Skip to main content
MESAIGO
Platform
Evidence core

One evidence backbone. Two distinct product outcomes.

Explore →
Evidence platform A shared core from device to decision How it works Follow the evidence flow end to end Standard profile Live BLE verification High Assurance Secure UWB and transaction approval Mobile app Device-bound identity with a focused experience Management platform Policy, fleet, audit, and operations
Solutions
One proof, two outcomes

Manage access and attendance without collapsing them into one event.

Explore →
Access control Doors, turnstiles, and controlled spaces Time and attendance From verified event to time record High-security spaces Vaults, server rooms, and critical zones For security teams Assurance, risk, and audit visibility For IT teams SSO, SCIM, SIEM, API, and webhooks For HR and operations Shifts, approvals, payroll, and transparency
Hardware
Gateway family

One product discipline from BLE to secure UWB.

Explore →
All gateway models Verify, Access Lite, Access, and Pro Verify WiFi + BLE verification point Access Lite WiFi, BLE, and field I/O Access Ethernet, NFC, and access I/O Access Pro Secure UWB High Assurance Installation and support Connectivity, commissioning, and lifecycle
Security
Trust by design

We explain trust through the evidence chain, not badges.

Explore →
Security model Threats, controls, and decision authority Trust Center Testing, privacy, and operational evidence Secure ranging UWB sessions and distance evidence Privacy No biometric templates or GPS tracking Report a vulnerability Responsible disclosure and incident channel Technical resources Architecture and protocol overviews
Resources
Self-guided evaluation

Understand the system before requesting a demo.

Explore →
Resource center Technical overviews and buying guides Integrations API, webhooks, HR, and physical systems Documentation Installation, usage, and troubleshooting Trust Center Security and service evidence Mobile app Stores, permissions, and compatibility Architecture consultation Evaluate your scenario with us
EN
EN English TR Türkçe
Sign in Architecture consultation
Menu
Current language
EN English TR Türkçe
Platform
Evidence platform A shared core from device to decision How it works Follow the evidence flow end to end Standard profile Live BLE verification High Assurance Secure UWB and transaction approval Mobile app Device-bound identity with a focused experience Management platform Policy, fleet, audit, and operations
Solutions
Access control Doors, turnstiles, and controlled spaces Time and attendance From verified event to time record High-security spaces Vaults, server rooms, and critical zones For security teams Assurance, risk, and audit visibility For IT teams SSO, SCIM, SIEM, API, and webhooks For HR and operations Shifts, approvals, payroll, and transparency
Hardware
All gateway models Verify, Access Lite, Access, and Pro Verify WiFi + BLE verification point Access Lite WiFi, BLE, and field I/O Access Ethernet, NFC, and access I/O Access Pro Secure UWB High Assurance Installation and support Connectivity, commissioning, and lifecycle
Security
Security model Threats, controls, and decision authority Trust Center Testing, privacy, and operational evidence Secure ranging UWB sessions and distance evidence Privacy No biometric templates or GPS tracking Report a vulnerability Responsible disclosure and incident channel Technical resources Architecture and protocol overviews
Resources
Resource center Technical overviews and buying guides Integrations API, webhooks, HR, and physical systems Documentation Installation, usage, and troubleshooting Trust Center Security and service evidence Mobile app Stores, permissions, and compatibility Architecture consultation Evaluate your scenario with us
Architecture consultation Sign in to platform
  1. Home /
  2. Evidence platform /
  3. Mobile app /
  4. Mobile app privacy
iOS and Android

Mobile app privacy policy

This policy explains which data the MesaiGo mobile app uses and why, the limits of device permissions, and how to submit access, correction, or deletion requests.

  • No tracking No advertising profile or cross-app tracking.
  • No GPS tracking Access and attendance decisions do not rely on precise GPS coordinates.
  • No biometric templates PIN and biometrics remain inside the device operating system.
Last updated: July 25, 2026
On this page Scope and roles Categories of data processed Data we do not collect or use Device permissions and proximity technologies Purposes for using data Sharing, service providers, and transfers Retention and security Account, access-area, and data-deletion requests Children’s privacy Changes to this policy Contact

Scope and roles

This policy covers the iOS and Android mobile apps published as MesaiGo, their communication with MesaiGo services, and the limited local state held on-device. The broader privacy approach for the corporate website is described on the separate Product Privacy page.

MesaiGo is an enterprise workforce and physical-access product. A user membership is normally created and managed by the user’s employer or another authorized organization. Controller and processor roles depend on the organization’s deployment model, contract, and applicable privacy notice.

Categories of data processed

The app processes only the data categories required for device enrollment, physical proximity verification, access or attendance outcomes, employee visibility, and system security.

Identity and membership
The user or employee identifier created by the organization; employee code or display name when provided; organization membership, access-area assignment, and necessary authorization context.
Device identity and assurance
An installation-specific opaque identifier; public key or fingerprint information for the on-device key; Android Key Attestation or iOS App Attest context; and device-assurance result. The private key never leaves the device secure boundary.
iOS App Attest
On supported versions, the App Attest key identifier, verified receipt context, and limited anti-fraud signals may be associated with the membership. The raw Apple response is not copied into general diagnostic logs.
Verification and business events
Organization, access area, entry point, or gateway context; transaction time; a summary of BLE proximity or risk signals; a UWB relative-distance result in enabled and supported High Assurance versions; assurance profile, policy version, decision, and any resulting access or attendance event. This proximity evidence is not a geographic GPS coordinate.
Product interaction and diagnostics
Technical records required to operate and protect the service, such as verification stage, app and protocol version, limited error class, and integrity or risk result.
Limited on-device state
Enrolled access areas, key aliases, permission cache, pending enrollment or removal steps, and up to five monotonic timestamps used for Android BLE scan rate limiting.
Authorized gateway setup
A WiFi network name and password entered only by an authorized installer are sent directly to the gateway over a protected BLE session for configuration. The password is not retained in logs, audit records, QR codes, or analytics.

Data we do not collect or use

MesaiGo physical proximity evidence does not depend on continuous people tracking or advertising profiles.

Biometric templates
MesaiGo does not receive, store, or send face images, fingerprints, or other biometric templates to the server.
Precise GPS location
Precise GPS coordinates are not collected, background location history is not created, and access or attendance decisions are not based on GPS coordinates.
Advertising and tracking identifiers
Advertising identifiers are not collected, and no third-party advertising, behavioral profiling, or cross-app tracking is performed.
Raw secrets
Private keys, raw enrollment tokens, and unnecessary protocol secrets are not written to general logs, diagnostics, or audit records.

Device permissions and proximity technologies

Permissions are requested only when the related feature is used and within the operating system permission model. The fact that the operating system displays a permission does not mean MesaiGo collects every type of data that permission could expose.

Bluetooth and Nearby Devices
Used to discover a nearby authorized MesaiGo gateway, perform live BLE verification, and run authorized setup or maintenance flows.
Android location permission
Some Android versions may display a system location or nearby-device permission for BLE scanning. MesaiGo does not use it to collect precise GPS coordinates or track background location.
Camera
Used at the user’s request to scan MesaiGo QR codes for phone enrollment, entry points, gateway setup, or the store-review simulation. It does not create a general photo archive.
Network access
Used for device enrollment, authorization and policy queries, server decisions, employee visibility, and secure transfer of security records.
UWB
On enabled and supported devices and versions, High Assurance may use UWB to securely verify relative distance between the phone and an authorized gateway. It does not create geographic location history.
PIN or biometrics
When required by a supported version and organization policy, the operating system evaluates local user approval for a critical transaction. MesaiGo uses only the result that the cryptographic operation completed after local approval, not the biometric template.

Purposes for using data

Data is used to enroll the user in an authorized organization and access area, protect device identity, evaluate live BLE or secure UWB proximity evidence, display access and attendance outcomes, prevent compromise and replay attempts, troubleshoot failures, and maintain auditability.

Integrity, unusual-signal, or device-assurance results may inform a technical security decision. They do not by themselves produce an employee disciplinary, fraud, or other HR judgment.

Sharing, service providers, and transfers

MesaiGo does not sell personal data or share it with third parties for advertising. As of the last-updated date, the mobile app does not enable third-party advertising, behavioral analytics, or general-purpose crash-analytics providers.

Data may be visible to the user’s organization within its authorization scope. When iOS device security verification is enabled, an App Attest/DeviceCheck verification request may be sent from the server to the relevant Apple service. If another processor is used to host, secure, or support the service, access is limited to the required purpose and scope. Data region, subprocessors, and any international-transfer conditions are disclosed in the applicable service agreement and organization privacy notice.

Retention and security

Retention for server-side membership, access, attendance, security, and audit records is determined by data category, purpose, organization policy, contract, and applicable legal obligations. Data should not be retained longer than necessary and should be deleted or anonymized in a controlled manner when its period expires.

Pending mobile enrollment state is cleared on result, cancellation, or expiry; access-area state is cleared when removed by the user; Android BLE rate-limit timestamps are cleared after the short rolling window ends. Resetting app data in operating-system settings removes on-device app state but does not automatically delete organization records held on the server.

Data in transit is protected by secure connections. Device-identity keys are held in the operating-system secure key boundary, and server and management access is restricted by role, scope, and audit controls.

Account, access-area, and data-deletion requests

MesaiGo Mobile is not a consumer app in which end users independently create a public account. User or employee membership is provided by an authorized organization. Removing an access area in the app removes its device credential and local state; it does not automatically delete employee, access, attendance, or audit records held by the organization.

To close a membership or request access, correction, deletion, restriction, or objection, contact an authorized administrator at your organization first. If MesaiGo must process the request, use the privacy contact below. After identity and authority verification, the request is handled under applicable law and mandatory retention obligations.

Submit a privacy or data-deletion request →

Children’s privacy

MesaiGo is designed for enterprise workforce and physical-access processes and is not a consumer service directed to children. If an organization uses it in a context involving minors, that organization must provide the required legal basis, notice, and protective controls.

Changes to this policy

This policy and its last-updated date are revised when app data practices, third-party components, or legal requirements change. Material changes may also be announced through the app, organization administrator, or relevant store listing when required.

Contact

For privacy, user-rights, or data-lifecycle questions, contact hello@mesaigo.com. Product-security vulnerabilities should be reported to security@mesaigo.com.

Contact the privacy team → Submit a security report →
Related technical paths

Continue your evaluation at the next evidence layer.

01 Mobile app

Mobile verification, permissions, and store experience.

Open related page →
02 Product privacy

The privacy approach across the MesaiGo product family.

Open related page →
03 Security model

Device identity, App Attest, and evidence security.

Open related page →
MESAIGO

It does not track people. It verifies presence.

Platform

  • Evidence platform
  • How it works
  • Standard profile
  • High Assurance
  • Management

Products

  • Access control
  • Time and attendance
  • Gateway family
  • Mobile app
  • Integrations

Trust

  • Security model
  • Trust Center
  • Product privacy
  • Mobile app privacy
  • Report a vulnerability
  • Terms of use

Get started

  • Resources
  • Support
  • Architecture consultation

© 2026 MesaiGo. All rights reserved.

Verifiable proximity evidence for physical decisions.

security@mesaigo.com