Legal
Privacy Policy
Last updated 12 June 2026 · Topcmesh Labs, Inc.
1 · Who we are
Topcmesh Labs, Inc. is a Delaware corporation operating the topcmesh realtime topic mesh. This policy covers the marketing site at www.topcmesh.com and the mesh itself at bus.topcmesh.com. Questions go to [email protected].
This document describes what we actually hold and for how long. Where a retention period is short, that is a property of how the mesh is built rather than a policy choice we could quietly reverse.
2 · What passes through the mesh
Message payloads you publish transit the mesh and are held in a topic's retention buffer for that topic's configured window — between 60 seconds and 24 hours depending on your tier and your own configuration. When the window elapses the buffer region is overwritten. There is no archive, no cold storage, and no second copy.
Within that window we do not index payloads, do not analyse them, do not use them to train anything, and do not read them. Access by our staff requires a support request that you, the namespace owner, initiate in writing, is scoped to the specific topic and time range you name, and is written to your namespace log where you can see it.
Because the buffer is finite and short, the mesh is not a system of record. Do not publish anything to a topic that you do not also hold somewhere durable.
3 · Connection metadata
For every subscriber connection we record, and retain for 30 days:
- Connection ID, namespace ID, and the list of topics attached
- IP address and the coarse geographic region derived from it
- User agent string as presented at handshake
- Attach and detach timestamps, and the close code
- Bytes delivered, and any
slow_consumerevents with the buffered byte count
This is the data that makes your namespace log useful, and it is what we rely on for abuse prevention, capacity planning and incident investigation. After 30 days it is deleted; aggregate counts with no connection-level detail are kept for capacity trending.
4 · Account and cohort data
If you request a cohort seat we collect the name and work email you supply, your company, the description of what you would publish, and the two structured answers about scale and current setup. We retain cohort requests for 24 months so that we can place returning applicants in the right cohort without asking them to repeat themselves.
For namespace owners we hold billing contact details and the invoicing record required by law. Payment card data is handled entirely by our payment processor; we never see or store a full card number.
Analytics on the marketing site are first-party, aggregate, and cookieless. We count page views and referrers. We do not build a profile of you, and there is no third-party tracking script on any page of this site.
5 · What we never do
- We do not sell personal data, and we have no arrangement that resembles selling it
- We do not share data with advertising networks, and we run no advertising
- We do not retain payload content beyond a topic's retention window
- We do not read your payloads for product development, benchmarking or model training
6 · Subprocessors
We use cloud infrastructure providers in each of the regions listed on our status page, one transactional email provider for account and incident mail, and one error-monitoring provider that receives stack traces from our own services. None of them receive message payloads. The current list, with entity names and locations, is available on request to [email protected], and namespace owners are notified 30 days before a new subprocessor is added.
7 · Security
All traffic to the mesh is TLS 1.3. Retention buffers are encrypted at rest with per-namespace keys. Access to production systems is role-scoped, requires hardware-backed authentication, and is logged. Tokens are signed with rotating keys identified by the kid claim, so a signing key can be retired without invalidating live connections.
To report a vulnerability, email [email protected]. We acknowledge within one business day and will not pursue legal action against good-faith research that stays within your own namespace.
8 · Your rights
You may request access to the personal data we hold about you, correction of anything inaccurate, deletion, a portable copy, or that we stop processing it. Write to [email protected] and we will respond within 30 days.
Where the GDPR applies, our legal basis is contractual necessity for account and connection data, and legitimate interest for abuse prevention. Where the CCPA applies, you have the right to know, delete, and opt out of sale — the last of which is moot, since we do not sell data. International transfers are covered by standard contractual clauses.
9 · Children
topcmesh is developer infrastructure sold to businesses. It is not directed at anyone under 16 and we do not knowingly collect their data. If you believe we have, write to [email protected] and we will delete it.
10 · Changes
Material changes to this policy are announced by email to namespace owners at least 30 days before they take effect, and the effective date at the top of this page is updated. Minor corrections are made without notice.
11 · Contact
Topcmesh Labs, Inc.
2261 Market Street, San Francisco, CA 94114, United States
[email protected]