MekaDesk Back home

Legal

Privacy Policy

Last updated August 8, 2026 · 14 sections

The short version

  • MekaDesk is a shared inbox, so it stores the messages and contacts of the Telegram, Messenger, and Instagram accounts you connect.
  • We never sell your data and never use message content for advertising.
  • Your team sees your conversations, according to each member’s role. A small number of MekaDesk operators can access account records to run the platform.
  • The mobile app asks for the microphone, camera, photos, files, and location only when you use the matching feature to attach something to a chat. Location is never tracked in the background.
  • You can disconnect at any time from Telegram or Facebook, which stops new messages from reaching us.

A summary for orientation only — the full text below is what applies.

Jump to a section
  1. 01Overview
  2. 02Channels we connect to
  3. 03What we collect
  4. 04How we use it
  5. 05Telegram’s role
  6. 06Meta’s role (Messenger & Instagram)
  7. 07How media is handled
  8. 08The mobile app & device permissions
  9. 09Storage & security
  10. 10Who can see your data
  11. 11Retention
  12. 12Your choices
  13. 13Changes to this policy
  14. 14Contact

01Overview#

This Privacy Policy explains what data MekaDesk collects, why, and how we handle it. It covers both the web dashboard and the Meka Desk mobile app for iOS and Android. MekaDesk is a shared team inbox for messaging channels, so by design it processes the messages and contacts of the accounts you connect. We aim to collect only what the Service needs to work.

02Channels we connect to#

MekaDesk can connect three kinds of accounts. Each connected account is a separate inbox, and its conversations, contacts, and messages are kept scoped to it.

  • Telegram:a personal or business account that enables our bot through Telegram’s official Business API.
  • Facebook Messenger: a Facebook Page you manage, connected with Facebook Login.
  • Instagram: an Instagram account linked to that same Facebook Page.

03What we collect#

  • Account & team data: names, email addresses, profile photos, roles, and — depending on how each person signs in — a Telegram user ID and username, a Google account identifier, or a password stored only as a salted hash.
  • Connection credentials:the identifiers of the connected account or Page, and, for Messenger and Instagram, a Page access token that lets us receive and send messages on that Page’s behalf. Page tokens are encrypted at rest.
  • Contact profiles: for each person who messages your connected account — their platform user ID, name, username, profile photo, and, where the platform provides it, phone number, language, and account flags.
  • Messages & metadata: message text and captions, timestamps, reply relationships, reactions, delivery and read status, and edit and deletion events. Any location or contact card a customer sends is stored as part of the message record.
  • Media & attachments: photos, videos, voice notes, documents, stickers, and their file metadata (type, name, size, duration, dimensions). See How media is handled for what is stored versus referenced.
  • Workspace activity: assignments, labels, conversation status, read state, internal notes, saved replies, and broadcasts your team creates to organize and answer conversations.
  • Notifications & devices: if you enable notifications, the push subscription or device token for that browser or mobile app, plus a rough device label so you can recognize it in a device list.
  • Security records: sign-in state and, where the workspace PIN lock is enabled, a record of unlock attempts so an owner can see who unlocked the workspace and when.
  • Technical data: basic server logs needed to operate, debug, and secure the Service.
  • Feedback you send us: the name, optional email, and message you submit through our feedback form.

04How we use it#

  • To provide the shared inbox — showing, routing, assigning, and sending messages across your connected channels.
  • To record who replied and keep conversation history for your team.
  • To send the notifications you have enabled, on the devices you enrolled.
  • To produce the analytics shown in your own dashboard, such as response times and message volume.
  • To authenticate users and keep the Service secure.
  • To operate, maintain, and improve the Service.

We do not sell your data or the data of your contacts, and we do not use message content for advertising.

05Telegram’s role#

Telegram inboxes connect through Telegram’s official Business API. Your use of Telegram is also governed by Telegram’s own terms and privacy policy. We only receive the data Telegram delivers for the chats you choose to include, and you can disconnect at any time from within Telegram, which stops new data from flowing to MekaDesk.

06Meta’s role (Messenger & Instagram)#

Messenger and Instagram inboxes connect through Meta’s Messenger Platform. When you connect a Page we request only the permissions needed to list the Pages you manage, receive and send that Page’s messages, and subscribe it to our webhook. Your use of those platforms is also governed by Meta’s terms and privacy policy. You can revoke our access at any time from your Facebook Business Integrations settings, which stops new messages from reaching MekaDesk.

07How media is handled#

For Telegram, we normally store only a file reference rather than the file itself, and fetch the file from Telegram on demand when someone opens it. For Messenger and Instagram, Meta’s attachment links expire, so we may download and keep a copy of the attachment on our server in order to keep your conversation history readable. Stored copies live under randomly generated file names and are served only to signed-in members of the workspace that owns them.

08The mobile app & device permissions#

The Meka Desk app for iOS and Android asks your device for the permissions below. Each one is requested only at the moment you use the feature that needs it, and each exists so you can put something into a chat. Declining a permission only disables that one feature — the rest of the app keeps working.

  • Microphone: to record a voice message. Used only while you hold the record control.
  • Camera: to take a photo to send to a conversation.
  • Photo library: to attach a photo you already have. The app reads only the item you pick.
  • Files: to attach a document. The app reads only the file you pick.
  • Location: to attach your current location to a chat, when you choose to share it.
  • Notifications: to alert you about new messages. Enabling them registers a push token for that install, along with the device name you gave your phone, so you can recognize it in your device list.

Location is requested for foreground use only — the app asks for it while you are using it, reads a single approximate position at the moment you tap to share, and never tracks your location in the background or builds a location history.

Anything you capture this way is sent as a message to the conversation you chose, and is then handled exactly like any other message content described in this policy. The app does not read your photo library, contacts, call history, or files in the background, and it does not use any of this for advertising or profiling.

To keep the inbox fast and readable offline, the app also stores a copy of your recent conversations and downloaded attachments in your device’s own cache. You can clear it at any time from Settings, which does not sign you out. Removing the app deletes this local copy.

09Storage & security#

Data is stored in our database and protected with reasonable technical and organizational measures. Passwords are stored only as salted hashes, and short-lived sign-in tickets are stored only as hashes. Page access tokens are encrypted at rest.

Workspaces can additionally turn on encryption of chat content at rest, which encrypts message text, message previews, media captions, internal notes, and saved-reply bodies with a key derived per workspace.

This is a setting rather than the default, and it does not cover metadata such as names, timestamps, or file names.

No system is perfectly secure, but we work to safeguard your data.

10Who can see your data#

  • Members of your workspace, according to their role. Owners and admins can see all conversations in the inboxes they have access to; sub-admins can be restricted to specific inboxes, and usually to the conversations assigned to them.
  • A small number of MekaDesk operators, who can access account and workspace records in order to run the platform, approve owner registrations, and respond to support or abuse reports.
  • Service providers that host our infrastructure and deliver push notifications, acting on our behalf.
  • Authorities, where we are legally required to disclose information.

11Retention#

We keep conversation and workspace data for as long as your account is active so your team has full history.

Because the inbox is a record of what was said, some events are preserved rather than erased. When a message is edited we keep a snapshot of the original text, and when a message is deleted on the messaging platform we mark it deleted and keep the record so your team can see that it existed.

When you close your account, we remove or de-identify the associated data within a reasonable period, except where we must retain it to meet legal obligations. Feedback you send us is kept as a permanent record of the message.

12Your choices#

  • Disconnect a Telegram account at any time from the Telegram app, or revoke a Page at any time from your Facebook settings.
  • Turn notifications off, or remove an enrolled device.
  • Withdraw any device permission — microphone, camera, photos, files, or location — at any time in your phone’s own iOS or Android settings, and clear the app’s local cache from Settings.
  • Delete labels, notes, and other workspace content you created.
  • Request access to or deletion of your personal data by contacting us.

If you are an end customer who messaged a business using MekaDesk, that business controls your conversation. Please contact the business directly, or reach us and we will route your request to them.

13Changes to this policy#

We may update this Privacy Policy from time to time. Material changes will be reflected in the “Last updated” date above.

14Contact#

For privacy questions or requests, message us on Telegram at @mekacard_dev.