacy page.
MesaiGo is an enterprise workforce and physical-access product. A user membership is normally created and managed by the user’s employer or another authorized organization. The customer agreement and privacy notice state which organization is the data controller and which service acts as the data processor for that setup.
Categories of data processed
The app processes only the data categories required for device enrollment, physical proximity verification, access or attendance outcomes, employees’ access to their own records, and system security.
An organization-defined entry point or gateway can identify an exact physical workplace point. For App Store privacy disclosure, MesaiGo therefore treats entry-point information linked to a user as Precise Location, even though the app does not request iOS Location Services, collect GPS coordinates, or create background location history.
- Identity and membership
- The user or employee identifier created by the organization; employee code and display name when provided; organization membership, enrolled access areas, and the permissions the user needs.
- Phone and app-installation verification
- A random identifier unique to this app installation; the public part or fingerprint of the key created on the phone; and the Android Key Attestation or iOS App Attest check result. The private key never leaves the phone’s secure storage.
- iOS App Attest
- On supported versions, the App Attest key identifier, Apple-verified App Attest result, and limited anti-fraud signals may be associated with the membership. Apple’s raw response is not copied into general error logs.
- Access and attendance records
- Organization, access-area, entry-point, and gateway identifiers; transaction time; a summary of BLE proximity or suspicious signals; a UWB relative-distance result in supported High Assurance versions; verification level, rule version, decision, and any resulting access or attendance record. This proximity information is not a geographic GPS coordinate.
- Security and error records
- Limited technical records required to operate and protect the service, such as the verification step reached, app and communication version, error type, phone-security check, or suspicious-signal result.
- Limited information stored on the phone
- Enrolled access areas, secure-key names, previously granted permission status, incomplete enrollment or removal steps, and at most the five most recent scan times used to enforce Android’s Bluetooth scanning limit.
- Authorized gateway setup
- A WiFi network name and password entered only by an authorized installer are sent directly to the gateway over a protected BLE session for configuration. The password is not retained in logs, transaction history, QR codes, or analytics.
Data we do not collect or use
MesaiGo’s live phone-to-gateway proximity check does not depend on continuous people tracking or advertising profiles.
- Biometric templates
- MesaiGo does not receive, store, or send face images, fingerprints, or other biometric templates to the server.
- Precise GPS location
- Precise GPS coordinates are not collected, background location history is not created, and access or attendance decisions are not based on GPS coordinates.
- Advertising and tracking identifiers
- Advertising identifiers are not collected, and no third-party advertising, behavioral profiling, or cross-app tracking is performed.
- Private keys and enrollment keys
- Private keys, raw enrollment keys, and unnecessary communication secrets are not written to general error logs, diagnostics, or transaction history.
Device permissions and proximity technologies
Permissions are requested on the phone’s own permission screen only when the related feature is opened. The fact that the phone displays a permission does not mean MesaiGo collects every type of data that permission could expose.
- Bluetooth and Nearby Devices
- Used to find a nearby authorized MesaiGo gateway, perform live BLE verification, and complete authorized setup or maintenance tasks.
- Android location permission
- Some Android versions may display a system location or nearby-device permission for BLE scanning. MesaiGo does not use it to collect precise GPS coordinates or track background location.
- Camera
- Used at the user’s request to scan MesaiGo QR codes for phone enrollment, entry points, gateway setup, or the store-review simulation. It does not create a general photo archive.
- Network access
- Used for phone enrollment, checking user permissions and organization rules, receiving the server decision, showing employees their own records, and securely transferring security records.
- UWB
- On enabled and supported devices and versions, High Assurance may use UWB to securely verify relative distance between the phone and an authorized gateway. It does not create geographic location history.
- PIN or biometrics
- When required by the supported app version and organization rule, a critical transaction is approved with the phone PIN or biometric check. MesaiGo receives only the result that the phone verified the user, never face or fingerprint data.
Purposes for using data
Data is used to enroll the user in an authorized organization and access area, protect the phone key, perform live BLE or secure UWB proximity checks, display access and attendance results, block forged or repeated requests, troubleshoot failures, and keep a transaction history.
Phone-security checks, suspicious signals, or unusual device results may inform a technical security decision. They do not by themselves produce an employee disciplinary, fraud, or other HR judgment.
Retention and security
How long server-side membership, access, attendance, security, and transaction-history records are kept depends on the data type, purpose, organization rule, contract, and applicable legal obligations. Data must not be kept longer than necessary. When its retention period ends, it must be deleted securely or changed so it can no longer be linked to a person.
An incomplete phone enrollment is deleted when it succeeds, is cancelled, or expires. When a user removes an access area, the phone enrollment for that area is cleared. Recent scan times stored for Android’s Bluetooth scanning limit are deleted after the short limit period. Resetting app data in phone settings removes information held on the phone but does not automatically delete organization records held on the server.
Data in transit is protected by secure connections. Phone keys are stored in the operating system’s secure key storage. Only explicitly authorized users whose jobs require it can access server and management screens, and access is recorded.
Account, access-area, and data-deletion requests
MesaiGo Mobile is not a consumer app in which end users independently create a public account. User or employee membership is provided by an authorized organization. Removing an access area in the app removes the phone identity and information stored on the phone for that area; it does not automatically delete employee, access, attendance, or transaction-history records held by the organization.
To close a membership or request access, correction, deletion, restriction, or objection, contact an authorized administrator at your organization first. If MesaiGo must process the request, use the privacy contact below. After the requester’s identity and right to make the request are verified, it is handled under applicable law and mandatory retention obligations.
Children’s privacy
MesaiGo is designed for companies managing employees and physical access; it is not a consumer service directed to children. If an organization uses it for minors, that organization must provide the required legal basis, notice, and protective measures.
Changes to this policy
This policy and its last-updated date are revised when app data practices, third-party components, or legal requirements change. Material changes may also be announced through the app, organization administrator, or relevant store listing when required.
Contact
For privacy, user-rights, data-retention, or deletion questions, contact hello@mesaigo.com. Product-security vulnerabilities should be reported to security@mesaigo.com.