UPDATED OCTOBER 2, 2026

Privacy Policy

This policy applies to all MeshWatch products: SyslogWatch, DeviceWatch, TrafficWatch, CertWatch, ConfigWatch, TrapWatch, MeshServerWatch, MeshWatch Central, and SecureServe, on macOS, Windows, and Linux — and to MeshWatch Central and the MeshServerWatch Manager wherever you choose to run it (your own server, VM, or cloud account).

Data processed

Each app processes only the data needed to do its job, configured by you: SyslogWatch receives syslog messages from devices you point at it; DeviceWatch polls devices you add over SNMP; TrafficWatch observes DNS queries from devices on your own network; CertWatch connects to the hosts you name and reads the TLS certificates they present; ConfigWatch connects over SSH to network devices you add with a read-only account and stores their configuration, masking credential-shaped values before anything is written to disk; MeshServerWatch Agent, installed on servers you choose, sends numbers and one-line summaries — a hashed machine identifier (never the raw machine ID), host name, IP address and aliases, operating-system name, agent version, uptime, CPU, memory and per-disk usage, load averages on Linux, and for each error-level event-log or journald entry its severity, log, source, event ID, time and a summary of at most 300 characters (never the full message text, event XML, user SIDs, user names, process lists or command lines) — only to the MeshServerWatch Manager you run and configure; SecureServe handles files and accounts on your own server; MeshWatch Central receives short, allow-listed summaries (severity, device name, a category, one line of text) from whichever of the other products you connect to it. This can include IP addresses, host names, application names, timestamps, and event details, plus any alert rules and settings you create.

Storage and transmission

Data and settings are stored locally on your own computer or server — macOS, Windows, or Linux — or, for MeshWatch Central and the MeshServerWatch Manager, on the server you choose to run it on. MeshWatch apps do not send this data to MeshWatch, analytics providers, or advertising networks.

If you enable email alerts, matched event details are sent only through the SMTP server and recipient you configure. If you connect a product to your own MeshWatch Central instance, only the allow-listed summary fields above are sent to the address you configure — never raw logs, configuration files, certificates, private keys, or packet captures. SMTP credentials, device credentials, and Central connection tokens are stored using your operating system's encrypted credential storage (or, for Central itself, in its own data directory on the server you control).

To keep a 30-day trial from restarting when the app's data folder is deleted, the desktop apps also record when the trial started in a small file or registry value outside that folder (macOS: ~/Library/Preferences; Windows: the current user's registry under HKCU\Software\MeshWatch and %LOCALAPPDATA%\MeshWatch; Linux: ~/.local/share/meshwatch and ~/.config/meshwatch). It holds only the trial start time and the latest time the app was seen, and it never leaves your computer.

The MeshServerWatch Manager keeps its trial record and licence key in licence.json inside its own data folder on the server you run it on (Windows: C:\ProgramData\MeshServerWatch\Manager\data\; Linux: /var/lib/meshserverwatch/manager/), together with the list of servers counted against its licence seats. The trial record holds the trial start and the latest time the Manager was seen running. None of it leaves that server. The Manager stores agent tokens only as hashes, and its SMTP password and Central token in settings.json, readable only by the service. It makes no outbound connection unless you configure SMTP or Central, or switch on its once-a-day update check, which is off by default and carries none of the data described above.

The desktop apps check for a newer version about once a day by downloading a small version file from meshwatch.app. That request carries none of the data described above.

Website

meshwatch.app keeps aggregate counts only: how many times each file was downloaded, from which country (taken from the request; no IP address is stored), by which browser family, and from which website the visitor originally arrived. For that last item the page remembers the referring site's domain name — or the utm_source value in the link you followed — in your browser's local storage for 30 days and attaches it to the download request. No path, search terms, cookie, or identifier is stored, and nothing is sent anywhere except to meshwatch.app itself. Page visits are measured with Cloudflare Web Analytics, which uses no cookies and no persistent identifier.

Previous versions

Downloading an earlier release from meshwatch.app/downloads/previous/ requires signing in. If you sign in by email, we store the company name and email address you enter, the time of each sign-in, and the names of the files you download, together with the times — nothing else. If you sign in with a licence key, the key is checked by its signature and not stored; the email address and organisation written inside the key are recorded in the same way. The sign-in link is single-use and expires after 15 minutes; it is stored only as a hash. To limit abuse, the number of sign-in requests per email address and per network address is counted for one hour, using hashes rather than the addresses themselves. Sign-in keeps a cookie (mw_prev) in your browser for 30 days, sent only to the download service on this site. These records exist to support customers and to control the distribution of older builds; they are kept for up to three years after the last sign-in, are not used for marketing, and are not shared. The legal basis under the GDPR is our legitimate interest in keeping a record of software distribution. To see or delete your record, email support@meshwatch.app from the address concerned.

Control and responsibility

The data these apps observe can contain personal or security-sensitive information. Connect only devices, networks, hosts, and servers you own or are authorised to administer, and follow applicable organisational policies and laws.

Contact

Operator: MeshWatch
Email: support@meshwatch.app · YouTube · GitHub