Privacy policy

Last updated: October 2026. This English version is provided for convenience; in case of doubt, the German Datenschutzerklärung prevails.

This privacy policy explains which personal data is processed when you visit the website meshup.3xd.eu and when you use MeshUp, for what purpose and on what legal basis. It covers the website, the MeshUp app for Android, MeshUp Desktop for Linux and Windows, and the services the controller runs for them: the mesh node mesh-node1.3xd.eu, the push server push-gateway.messenger.3dns.eu and the downloads on git.3dns.eu. Terms such as “personal data” and “processing” are used as defined in Art. 4 of the General Data Protection Regulation (GDPR).

1. Controller

Dominic Schubert
Varkausring 98
01796 Pirna
Germany

Phone: +49 3501 44044
Email: info@dom1nic.eu

See also the legal notice.

2. Summary

3. The website meshup.3xd.eu

3.1 Visiting the website and hosting

When you visit this website, your browser necessarily transmits data to the server: your IP address, date and time, the requested address, details about your browser and operating system (user agent) and, where applicable, the page you came from (referrer). The pages cannot be delivered without this data.

The website runs on the controller’s own server, without an external hosting provider, content delivery network or advertising network. An upstream web server (reverse proxy, Caddy) on the controller’s own router accepts the encrypted HTTPS connection and forwards the request over the controller’s own network to the server that delivers the pages. In doing so, it technically passes on your IP address; the page server neither evaluates nor stores it.

The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is to provide the website securely and reliably.

3.2 Logs of the page server

For every request, the page server writes one short line to the server’s system log (systemd journal): time, request method, requested path without parameters, status code, response size and processing time. IP address, user agent and referrer are not recorded. These lines are used for troubleshooting and secure operation; they are deleted as the system log is rotated automatically.

3.3 Upstream web server

The upstream web server on the router keeps no access log for this website.

3.4 No cookies, no analytics, no third-party content

This website sets no cookies, uses no analytics, advertising or tracking services and embeds no third-party content – no external fonts, maps, videos or content delivery networks. Images, styles and scripts come from this domain, and text is set in your device’s own fonts. The pages instruct your browser not to send a referrer when you follow a link. There are no forms, no comments and no user accounts.

3.5 Storage in your browser

If you use the switch in the header to change between light and dark theme and your choice differs from your device’s system theme, your browser stores it locally (localStorage, entry meshup-theme with the value “light” or “dark”). The entry never leaves your device and is not transmitted to the server. If you switch back to your system theme, the page removes the entry itself; you can also delete it at any time by clearing the site data in your browser. The legal basis is § 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG), as the storage is strictly necessary for the function you explicitly requested.

3.6 Links to git.3dns.eu and other websites

Download and source code links lead to git.3dns.eu. This service is also run by the controller himself (3DNS). Your browser only connects to that server once you follow such a link; as with any website visit, your IP address, the time, the requested file and details about your browser are necessarily transmitted. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is to provide downloads and source code.

Other links, for example to the licence or to the supervisory authority, lead to third-party sites. No data is transmitted to their providers unless you click such a link; after that, their own privacy policies apply.

4. Privacy when using MeshUp

This part describes what happens to your data when you use the MeshUp app for Android and MeshUp Desktop, and which data the controller’s services receive in the process. It is based on the published source code. Wherever something can be switched off, we name the setting in the app.

4.1 Basic principle

MeshUp is a peer-to-peer messenger. On first launch, the app creates a key pair on your device – that is your identity. You need no account, no registration, no phone number and no email address. You add contacts by QR code, NFC or invite link.

Every connection between two devices is end-to-end encrypted with the Noise protocol and authenticated on both sides; in addition, each message is sealed in its own encrypted envelope that only the recipient can open. Messages travel directly from device to device or are passed on, encrypted, by other MeshUp devices. There is no central server storing messages, contact lists, profiles or media. The controller therefore receives none of the content of your communication.

Your profile (name, about, profile picture, banner), your online status and your status updates are only visible to the people you allow in the app’s privacy settings; read receipts and typing indicators can be switched off.

4.2 Data on your device

What you write and receive in MeshUp is stored only on your devices: your private key (encrypted with the Android Keystore), contacts, groups, messages, photos, voice messages, videos and files, the call log, your profile and settings and – if you use “find contacts” – your phone number or email address and the suggestions from the address book match. In addition, there are encrypted messages of others that your device passes on in the mesh (section 4.5) and cached map tiles. This storage is strictly necessary for the functions you use (§ 25(2) no. 2 TDDDG); the controller has no access to it.

The app is excluded from Android’s automatic cloud backup and device-to-device transfer, so its data does not end up in a cloud account without you noticing. If you like, an app lock protects MeshUp with fingerprint, face or screen lock – Android performs the check, and the app never receives biometric data. Disappearing messages can be switched on per chat. Photos that MeshUp downsizes before sending only carry harmless camera data, never the location or serial numbers.

4.3 Backups

Since no server keeps your data, MeshUp offers an encrypted backup (Settings > Chats > Chat backup): manually into a file of your choice, or automatically every day or week into a folder of your choice. The backup is protected by a password that MeshUp does not store; without this password it cannot be opened. If you choose a cloud app as the destination, the encrypted file is stored with that provider, and its privacy policy applies.

4.4 Nearby connections

Nearby devices find each other on the same Wi-Fi network via mDNS and via Bluetooth Low Energy. To do so, the app announces a short identifier derived from your public key; devices within range can therefore tell that a MeshUp device is present and recognise it again. While a connection is being set up, other MeshUp devices also see your profile name. They cannot read the content of the connection. Wi-Fi and Bluetooth can be switched off individually under Settings > Connections; you can also enter fixed addresses there, for example for devices on a VPN.

4.5 Passing messages on via other devices (mesh)

If a recipient cannot be reached directly, other MeshUp devices can carry a message along and pass it on. Only encrypted envelopes are passed on: whoever carries them sees only technical details such as the envelope’s identifier, a recipient tag and the expiry time, but neither the content nor the sender. An envelope is valid for at most 14 days and is deleted once it has been delivered or has expired; the storage used for this is limited.

Your device passes on messages of others in the same way (up to 64 MB by default). Under Settings > Storage and data you can switch off “Pass on messages for others” or limit the storage.

4.6 Mesh node mesh-node1.3xd.eu

If two devices cannot find each other over Wi-Fi or Bluetooth, a mesh node connects them over the internet. The app comes set up with mesh-node1.3xd.eu, which the controller runs himself. The node only relays tunnels between two devices that are currently online; inside them runs the devices’ normal end-to-end encrypted connection. It does not keep messages.

What the node sees during operation:

It does not see the content of messages, calls or files.

What the node stores: its own key and – only if you switch it on in the app – your entry in the “find contacts” directory. Everything else is kept only in memory for as long as the connection lasts; counters used to limit requests per key and per IP address are kept for at most one day. When a device connects or disconnects, the node writes one line to its system log (systemd journal) with the time, the first twelve characters of the public key and the number of connected devices, without the IP address. These lines are used for troubleshooting and are deleted as the system log is rotated automatically.

The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is to connect MeshUp devices across network boundaries and to protect the node against abuse.

Mesh nodes can be switched off under Settings > Connections; MeshUp then only connects via Wi-Fi, Bluetooth, the mesh and fixed addresses. You can also run your own node – the server is part of the source code – or enter a node run by someone else. Its operator is then responsible for the processing there.

4.7 Find contacts (voluntary directory)

If you want, you can link your phone number (suggested from the SIM card if you like) and/or your email address so that people who know you can find you from their address book. On devices with a SIM card, the app asks once during setup or with a card in the chat list; otherwise you set it up in the settings. Nothing is registered without your action.

To be honest: phone numbers have comparatively few possible values. Someone who runs a node and holds its private key could, with considerable computing effort, try out numbers to recover registered ones. The expensive hash slows this down but does not prevent it. Also, you can only be found by people using the same node.

The legal basis for registering your own number or address is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future by removing the entry as described above. For the address book match, where hashes of your contacts’ data are transmitted solely to look them up, the legal basis is Art. 6(1)(f) GDPR; the legitimate interest is to find people you know without uploading address books.

4.8 Push wake-ups

To save battery, the app can sleep in the background and be woken up via push. If someone writes to you or calls you while your device is asleep, their device sends a wake-up to your push address; your device wakes up, connects and fetches the message over the usual encrypted channels. The wake-up contains no content and no sender – just the word “wake”. Your push address is only shared with your contacts and a paired computer, inside your encrypted profile.

The push service sees your push address, the time of the wake-up, the IP address of the device sending it and the connection over which your device receives it.

UnifiedPush (ntfy): the first choice is UnifiedPush, for example with the ntfy app. MeshUp recommends the ntfy server push-gateway.messenger.3dns.eu, which the controller runs himself. You can, however, enter any other server in ntfy; its operator is then responsible for the processing. The legal basis for running our own push server is Art. 6(1)(f) GDPR; the legitimate interest is reliable, battery-friendly delivery.

Firebase Cloud Messaging (only with consent): if no UnifiedPush app is installed, MeshUp offers – on devices with Google Play services (or microG) – to wake up via Firebase Cloud Messaging (FCM) instead. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Firebase only starts once you agree during setup, via the card in the chat list or in the settings; Firebase’s analytics and data collection features are switched off.

The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw it at any time with effect for the future by switching off “Wake up via Google (FCM)” under Settings > Connections. Data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision under Art. 45 GDPR. Google provides further information at Privacy and Security in Firebase.

Switching it off: under Settings > Connections you can switch off “Wake up via push” entirely. MeshUp then keeps the connection open with a foreground service (“Always connected”); if you switch that off too, MeshUp cannot be reached in the background.

4.9 Calls and walkie-talkie

Voice and video calls, group calls, screen sharing and the walkie-talkie use the same end-to-end encrypted connections as messages: directly between the devices or through a tunnel via the mesh node, which sees no content. In group calls, each device sends its audio directly to every other one; there is no conference server. If a contact’s device is asleep, it is woken up via push first (section 4.8). The app only uses the microphone, camera and screen capture during a call, recording or screen share that you start or accept yourself.

4.10 Location, emergency alerts and maps

MeshUp only uses your location when you send it yourself, share a live location (15 minutes, 1 or 8 hours, can be stopped at any time) or trigger an emergency alert. It is sent end-to-end encrypted only to the participants of the chat in question or to your emergency contacts. The location comes straight from Android, without Google services. MeshUp does not request the background location permission; a live location runs as a visible service with a notification.

The emergency alert feature is off by default. Only if you explicitly agree when triggering it is an alert also sent to all MeshUp devices nearby, including strangers. Those devices then see your name, your location and your text, and pass the alert on.

Map tiles are loaded by the app from the OpenStreetMap tile servers (tile.openstreetmap.org) run by the OpenStreetMap Foundation (St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom). The tile server receives your IP address, the map area displayed and an identifier of the app (user agent). The app caches loaded tiles on the device for a while so they don’t have to be fetched every time. The European Commission has adopted an adequacy decision for the United Kingdom (Art. 45 GDPR). The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is to show locations on a map. Under Settings > Privacy you can switch off “Load map previews”; the app then shows locations without a map image. See the OpenStreetMap Foundation’s privacy policy for more.

4.11 Link previews

If you type a link into a message, your device loads the page’s title, description and preview image after a short pause and sends them, encrypted, along with the message. As with any visit, the website receives your IP address and the time; the app identifies itself as “MeshUp-Linkvorschau” and sends no cookies. Recipients never fetch the page themselves. Under Settings > Privacy you can switch off “Generate link previews”.

4.12 Sharing contacts and events

You only share a contact from your address book or an event from your calendar if you choose “Contact” or “Event” in the attachment menu; only then does the app ask for the permission. You choose which details are included, and the card is sent end-to-end encrypted only to that chat. Apart from that, MeshUp does not read your calendar and only reads your address book for the voluntary match (section 4.7); none of it is uploaded. You can save received contacts and events via your contacts or calendar app without MeshUp needing a permission for that.

4.13 MeshUp Desktop

You pair MeshUp Desktop with your phone by scanning a QR code under “Linked devices” on the phone. The phone then connects to the computer end-to-end encrypted (Noise) on the same network – Wi-Fi or a VPN; no server is involved. On the local network, the computer announces itself via mDNS with a short identifier derived from its key, so that the phone can find it again.

Your chats stay on the phone; the computer displays them and serves as microphone, speaker, camera and screen during calls. The computer stores its own key (encrypted via the system keychain where possible), which phone it is paired with, that phone’s push address and a limited cache for loaded media such as videos. If the phone is asleep, the computer wakes it via its push address (section 4.8). The computer receives map previews ready-made from the phone, provided they are allowed there.

4.14 Updates

Android: on launch, at most every six hours, the app checks the file meshup-nightly.json on git.3dns.eu for a newer version. It only sends the request itself, identified as “MeshUp”, without cookies and without device or user identifiers. It only downloads the new version once you tap the update; Android asks before installing it. Under Settings > Help you can switch off “Check for updates automatically”; “Check for updates” then only checks when you tap it.

Computer: the Linux AppImage and the Windows installation check the update information in the same release on git.3dns.eu shortly after launch and every four hours afterwards, and download a new version in the background. This can be switched off with the environment variable MESHUP_NO_UPDATE=1.

git.3dns.eu necessarily receives your IP address and the time of the request. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is to provide bug fixes and security updates.

4.15 App permissions

MeshUp only asks for a permission when you use a feature that needs it. You can revoke permissions at any time in the Android settings; the other features remain usable.

4.16 No ads, no analytics, no Google requirement

MeshUp and MeshUp Desktop contain no ads and no analytics, tracking or crash-reporting libraries; no usage statistics are collected. The app does not need Google Play services: location comes straight from Android, maps from OpenStreetMap, and QR codes are read by a built-in library. The only Google component is Firebase Cloud Messaging for wake-ups, and it only starts with your consent (section 4.8).

4.17 Deleting data

5. Recipients and transfers to third countries

The controller runs the website, the mesh node mesh-node1.3xd.eu, the push server push-gateway.messenger.3dns.eu and git.3dns.eu himself. Beyond that, data only reaches others in the cases described:

Messages and other content are only received by the people you communicate with.

6. Contacting us

If you contact us by email or phone, the details you provide (such as name, email address, phone number and the content of your message) are processed to handle your enquiry and any follow-up questions. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in answering enquiries) or Art. 6(1)(b) GDPR if your enquiry concerns a contract, such as a licence for commercial use. The data is deleted once your enquiry has been dealt with, unless statutory retention obligations apply. It is not passed on to third parties.

7. Data security

The website is only available via HTTPS; requests over unencrypted HTTP are redirected to HTTPS. MeshUp encrypts every connection between devices, to the mesh node and to the paired computer with the Noise protocol. In addition, appropriate technical and organisational measures are taken to protect the data processed against loss, misuse and unauthorised access.

8. Your rights

Subject to the statutory requirements, you have the following rights regarding the personal data concerning you:

To exercise your rights, an informal message to info@dom1nic.eu is sufficient. Because MeshUp works without accounts and the controller receives neither names, plain-text phone numbers nor content, he often cannot attribute data to a person (Art. 11 GDPR). In that case, please provide details that allow your data to be found, such as your MeshUp key. Most of your data is managed by you in the app anyway.

Right to object

Where processing is based on Art. 6(1)(f) GDPR, you may object to it at any time on grounds relating to your particular situation. You can also end many of these processing operations yourself by switching off the respective feature in the app.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for the controller is:

Sächsische Datenschutz- und Transparenzbeauftragte (Saxon Data Protection and Transparency Commissioner)
Devrientstraße 5
01067 Dresden, Germany
www.datenschutz.sachsen.de

9. Obligation to provide data, automated decisions

You are under no statutory or contractual obligation to provide personal data. Without the technically necessary connection data, however, the website and connections via mesh node and push cannot be used; MeshUp itself works without a phone number, email address or account. There is no automated decision-making, including profiling (Art. 22 GDPR).

10. Changes

This privacy policy is updated when the website, MeshUp or the legal situation changes. The version published here applies.