Legal
Privacy Policy
Effective 2026-08-08 · Beta version
Plain-English privacy policy for the Relay private beta. A fuller version, finalized with counsel, will replace this before general availability. What we do today: as little as possible with your data, always cited back to the source.
1. What we collect
Account data: email, name, workspace name.
Source data you connect: messages, documents, calendar events, meeting transcripts — only from the sources you explicitly authorize via OAuth.
Usage telemetry: which pages you visit, which queries you run. Never the query content itself except in your own audit trail.
2. What we do with it
Extract atoms (decisions, commitments, policies) from your source data so your workspace can query them with citations.
Serve those atoms back to your own users and to AI tools you've authorized (e.g. Claude Code via MCP).
Improve the product — aggregate, anonymized signals only. Your source content is never used to train models.
3. What we don't do
We do NOT sell your data.
We do NOT train ML models on your source content.
We do NOT share your data with third parties except our named sub-processors (see /trust).
We do NOT retain source content past your workspace's retention window.
4. Where it lives
Postgres on Railway (US). Embeddings stored via pgvector in the same database. OAuth tokens encrypted at rest with Fernet.
See /trust for the full architecture and sub-processor list.
5. How long we keep it
Default retention follows your plan tier (Free: 30 days rolling; Pro: 365 days; Team: configurable). Older atoms are soft-deleted by a nightly job.
On workspace deletion, everything is hard-purged within 30 days (soft-delete grace window in case you change your mind).
6. Your rights
You can export or delete your data at any time from Settings → Workspace.
You can revoke any connected source (Slack, Notion, etc.) at any time from Settings → Integrations. Revoking stops future ingestion but does not retroactively delete atoms already extracted — use the workspace-delete flow for that.
For EU / UK residents: your GDPR rights (access, rectification, erasure, portability, restriction, objection, complaint to a supervisory authority) apply. Contact sadiq@try-relay.com to exercise them.
7. Cookies
We use one cookie: a session token that keeps you logged in. No tracking cookies, no third-party ad cookies, no analytics that follow you around the web.
8. Security incidents
In the event of a data breach affecting your workspace, we notify the workspace owner within 72 hours with the scope of impact and remediation steps.
9. Changes
Material changes to this policy are notified 30 days in advance via email to the workspace owner. Continued use constitutes acceptance.
10. Contact
Privacy questions or requests: sadiq@try-relay.com