Privacy policy for the website, trial, workspace and APIs
This page explains how TRMesh handles data across website visits, trial registration, workspace usage, AI assistant workflows, combined queries, API operations, billing and referral rewards. TRMesh is social data access and API orchestration infrastructure. It helps customers access, govern and meter public or authorized data capabilities; customers remain responsible for their own use, export, storage and downstream processing of retrieved data. Enterprise data-processing commitments are handled through contract-specific agreements when applicable.
Our role
TRMesh usually acts as an API infrastructure and service provider for account, billing, usage, audit and operational data. Social platform data retrieved or exported through customer API usage is controlled by the customer for downstream use, storage, legal basis and end-user notices.
Public-data and authorization boundaries
The service is designed around public, customer-authorized or data-service-permitted capabilities. It is not intended to bypass platform permissions, login walls, privacy settings or technical access controls. Where returned data is affected by platform rules, privacy settings or regional restrictions, customers must evaluate the permitted use of the actual response.
Account and identity data
This may include email, name, sign-in state, password hashes, verification status, OAuth binding data, roles and permissions, session refresh records, invitation relationships, referral attribution and customer-support communications.
API, AI and tool-call data
When users call APIs, combined queries, the AI assistant or MCP/tool orchestration, the platform records request time, route, status, cost, quota consumption, request source, tool-call summaries, error codes and necessary response metadata for quota control, billing reconciliation, troubleshooting, security auditing and service improvement.
Billing, recharge and reward data
The platform processes recharge orders, payment-channel status, transaction identifiers, balance movements, consumption records, refunds or disputes, referral-reward calculations and wallet-balance conversion records. Payment providers may process payer account, blockchain transaction or fraud-prevention data under their own rules.
Device, log and security data
To protect accounts and service reliability, the platform may record IP address, user agent, access time, page path, exception logs, audit logs, account administration actions, RPS setting changes, token creation and revocation records, and diagnostics related to security investigations.
Purpose of processing
Data is used for authentication, verification email delivery, session maintenance, permission checks, quota control, billing reconciliation, payment callback confirmation, referral settlement, data-route failover, abuse detection, troubleshooting, security auditing, product improvement and customer support.
Data and third-party services
Some features rely on data providers, email and sign-in services, payment providers, cloud infrastructure, monitoring systems, and AI model services. We share only the data needed to provide and protect the service and require these providers to process it under applicable agreements and security requirements.
Data minimization
The platform aims to process only what is required to operate the service, does not intentionally become a long-term store for raw social platform content, does not use customer API responses as general training data and avoids unrelated secondary use unless authorized or legally permitted.
Security controls
Controls include access control, permission isolation, encrypted transport, hashed developer tokens, sensitive configuration protection, administrative auditing, exception-log governance, resource-pool isolation and least-privilege operations.
Retention and deletion
Account, billing, usage, payment, audit and security logs are retained for service delivery, compliance, financial reconciliation, dispute handling and security traceability. Users may request access, correction or deletion of account data that is no longer necessary, except where retention is required for legal, financial or audit reasons.
Customer exports and downstream processing
Once data is exported through APIs, reports or combined queries into customer systems, customers are responsible for access controls, retention periods, deletion workflows, lawful-use basis, data-subject request handling and disclosures to third parties.
Cross-region delivery
Because the platform serves global customers, some service paths may involve cross-region deployment, access, logging, data routing or third-party processing. Enterprise data region, subprocessors and transfer arrangements depend on infrastructure choices and signed agreements.
Children and sensitive data
The service is not directed to children, and customers should not submit or process legally sensitive personal data unless they have confirmed a lawful basis and implemented additional safeguards.
Policy updates
This policy may change as the product, data capabilities, payment channels, legal requirements and security practices evolve. Material changes will be communicated through the website, workspace notice or email when practical. Continued use means acceptance of the then-current public version.
Contact channel
If you have privacy questions, you can contact [email protected].