This page describes what MeshHold is built for, what it must not be used for, and what you should check before running it where you live. It is not a licence — the licence is the AGPL, and it is the document that governs your rights to the software itself.
1. What MeshHold is for
MeshHold is self-hosted infrastructure. It exists so that people and organisations can keep their own data on their own machines and still get the conveniences that normally require handing everything to a provider: storage that replicates between your own nodes, a private network between them, chat and calls that don't transit anyone else's servers.
The people it is built for are homelab operators, small businesses that would rather not put their files on someone else's cloud, organisations under data-residency obligations, and anyone maintaining infrastructure that has to keep working on an unreliable or restrictive network.
Everything in the project is meant to be used lawfully, on machines and networks you own or are authorised to use.
2. What you must not use it for
Do not use MeshHold:
- to break the law that applies to you;
- to store or distribute child sexual abuse material, or content that incites violence or terrorism;
- to run command-and-control infrastructure for malware, or to move data taken from systems you do not own;
- to get around the rules of a network you do not control — a corporate or campus network, an employer's device, a provider whose terms forbid it — without the network owner's permission;
- to harass, stalk, impersonate, or infringe someone else's rights.
The project has no ability to enforce any of this on software you run yourself; it holds no keys and sees no traffic. The list exists to be unambiguous about what the project is for, not to imply a control that does not exist. Where we do operate something — this website, the forum, and any hosted relay we run — these rules are enforceable and we act on reports sent to meshhold@gmail.com.
3. Encryption, transports, and your local law
MeshHold encrypts data at rest and in transit, and can carry its traffic over transports that share a port with an existing web or SSH server. Those transports exist because they reduce a node's exposed surface and because they keep a node reachable on networks that pass only familiar protocols. See the documentation for what they do and do not provide.
Rules differ by country. Most jurisdictions place no restriction at all on using encryption. Some restrict or license the commercial distribution of cryptographic products, some can compel you to disclose a key or password, and some regulate VPN and anonymisation services or the promotion of tools for reaching blocked resources.
You are responsible for knowing what applies where you are and where your nodes run. If you are unsure, ask a lawyer in your own jurisdiction — nothing on this site is legal advice, and we cannot give any.
4. Export and sanctions
MeshHold is publicly available open-source software, published openly and free of charge. It is not supplied under any arrangement intended to circumvent export controls or sanctions, and you must not use or redistribute it in a way that breaches the export, sanctions, or import rules that apply to you.
5. We run no nodes and hold no data
This is worth stating plainly, because it decides who can answer what.
The project operates this website and its forum. It does not operate your nodes. It has no access to your network key, your vault keys, your files, your messages, or your traffic, and it keeps no record of who runs a node or what they store. Nodes talk to each other directly, or through relays chosen by their operators.
One consequence is that there is nobody to ask for a copy of your data — including you, if you lose your keys. Another is that a request to hand over user content is not something we can satisfy, because we do not have it. What we do hold is described in the Privacy Policy.
6. No warranty
MeshHold is provided as-is. The AGPL's warranty disclaimer and limitation of liability (sections 15 and 16) apply in full: there is no warranty of any kind, and the authors are not liable for damages arising from the use of the software.
That is a statement about the software, not permission for anything in section 2. Nothing here removes obligations you have under the law that applies to you, and no disclaimer could.
7. Changes and contact
We will update this page as the project changes — in particular if we begin operating hosted infrastructure, which would bring obligations this version does not cover. Questions and reports: meshhold@gmail.com.
Questions about this document? Email meshhold@gmail.com.