Legal
Privacy policy
What we collect when you use Relay, why we collect it, who helps us process it, and the choices you have.
Last updated [Month DD, YYYY]
Draft. Bracketed details are placeholders and this text hasn't been reviewed by a lawyer yet. Edit src/lib/legal.ts before launch.
Who we are
Relay is operated by [Company legal name], [Registered address] (“we”, “us”). We are the controller of personal data collected on this website and in your Relay account. Questions about this policy go to [privacy@yourdomain.com].
Information we collect
Information you give us.
- Messages you send through the support widget, any files you attach to them, and the name and email address you add so we can reply.
- Your email address and name when you create a Relay account or sign in (with Google or an emailed link), and the name of the workspace you create.
- The email addresses of teammates you add to your workspace, so they can sign in.
- Feature requests, comments and the optional display name you post on the feedback board.
- Billing details if you subscribe to a paid plan. You pay through Dodo Payments, our merchant of record, so card details go straight to them and we never see them. We receive your plan, billing status and a customer reference.
- Emails you send to our support address.
Information collected automatically.
- A random visitor ID stored in your browser's local storage, so the widget and feedback board can show you your own conversations and votes. It isn't linked to your identity unless you give us your name or email.
- Your IP address and browser user agent, which our servers receive with every request. We use the IP address in memory to limit abusive traffic and keep it in server logs for up to [30] days.
- Aggregate usage statistics from Plausible Analytics, such as page views, referrers, country and device type. Plausible uses no cookies and stores no personal data.
Information from businesses that use Relay. When a company installs the Relay widget on its own site, it may pass us your name, email, account ID and other details so its support team knows who they're talking to.
Cookies and local storage
We set cookies only when you sign in to Relay: authjs.session-token keeps you signed in, relay_ws remembers which workspace you were using, and a few short-lived authjs.* cookies protect the sign-in itself. They are strictly necessary. The widget and feedback board use local storage for your visitor ID and remembered display name, and our home page keeps the business name you enter to personalize its demos there. That name never leaves your browser. We use no advertising or cross-site tracking cookies, so we don't show a cookie banner. If that changes, we'll ask for your consent first.
How we use your information
- To answer your support requests and email you replies (performance of a contract, or our legitimate interest in helping you).
- To run, secure and improve Relay, including preventing spam and abuse (legitimate interests).
- To bill paid plans and meet tax and accounting duties (contract and legal obligation).
- To send product or service emails you've asked for. You can unsubscribe at any time (consent).
We don't sell your personal information, and we don't share it for cross-context behavioral advertising.
AI-generated answers
When AI answers are turned on, your message and relevant help-center articles are sent to Anthropic to write a reply. Anthropic processes this data on our behalf under its commercial terms. You can always ask to talk to a human instead.
Who processes your data
We share personal data only with service providers who process it for us under written agreements:
- [Hosting provider, e.g. Vercel / AWS / Fly.io]: Hosting the website and application servers
- [MongoDB hosting provider, e.g. MongoDB Atlas]: Storing accounts, workspaces, conversations, contacts and feedback
- Cloudflare (R2 storage): Storing files attached to conversations and the brand logo
- Anthropic: Generating AI answers from help-center content (only when AI answers are turned on)
- Resend or Postmark (whichever email provider is enabled): Sending and receiving support email and sign-in links
- Google: Signing in to Relay with Google (only for people who choose it)
- Plausible Analytics: Cookieless, aggregate website analytics
- Dodo Payments: Merchant of record for subscriptions: takes payment, calculates and collects sales tax and VAT, and issues invoices
We may also disclose information if the law requires it, or to protect our rights, our users or the public.
How long we keep it
- Conversations, contact details and feedback: while the account they belong to is active, then deleted within [30] days of closure.
- Billing records: as long as tax law requires, usually [7] years.
- Server logs: up to [30] days.
International transfers
Our providers may process data outside your country, including in the United States. Where the law requires it, we rely on safeguards such as the EU Standard Contractual Clauses.
Your rights
Depending on where you live, including under the GDPR, UK GDPR and the California Consumer Privacy Act, you can ask us to:
- access or get a copy of the personal data we hold about you;
- correct it, or delete it;
- restrict or object to how we use it, or withdraw consent you gave us;
- move it to another service (data portability).
Email [privacy@yourdomain.com] and we'll respond within 30 days (45 days for California requests). We won't discriminate against you for using these rights. You can also complain to your local data protection authority.
If a company uses Relay to support its own customers, that company controls those conversations. Send requests about them to the company, and we'll help it respond.
Security
We use HTTPS for all traffic, sign session cookies, rate-limit public endpoints, keep each workspace's data in its own database, and restrict each inbox to the members of its workspace. No system is perfectly secure, so we can't guarantee absolute security.
Children
Relay isn't directed at children under 16, and we don't knowingly collect their personal data.
Changes to this policy
If we make material changes, we'll update the date above and, where appropriate, notify account holders by email before they take effect.
Contact
[Company legal name], [Registered address]. Email [privacy@yourdomain.com]. See our terms of service for the rules that apply to using Relay.
See also: Terms of service