Meshy
meshy.aiMeshy is an AI-powered 3D modeling platform with mixed privacy practices. While paid users retain ownership of their outputs, free users' content is owned by Meshy and licensed back under CC BY 4.0. The platform uses non-enterprise user content for model training, has broad data collection practices, and lacks clear opt-out mechanisms. Enterprise customers receive better data protection terms.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain ownership of their input data (prompts, images, files). Meshy receives only a license to use inputs as necessary to provide the service.
Output Data Ownership
Ownership depends on subscription tier: Free users don't own outputs (Meshy owns them and licenses back under CC BY 4.0), while paid users retain ownership. This creates significant risk for free tier professional use.
Training Data Usage
Meshy uses content from non-enterprise customers to train and improve their models. Only Enterprise customers are excluded from this practice, creating a significant distinction between user tiers.
Data Retention & Deletion
Retention varies by tier: Enterprise data retained indefinitely unless configured otherwise (1-30 days), API users' data deleted after 3 days, webapp users subject to unspecified storage limits. Users can request deletion but process is not clearly defined.
Third-Party Data Sharing
Data is shared with various service providers including security, advertising, and hosting providers. While not sold to third parties, the scope of advertising-related sharing raises concerns for professional use.
Opt-Out Rights
Limited opt-out rights exist primarily for marketing communications. The policy lacks clear opt-out mechanisms for model training or broader data collection, though users can configure some retention settings.
Compliance & Certifications
Claims compliance with GDPR and CCPA/CPRA, mentions Privacy Shield for Google Analytics, but lacks evidence of third-party certifications like SOC 2, ISO 27001, or formal audits.
Model Explainability & Auditability
No mention of model explainability, transparency into AI decision-making, or enterprise audit capabilities. The service operates as a black box with no documented audit trail provisions.
Security Practices & Breach History
General security commitments mentioned including encryption, access controls, and dedicated security team, but lacks specific technical details or certifications. No breach history disclosed. References a security email for vulnerability reports.
Enterprise vs. Consumer Risk Delta
Significant differences between tiers: Enterprise customers get indefinite data retention, exclusion from model training, and better privacy protections. Free users don't own their outputs and all content is used for training.
Human Review of User Inputs
Policy doesn't explicitly state whether staff can access user content, but implies possible access for security and service improvement purposes. Employees with access must sign confidentiality agreements.
Regulatory & Litigation Exposure
Standard provisions for law enforcement cooperation and government data requests. DMCA takedown procedures in place. Arbitration clause may limit litigation options.
PII & SPI Data Inventory
Collects standard PII including email, IP addresses, device info, and usage data. Financial information collected for payments. Policy prohibits users from submitting sensitive personal data but doesn't prevent collection of behavioral/usage patterns that could be sensitive.
You've read all 15 risk ratings for Meshy. Create a free account to see the exact policy wording behind each rating.