SyncMesh privacy
Last updated 19 September 2026
What SyncMesh is
SyncMesh lets you share selected notes from your AI with a specific person, who sees them in their own AI. Everything is private unless you choose someone to share it with. It is a small personal project run by Jason Hopkins.
What is stored
From Google sign-in: your email address and display name. Your email address is how other people address shares to you. SyncMesh asks Google for nothing else and never sees your Google password, mail, contacts or files.
What you publish: the text, topic tags, recipient and optional expiry of each item you or your AI publish to your vault.
Invites: the email address of anyone you invite, so the invite can only be accepted by them.
An activity log: a record of actions such as "item published", "item shared with this address", "item fetched" and "connection made", with who did it and when. The log holds this metadata only. It never contains the text of an item.
Who can see it
A private item is visible only to you. A shared item is visible to you and the one person you shared it with. People you are connected to cannot browse your vault.
SyncMesh has a small number of administrators. Their console shows the activity log and counts: who has joined, who is connected to whom, who shared with whom and when, and what is still unread. It has no way to show the text of an item.
The operator can technically access the database, as with any hosted service, but does not read item contents; running the service relies on the activity log, which has no item text in it. End-to-end encryption, so that the server cannot read item text at all, is planned.
Nothing is sold, used for advertising, or given to anyone else. Data is held by the service providers SyncMesh runs on: Supabase (database and sign-in, hosted in Japan), Vercel (this website) and Resend (which sends the emails below; it is given the recipient address and the email itself).
Emails
SyncMesh sends a few emails, from invites@syncmesh.net: an invite when someone asks to connect with you, setup steps once you accept, a note when you are invited to a group, and a note when something is shared with you. They say who did something and, for a group, which group. They never say anything about what was shared: not the text, and not its topic tags. They carry no tracking: links are not rewritten and opens are not recorded. Replies go to the operator.
If someone invites you or shares with you before you have an account, your address is used to send you that one email. You can turn off the share and group emails in your dashboard. A record of which emails were sent, to which address and when, is kept with the activity log.
Your AI
When you connect an AI assistant such as Claude, you approve its access on a consent page. It can then publish items to your vault and fetch what you have published and what others have shared with you, acting as you. What your AI provider does with what it reads is covered by that provider's own policy. You can disconnect it at any time from the assistant's settings.
Deleting your data
Once someone has read an item you shared, it cannot be unread, but you can ask for any item or your whole account to be deleted. Deleting your account removes your vault, your items and your connections. The activity log is kept as a permanent record of actions, so its entries (which include your email address but no item text) remain.
To delete something or ask a question, email jason.hopkins.tf@gmail.com.