Privacy Policy
Last updated: July 11, 2026
This policy explains what personal data Relay ("we") collects when you use our website and API, why, and what rights you have. Questions or requests: contact us.
1. What we collect
- Account data — email address, optional company/project name, and a hashed password (we never store the password itself).
- Usage data — per-domain request, success, and failure counts and transferred bytes, used for your dashboard and billing.
- Security logs — IP addresses and rate-limit counters for abuse prevention, kept short-term.
- Support data — tickets you open, including messages and images you attach.
- Billing data — handled by our payment processor when you buy a paid plan; we never see or store full card numbers.
Cookies: we set one essential, httpOnly session cookie to keep you signed in. No advertising or cross-site tracking cookies.
2. Why we process it (lawful bases)
- To provide the Service you signed up for — accounts, dashboards, quota, support (contract).
- To secure the platform and prevent abuse (legitimate interest).
- To send transactional email — verification, password resets, quota alerts, ticket replies (contract). We do not send marketing email without your consent.
- To meet legal obligations, such as tax and accounting rules (legal obligation).
3. Content you scrape
Web content retrieved at your instruction passes through our infrastructure and is retained only briefly to deliver results and operate the Service. For any personal data contained in that content, you are the data controller and we act as your processor on your instructions — your obligations for it are set out in the Terms of Service.
4. Who else processes data
We share personal data only with service providers needed to run Relay: infrastructure hosting, email delivery, payment processing (for paid plans), and network/proxy carriers that transport API traffic. We do not sell personal data and we do not run ads.
5. Retention
- Account and usage data: for as long as your account exists. Deleting your account removes your workspace, logins, and usage history.
- Security logs: short-term, rolling.
- Encrypted off-site backups: kept on a rolling window, then overwritten.
6. Your rights
You can access and export your usage data (CSV) and change your email or password in the dashboard, and delete your account from the Account tab. Under GDPR/UK GDPR you also have the rights to access, correct, delete, restrict, and port your personal data, to object to processing, and to complain to your supervisory authority. To exercise any of these, contact us.
7. Security
All traffic is TLS-encrypted, passwords are stored bcrypt-hashed, session cookies are httpOnly, and production data lives on access-controlled servers.
8. Children
The Service is not directed at children under 16 and we do not knowingly collect their data.
9. Changes
We may update this policy; material changes will be announced by email or in the dashboard. The date above always reflects the current version.