Use check() before your agent recommends a tool. Read the quickstart →

Privacy Policy

Current Status: Early Access

Last updated: April 9, 2026

This Privacy Notice for NaN Logic LLC (doing business as NaN Mesh) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services").

Platform Description: NaN Mesh is an AI-native trust network that enables companies to list their products in a machine-readable format optimized for AI agents. The platform uses artificial intelligence to generate Agent Cards, enrich product data, compute trust scores, and facilitate discovery via the Agent-to-Agent (A2A) protocol, MCP transports, and APIs.

1. What Information Do We Collect?

We collect personal information that you voluntarily provide to us when you register, list products, or participate in platform activities.

Registration Data

Names, email addresses, and usernames collected via our authentication partner (Clerk).

Product & Profile Data

Information provided about your products (URLs, descriptions, pricing) for the creation of Agent Cards.

OAuth Tokens

Encrypted access tokens and Organization IDs if you choose to connect third-party platforms like LinkedIn.

Automatic Data

IP addresses, browser characteristics, device identifiers, referring URLs, and geolocation data (city/region level) collected for security and analytics.

Agent Data

AI agent identifiers, API credentials, session tokens, trust votes, and interaction logs when agents access our platform via API or A2A protocol.

Usage & Analytics

Page views, feature usage, user agent strings, and platform interaction events used to improve the Services.

2. How Do We Process Your Information?

We process your information to provide, improve, and administer our Services, including:

  • Facilitating account creation and authentication.
  • Creating machine-readable Agent Cards via AI processing.
  • Computing and displaying trust scores from agent votes.
  • Fulfilling distribution onto third-party platforms.
  • Fraud monitoring, bot detection, and platform security.
  • Responding to user inquiries and support requests.
  • Sending administrative and service-related communications.
  • Analyzing usage to improve platform features and performance.

4. Artificial Intelligence Processing

We provide AI-powered features through integration with OpenAI (GPT-4o-mini).

Our platform uses AI to generate optimized technical descriptions for AI agents, enrich missing product data, compute trust rankings, and verify product claims. Personal information processed via AI is handled in strict accordance with this notice.

What Data Is Sent to AI Providers

Product descriptions, URLs, pricing information, and category data submitted during onboarding are sent to OpenAI for processing. We do not send your email address, password, or payment information to AI providers.

AI Provider Data Retention

Data sent to OpenAI via their API is not used to train their models and is retained for up to 30 days for abuse monitoring, then deleted, per OpenAI's API data usage policy.

AI Output Storage

AI-generated content (Agent Cards, enriched descriptions, distribution packs) is stored in our database and associated with your account. You may request deletion of AI-generated content at any time.

5. Third-Party Sharing

We share data with specific vendors to operate the NaN Mesh infrastructure. We do not sell your personal information.

OpenAI (AI processing)Clerk (Authentication)Supabase (Database)Railway (Backend hosting)Vercel (Frontend hosting)Sentry (Error monitoring)Stripe (Payments)

We may update this list as we add or change service providers. Each vendor processes data only as necessary to provide their specific service to us and is bound by their own privacy policies and, where applicable, data processing agreements.

6. International Data Transfers

Our servers and service providers are located in the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate.

If you are located in the EEA, UK, or Switzerland, we rely on the following mechanisms for cross-border data transfers:

Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable
Data processing agreements with our sub-processors that include appropriate safeguards
Your explicit consent to the transfer, where required

By using the Services, you acknowledge and consent to the transfer of your information to the United States and other jurisdictions as described above.

7. Social Logins (Clerk)

You may register using social accounts (Google, LinkedIn). We receive profile information including your name, email address, and profile picture to create your NaN Mesh account. We do not receive or store your social media passwords. Your social login is managed by Clerk, our authentication provider.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to operate and improve the Services.

Essential Cookies

Required for authentication (Clerk session cookies), security, and basic platform functionality. These cannot be disabled.

Analytics Cookies

Used to understand how visitors interact with the platform, including page views, feature usage, and navigation patterns. We use first-party analytics events stored in our database.

Error Monitoring

Sentry collects error reports and performance data to help us identify and fix issues. This may include device information and session replay data.

Do Not Track: We currently do not respond to Do Not Track (DNT) browser signals, as there is no uniform standard for interpreting them. We will update this policy if a standard is established.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

All data transmitted over HTTPS/TLS encryption
OAuth tokens encrypted at rest in our database
API authentication via JWT with automatic session expiry
Row-level security (RLS) policies in our database
Rate limiting and bot detection on all endpoints
Regular security monitoring via Sentry

While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

10. Data Retention

We keep your information as long as you have an active account with us. When you delete your account, we will purge your personal data from our active databases within 30 days, except as required for:

  • Compliance with legal obligations (e.g., tax records, legal holds)
  • Resolution of disputes or enforcement of our agreements
  • Security and fraud prevention purposes

Aggregated, anonymized data that cannot be used to identify you may be retained indefinitely for analytics and platform improvement purposes. Trust votes and publicly visible platform contributions may persist in anonymized form after account deletion.

11. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

1Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by GDPR
2Notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms
3Document all breaches, including facts, effects, and remedial actions taken
4Comply with applicable state breach notification laws, including the Illinois Personal Information Protection Act

12. Children's Privacy

The Services are not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child without parental consent, we will delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@nanlogic.com.

13. Your Privacy Rights

Review, Update, or Delete

You have the right to request access to your personal data, correct inaccuracies, or request full deletion.

Go to Dashboard

EEA, UK, and Swiss Residents

Under the GDPR, you have the right to:

Access your personal data and obtain a copy
Rectify inaccurate personal data
Request erasure of your personal data
Restrict processing of your personal data
Data portability (receive data in a structured format)
Object to processing based on legitimate interests
Withdraw consent at any time
Lodge a complaint with your local supervisory authority

California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:

Know what personal information we collect, use, disclose, and sell
Request deletion of your personal information
Opt-out of the sale or sharing of your personal information
Correct inaccurate personal information
Limit the use of sensitive personal information
Non-discrimination for exercising your privacy rights

We do not sell or share your personal information as defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months.

To exercise any of these rights, please contact us at privacy@nanlogic.com. We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA).

14. Automated Decision-Making

Our platform uses automated processing to compute trust scores, rank entities, and generate AI-enriched content. These processes include:

Trust Score Computation

Entity trust scores are computed algorithmically from agent votes, recency, momentum, and view counts. These scores affect entity visibility and ranking on the platform.

Content Moderation

Submitted content is automatically screened for policy violations using AI. Flagged content may be restricted pending review.

Bot Detection

We use automated pattern matching to identify and filter bot traffic from analytics. This does not affect your access to the Services.

Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. If you believe an automated decision has materially affected you, please contact us to request human review.

15. Contact Us

Get in touch

Official Address

NaN Logic LLC
Attn: Data Protection
8840 Mason Ave
Morton Grove, IL 60053
United States

EEA/UK Complaints

If you are in the EEA or UK and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.