Mesa
About Features Plans Download
Sign in Get the app
Legal

Privacy Policy

Last updated: 22 July 2026  ·  Effective: 22 July 2026

Mesa is a personal memory journal — a private place to keep the experiences that mattered, the people who were there, and the photos worth holding on to. This policy explains what information we collect, why we collect it, who we share it with, and the choices you have. We've written it to be read, not skimmed past.

Who we are

Mesa ("Mesa", "we", "us" or "our") provides the Mesa mobile app and web app (together, the "Service"). For the purposes of the UK GDPR and EU GDPR, Mesa is the data controller for the personal information described in this policy.

If you have any questions about this policy or your data, contact us at privacy@mymesa.app.

Information we collect

Information you give us

  • Account details — your name and email address, used to create and secure your account.
  • Your memories — the experiences you create, including titles, dates, places, notes and any details you add.
  • Photos — images you upload or import to attach to an experience.
  • Companions — the names of people you add to an experience, and the email address of anyone you invite to join as a companion.
  • Support messages — anything you send us when you ask for help or get in touch.
  • iOS waitlist — if you ask to be told when Mesa arrives on iOS, we store the email address you give us for that one purpose. You don't need an account, we don't add you to any mailing list, and every message includes a link to remove yourself.

Information collected automatically

  • Device & usage data — basic technical information such as device type, operating system, app version, and log data needed to run the Service and diagnose problems.
  • Notification tokens — if you enable push notifications, a device token so we can send them.
Mesa does not collect your precise (GPS) location. When you add a place to an experience, that's a name you type or select — not a reading taken from your device.

Information from connected services

Some Mesa features work by connecting to services you already use. You choose whether to connect them, and you can disconnect at any time.

  • Google sign-in — if you sign in with Google, we receive your name, email address and profile identifier to authenticate you.
  • Google Photos — if you connect Google Photos, we access the photos you select in order to import them into an experience. We only use them for that purpose.
  • Google Calendar — if you connect Google Calendar, we read your calendar list so you can choose which calendar to import from, and read events from that calendar so you can turn one into an experience with its title, date and place filled in. Access is read-only: we never create, change or delete anything in your calendar.
  • setlist.fm — if you add a concert, we use setlist.fm's public data to fetch the setlist for that show. We store the setlist alongside your experience.

Mesa's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features described above. We do not sell it, use it for advertising, use it to train generalised AI or machine-learning models, or transfer it to others except as needed to provide those features, for security purposes, or where required by law.

How we use your information

We use the information above to:

  • Provide the Service — store your memories, photos and companions, and show them back to you across your devices;
  • Authenticate you and keep your account secure;
  • Enable sharing and companion features you choose to use;
  • Send push notifications you've opted into;
  • Email you once, if you asked to be told when Mesa launches on iOS;
  • Provide customer support and respond to your requests;
  • Maintain, troubleshoot and improve the Service;
  • Comply with our legal obligations and enforce our terms.

Legal bases for processing

Where the UK/EU GDPR applies, we rely on the following legal bases:

  • Contract — to provide the Service you've signed up for.
  • Consent — for optional features such as connecting Google Photos or Google Calendar, enabling push notifications, or joining the iOS waitlist. You can withdraw consent at any time.
  • Legitimate interests — to keep the Service secure, prevent abuse, and improve how it works.
  • Legal obligation — where we're required to retain or disclose information by law.

Sharing your information

We do not sell your personal information, and we do not use it for advertising. We share information only in these limited cases:

WhoWhy
Microsoft AzureCloud hosting, database and account sign-in (Azure AD B2C). Your data is stored on Microsoft's infrastructure.
Google / FirebaseGoogle sign-in, Google Photos and Google Calendar import (when connected) and delivery of push notifications.
setlist.fmFetching concert setlist data when you add a gig.
Apple & GoogleApp distribution and, if you subscribe in future, payment processing through their app stores.
Companions you invitePeople you tag or invite can see the experiences you choose to share with them.
Anyone with a public linkIf you create a public share link for an experience, anyone who has that link can view it (its title, date, place, photos and any setlist) until you revoke it or it expires. Companion names and your tags are not shown.
Legal & safetyWhere required by law, or to protect the rights, safety and security of Mesa and its users.

These providers process data on our behalf under their own security and privacy commitments, and only for the purposes described here.

Sharing with companions

Mesa is built around shared memories. When you add someone as a companion or tag them in an experience, information about that experience — including its title, date, place and photos — may be visible to them. Your journal stays yours: nothing is added to another person's library unless they choose to keep it, and tagged-in experiences land in their inbox rather than their journal automatically. Please only add details and photos you're comfortable sharing with the people involved.

Public share links

You can create a public link to an individual experience to show it to someone who doesn't use Mesa — a friend, a family member, anyone you choose. Creating a link is entirely optional and always starts with you: no experience is ever public unless you deliberately make it so.

A share link is exactly that — public. Anyone who has the link can open the page in a web browser and view that experience, with no Mesa account needed — and if they pass the link on, others can view it too. The page shows the experience's title, date, place, photos and (for concerts) its setlist. It does not show the names of the companions tagged in the experience, or your private tags.

You stay in control. Each experience has a single link that you can switch off at any time from the app — once revoked, it stops working for everyone immediately. Links also expire on their own after a set period. We ask search engines not to index shared pages, but a public link should still be treated as public: only share experiences you're comfortable anyone seeing.

Data retention

We keep your information for as long as your account is active. If you delete an experience or a photo, it is removed from your account. If you delete your account, we delete your personal data and content within a reasonable period, except where we're required to retain certain information to meet legal obligations. Backups are cycled out on a rolling basis.

If you joined the iOS waitlist, we keep your email address only until Mesa launches on iOS and we've let you know — after that it's deleted. You can ask us to remove it sooner at any time.

Your rights and choices

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you;
  • Correct information that's inaccurate or incomplete;
  • Delete your account and associated data;
  • Object to or restrict certain processing;
  • Request a copy of your data in a portable format;
  • Withdraw consent for optional features at any time.

You can delete your account and its data directly in the app. To exercise any other right, email privacy@mymesa.app and we'll respond within the time required by applicable law. If you're in the UK or EU and unhappy with how we've handled your data, you may also complain to your local data protection authority (in the UK, the Information Commissioner's Office).

Security

We use industry-standard measures to protect your information, including encryption in transit, access controls, and reputable cloud infrastructure. No system is ever completely secure, but we work to keep your memories safe and to respond quickly if something goes wrong.

International transfers

Your information may be processed on servers located outside your country, including by the providers listed above. Where data is transferred internationally, we rely on appropriate safeguards (such as standard contractual clauses) to protect it.

Children

Mesa is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we'll delete it.

Changes to this policy

We may update this policy from time to time. When we make material changes, we'll update the "Last updated" date above and, where appropriate, let you know in the app. Your continued use of Mesa after an update means you accept the revised policy.

Contact us

Questions, requests or concerns about your privacy? Email us at privacy@mymesa.app and we'll be glad to help.

Mesa

A private, beautiful record of everything worth remembering — and everyone you were with.

Product

  • Features
  • Pricing
  • Download

Company

  • About
  • Contact

Legal

  • Privacy
  • Terms
© 2026 Mesa. All rights reserved.
Privacy Terms