Legal
Privacy Policy
OpenMesh reads, transforms, and transports data to run your front office. We do not permanently store customer content as a product archive — your connected tools remain the system of record.
Last updated: July 22, 2026
1. Who we are and what this policy covers
OpenMesh (“OpenMesh,” “we,” “us,” or “our”) provides an AI front-office layer for service businesses. We sit on top of the phones, messaging channels, inboxes, calendars, and CRMs you already use, so routine calls, messages, bookings, and follow-ups can be handled without replacing your stack.
This Privacy Policy explains how we collect, use, share, and handle information in connection with (a) the OpenMesh product and related services (the “Product”), and (b) our marketing website and contact flows (the “Website”), including any in-product disclosures that accompany specific features.
Last updated: July 22, 2026.
2. Core privacy principle: read, transform, transport
OpenMesh is designed as a processing and routing layer, not as a long-term customer data warehouse. In normal Product operation we:
Read channel and integration data only as needed to run a front-office workflow (for example, an inbound call, WhatsApp or email thread, booking request, or CRM update).
Transform that data in transit — extracting intent, drafting replies, building summaries, deciding routing, and assembling human-handoff context.
Transport / write through results to systems you own or authorize (phone and messaging providers, email, calendar, CRM, spreadsheets, databases, and similar tools). Those systems remain your systems of record.
We do not permanently retain customer communications content or CRM records as a primary OpenMesh datastore. Processing state is transient: ephemeral buffers and short-lived workflow state used to complete a request, then discarded when the workflow finishes.
3. Categories of data we process
Depending on how you configure the Product and what you send us on the Website, we may process the following categories:
Communications content and metadata — call audio or transcripts (where enabled), message bodies, email content, timestamps, participant identifiers (phone numbers, handles, addresses), channel type, and delivery status.
Booking and calendar fields — requested times, availability windows, appointment details, reminders, and related scheduling metadata needed to create or update events in your connected calendar.
CRM and workflow records in transit — lead or customer fields, notes, tags, pipeline stage updates, and similar records that pass through OpenMesh solely to be written to or read from your connected tools.
Operator handoff context — structured summaries and context packages generated so a human teammate can take over with enough information to continue the interaction.
Account and configuration data — workspace settings, integration credentials or tokens (stored only as needed to keep connections working), routing rules, escalation preferences, and similar configuration.
Website inquiry data — name, work email, company, topic, and message content when you submit our contact form or email us directly; scheduling details when you book a demo.
4. How we collect data
Customer-connected channels and integrations. When you connect phones, messaging (for example WhatsApp or similar), email, calendar, CRM, spreadsheets, or databases, OpenMesh reads from and writes to those systems according to the permissions and scopes you grant.
Automated processing during workflows. As interactions occur, the Product automatically processes inbound and outbound events to classify intent, generate responses, schedule actions, sync updates, and escalate when a human is required.
Information you provide. You or your team may provide account details, configuration, scripts or playbooks, and Website form or email inquiries.
We do not scrape unrelated third-party services beyond what you explicitly connect, and we do not buy personal data lists for Product operation.
5. How we use data
We use the data described above to:
Operate the Product — automate routine replies, bookings, reminders, and follow-ups; qualify and route leads; and hand off to humans with full context when judgment is required.
Write through to your tools — sync notes, statuses, appointments, and related updates into the CRM, calendar, and other systems you authorize, so durable records live where you already work.
Secure and improve reliability — detect abuse, debug failures, maintain uptime, and enforce access controls. Operational logs used for this purpose are limited to what is needed to run and protect the service and are not used as a permanent content archive.
Respond to Website inquiries — reply to demos, sales, support, and partnership requests you send us.
We do not sell personal data. We do not use customer communications content to build advertising profiles.
6. Storage posture: no permanent customer-content store
OpenMesh’s Product architecture is built around transient processing. Customer content (messages, call-derived content, CRM payloads, booking details in flight) is processed to complete the workflow and is not retained by OpenMesh as a permanent content archive.
Your connected systems — calendars, CRMs, inboxes, messaging providers, spreadsheets, and databases — are the durable stores. When marketing materials refer to “sync,” “transcripts,” “notes,” or “visibility,” those refer to processing in transit and/or records written to or read from your systems of record, not to OpenMesh keeping a long-term copy of that content as its own database of customer interactions.
Limited exceptions: account configuration, integration connection state, and Website inquiry records needed to operate your workspace or respond to you may be retained as described in the Retention section. Transient processing caches may exist briefly during a request and are discarded when no longer needed.
9. Retention
Product traffic and customer content in processing: retained only transiently for the duration needed to complete the read–transform–transport workflow, then discarded from OpenMesh processing state. Durable copies, if any, reside in your connected systems under your retention policies.
Account and configuration data: retained for as long as your workspace remains active and for a reasonable period afterward as needed to wind down the service, resolve disputes, or meet legal obligations.
Website inquiries: retained only as long as reasonably necessary to respond to your request and maintain ordinary business records of that correspondence.
When retention is no longer necessary, we delete or de-identify information in accordance with our operational practices.
10. Security
We apply administrative, technical, and organizational measures appropriate to a processing-and-routing service, including access controls, encrypted transport where supported by connected providers, and least-privilege handling of integration credentials.
No method of transmission or processing is perfectly secure. You are responsible for safeguarding credentials to your connected systems and for configuring those systems’ own access and retention settings.
11. Your choices and privacy requests
Because durable customer records typically live in your own tools, many access, correction, and deletion requests are most effectively handled in those systems of record.
For requests that relate to OpenMesh itself — for example, Website inquiry data, account configuration, or questions about how processing works — contact us at the address below. We will respond within a reasonable period consistent with applicable law.
Privacy contact: junbin@riye.one
12. International processing
OpenMesh and its subprocessors may process data in regions where we or they operate infrastructure. By using the Product or Website, you understand that processing may occur outside your local jurisdiction, subject to appropriate safeguards with our providers.
13. Children
The Product and Website are directed to businesses and professionals. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it from OpenMesh-controlled records.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect product, legal, or operational changes. The “Last updated” date at the top will change when we do. Continued use of the Product or Website after an update constitutes acceptance of the revised policy. Material changes will be reflected on this page; where required, we will provide additional notice.
15. Contact
Questions about this Privacy Policy or OpenMesh’s data practices:
Email: junbin@riye.one
Subject line suggestion: OpenMesh Privacy Request