mepa8
Privacy

What this site stores, where, and for how long.

Short, because there is not much. If anything here changes, the change log at the bottom says what and when.

By Ryan Bolden with NousPublished Updated

Who we are

Mepa8 is a product of InboundAI365, LLC, based in Sacramento, California, reachable at ryan@ib365.ai. This page covers the website at mepa8.com. The hosted monitoring product has its own terms, which you see before you connect a vendor.

What the audit form stores

The booking form on the audit page collects 6 fields: your name, your email, your company, a spend bracket, the vendors you name, and a note. It also records the time and a one-way hash of your network address, which we use only to stop more than 5 submissions an hour from one place. The hash cannot be turned back into the address. The form has no card field and never asks for a password.

Those fields are written to 1 database table on Cloudflare's D1, in Cloudflare's infrastructure, and 1 email is sent to our founder through Resend with the same fields and your address as the reply-to. The message is tagged “audit_request” so it can be found and deleted. We keep a request until the audit is finished or you ask us to delete it, whichever comes first, and in any case no longer than 12 months.

What this site does not do

“The registry stores key names, never values.”Mepa8 How-to page, 2026-10-08

Where the data lives

The site and its database run on Cloudflare Workers and D1. Cloudflare's own D1 documentation describes the storage. Email goes through Resend from a verified sending domain. Neither provider is given more than the fields listed above, and neither is permitted to use them for anything but delivering our service. We do not sell or share form data with anyone else.

Crawlers and AI agents

This site asks to be read. Our robots file allows the main search crawlers and the AI crawlers, including GPTBot, ClaudeBot and PerplexityBot, and we publish an llms.txt and a sitemap so a machine can find every page in 1 request. The API paths are excluded from crawling because they hold form submissions, not pages.

Your rights

Write to ryan@ib365.ai from the address you used and we will send you what we hold, correct it, or delete it within 10 business days. There is no account to close on this site because there are no accounts on it. California residents have the rights described in the CCPA, and we honour the same requests from anyone, anywhere.

Security

Every page is served over HTTPS with a strict transport header, a content security policy that allows scripts and styles only from mepa8.com, and frame embedding disabled. The form accepts at most 8 kilobytes, refuses requests from other origins, and strips control characters before storing anything. Database access is limited to the one worker that serves this site.

Changes

When this page changes, the change log below records the date and the substance on the same day. The 3 things most likely to change are the retention period, the list of providers, and the addition of an accounts system when the hosted product opens. We will not move data to a new provider without updating this page first.

Questions people ask

Do you use cookies?

No. The only thing stored in your browser is the theme choice, one word in local storage, set when you press the Theme button. It is never sent to us. Clearing site data removes it and nothing breaks.

Who sees what I type in the audit form?

Two places: 1 database table on Cloudflare D1 and 1 email to Ryan Bolden, the founder, through Resend. No third party receives it, and it is deleted on request or after the audit, and in any case within 12 months.

Can I ask for my data?

Yes. Email ryan@ib365.ai from the address you used and we reply within 10 business days with a copy, a correction, or confirmation of deletion. There is no fee and no form to fill.

Sources

  1. Cloudflare D1 documentation
  2. Resend

Change log: October 9, 2026 — First published.