Mesavo

Privacy

Data minimization is part of the product logic, not just legal copy.

Mesavo only asks for data needed for sign-in, verification, security and operation.

For privacy questions, you can reach us directly through the contact address below.

Controller

NET-LINE Online-Dienste GmbH

This entity determines the purposes and means of the processing described here.

Company

NET-LINE Online-Dienste GmbH, Wannenäckerstr. 25, D-74078 Heilbronn

Scope

This notice covers mesavo.app and the native Mesavo app for iOS and Android. Store disclosures are kept aligned with the released app version.

Website & browser storage

Technically necessary operation without advertising tracking

The public information and legal pages do not use analytics, advertising or cross-site tracking services.

Server access

When a page is requested, the technical infrastructure processes in particular the requested URL, time, IP address, user agent, referrer, and status and error data. This is necessary for delivery, stability and abuse prevention and is based on GDPR Article 6(1)(f).

Cookies & local storage

We do not place non-essential cookies or comparable tracking technologies on the public information and legal pages. Technically necessary session and security information may be stored in the browser only when messenger, sign-in or account features are used.

No decisions under GDPR Article 22

There is no profiling or solely automated decision-making producing legal or similarly significant effects. Automated content pre-checks may prevent publication; reporting, support and human review remain available.

Principles

What Mesavo stands for

These principles apply to the website and shape the app interface too.

Minimal data collection

Only information required for sign-in, verification, security and product operation is requested.

No contact sync

There is no address-book access, no contact permission and no silent contact import.

Transparent auth explanations

When email or phone number are used, the purpose is explained briefly, clearly and directly.

Data we process

Accounts, communication, devices and user-initiated calls

The data involved depends on the features you actually use.

Account & sign-in

User ID, email address, optional phone number and linked sign-in methods for sign-in, verification, recovery and account linking.

Apple & Google Sign-In

If you voluntarily choose Sign in with Apple, we receive your unique Apple account identifier and, depending on your choice and generally only on first authorization, your email address and name. If you choose Hide My Email, Apple provides a private relay address. With Google Sign-In, we receive your unique Google account ID, verified email address, first name and last name. We use and store this information solely to sign in to, create or securely link your Mesavo account with the selected provider. Mesavo does not request access to Apple or Google contacts, messages, Drive or iCloud files, or other provider content.

Apple · Google

Messages & media

Message text and images, videos or voice messages you choose. Camera and microphone are used only after you start a capture or call.

Smart dictation

When you choose smart dictation, Mesavo asks for explicit consent before each new recording. Only after you consent is the microphone recording sent to OpenAI solely for transcription. Without consent, no recording starts and you can continue writing messages without this optional feature.

OpenAI

Calls & account linking

Audio/video data during a call plus call offer, call state, a short-lived QR challenge, and an explicitly selected link to another messaging profile for setup, delivery, security, and revocation.

Optional billing metadata

A normal Mesavo account shows no prices, coins, or paid content and offers no purchase path. Only if you explicitly link a separate messaging profile may existing price or access metadata from that profile be displayed and processed for a reliable status representation; Mesavo does not sell that content.

Device & push

Installation ID, a pseudonymous device identifier derived from the Android ID, app version, device model, operating-system version and push token for device management, notifications, abuse prevention and troubleshooting.

Mesavo content safety

Text, images, and videos published directly in Mesavo messages or Mesavo Channels are automatically checked against the Community Standards. Text is checked by our own compliance infrastructure on dedicated servers at Leaseweb, while images and videos are checked by Amazon Rekognition and Amazon Rekognition Video. Separately linked message stores are not changed by this Mesavo filter. Reports, blocks, and human review remain available in addition.

Text · Bild · Video

Purposes & recipients

Product operation without advertising tracking

We do not sell personal data or use it for third-party advertising or data brokerage.

Product functions

Processing for sign-in and recovery, messaging, media upload, push delivery, QR linking and audio/video calls.

Call billing

Billing data is used to show the price before a live call, perform debits atomically and accountably, prevent duplicate charges, process required refunds, and meet statutory accounting or evidence duties.

Safety & support

Processing to fulfil deletion requests, prevent and investigate abuse through automated and human review, and diagnose technical failures.

OpenAI dictation

Only when you consent immediately beforehand and start smart dictation does Mesavo send the microphone recording to OpenAI Ireland Limited or its technical subprocessors for transcription. The transfer is used solely for the conversion to text that you requested.

OpenAI

Optional external delivery

External delivery configured outside the app processes new Channel content only after it has been explicitly authorized and activated for the relevant destination. Mesavo 1.2 contains no setup or controls for external destinations. Revocation or deactivation stops future transfers.

Google sign-in

When you choose “Continue with Google”, your device or browser and our sign-in service exchange the technically required OAuth/OpenID data with Google Ireland Limited. Mesavo requests only the openid, email and profile scopes, uses them solely for sign-in and account linking, and receives neither your Google password nor access to contacts or other Google services.

Google Identity

Contracted service providers

Data is processed only as needed by contracted providers. These include Amazon Web Services for hosting, storage, and image or video moderation; Leaseweb for our own text-compliance infrastructure; OpenAI for dictation started only after consent; and Apple and Google for the selected sign-in, push, and device functions. They act under our instructions and safeguards.

International transfers

Some sign-in, push, device-platform, or explicitly selected OpenAI transcription providers may process data outside the EEA. Where this occurs, transfers rely on an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses. Information about specific safeguards and copies is available via datenschutz@netline-services.de.

Legal disclosure

Disclosure to authorities or others occurs only when legally required or needed to protect rights and safety.

Retention & protection

Only as long as needed for each purpose

Retention depends on the data category, user choice, security needs and legal obligations.

Account & content

Account deletion is processed by data category. Deletable account data, messages and media are deleted or anonymised after verified completion. Categories retained for legal, security or evidentiary reasons remain for their applicable period; backups expire under their related protection and rotation periods.

Billing evidence

Coin and call billing data is handled separately from deletable communication content. It is retained only as long as required for open debits or refunds and statutory accounting, tax, fraud-prevention, or evidence duties, and is then deleted or anonymised under the applicable rule.

Short-lived linking data

Unused QR challenges expire after five minutes. Device/push registrations and links to additional messaging profiles remain active only until sign-out, revocation, invalidation or verified processing in the account-deletion workflow.

5 min

Technical logs

Security, delivery and error logs are kept only for each service's limited operational retention period and then deleted or aggregated unless a specific security or legal case requires longer preservation.

Technical protection

Transport protection, role/purpose-bound access, short-lived tokens, revocable device/QR links and protected secrets limit access. App tokens are stored in protected device storage.

Data subject rights

Access, correction, deletion and objection

You can exercise your rights directly through the privacy contact. Account and deletion processes are also available in the app.

Access & copy

You can request information about personal data being processed and obtain a copy.

Correction, restriction & portability

You can have inaccurate data corrected, restrict processing where the legal conditions apply, and receive provided data in a portable format.

Account deletion

The app accepts a confirmed deletion request for processing with HTTP 202 Accepted and provides a receipt status that can be checked without signing in. This is not proof of completion; without complete cross-store and Apple evidence, the status remains manual-review-required. An email request is available without app access.

Objection & withdrawal

You can object to processing based on legitimate interests for reasons relating to your particular situation. Consent can be withdrawn at any time with future effect.

Privacy contact

Requests concerning any of these rights go to datenschutz@netline-services.de.

Direct

Right to complain

You may lodge a complaint with a data-protection supervisory authority. For the company seat, the Baden-Württemberg State Commissioner for Data Protection and Freedom of Information is available in particular.

Privacy notice version

28 July 2026

We update this notice when features, recipients or legal requirements change materially.