Privacy
Last updated 13 September 2026
Relay is early. This page describes exactly what the software does today. Where something is a limitation rather than a protection, it says so.
What we cannot read
The secret content of every vault item — the password, the account number, the note — is encrypted in your browser with a key we never receive in usable form. Our servers store only the ciphertext and a copy of that key wrapped by AWS KMS. We cannot decrypt your secrets, and neither can anyone who obtains our database.
What we can read
This is the part most services leave vague, so to be direct: the labels you give an item are not encrypted. We store, in readable form:
- the item title and service name (e.g. “Chase”)
- the website address you associate with it
- its category and how critical you marked it
- which items you said depend on which others
- your email address, and when you last checked in
- the names, emails and phone numbers of people you designate
- the secret behind your own sign-in authenticator — the one Relay gave you when you created the account. It is stored on our servers in readable form, unlike everything in your vault
So we can tell that you store a Chase account. We cannot tell you anything about it. If the mere existence of an account is sensitive to you, do not label it accurately.
The last item is the sharpest one and it is listed deliberately. Your vault contents are encrypted where we cannot reach them; your sign-in authenticator is not. Anyone who obtained our database could not read a single vault item — but they could generate your sign-in codes. That is why the vault is worth what it is and the database alone is not, and why we would tell you about a breach rather than reassure you with the first half of that sentence.
Automated analysis
Relay ranks your items by consequence and works out which credentials others depend on. That analysis runs over the labels above and never over your secrets — the component that performs it is technically prevented from decrypting anything. Some of it uses a third-party language model (OpenAI), which therefore receives item labels but never secret content.
Who else is involved
- Amazon Web Services — database and key management (United States)
- Vercel — hosting and privacy-friendly, cookieless analytics
- OpenAI — the labels-only analysis described above
- Resend — sending email such as invitations and alerts
- Cloudflare — our domain’s DNS, and the mail forwarding that delivers anything you send to our support address
- Google — the mailbox (Gmail) where that forwarded support mail is read, and where our mail-authentication reports arrive
- Stripe — payment processing, if you subscribe. Your card details go to Stripe directly and never reach our servers; we keep only the fact that a subscription exists and its status
We do not sell your data, we do not share it for advertising, and there are no advertising or tracking cookies on this site.
People you designate
When you name a recipient or a trusted contact, we store their name and contact details and may email them. A recipient sees only what you granted them, and only after the conditions you set are met.
Text messages. Text messaging is not switched on yet and Relay has never sent one; this is the rule it will run under. We would only text someone who gave us a mobile number themselves, from inside their own signed-in account, having chosen it. It would be off unless chosen, and could be switched off there or by replying STOP. A number somebody else entered for you is never used for text messages — only one you added yourself. We use it for a single thing: telling you something needs your attention and that you should sign in. Never marketing, and never a code, a link, or anything else worth intercepting. Message and data rates may apply and message frequency varies. We do not sell, rent or share these numbers.
A trusted contact is only ever asked whether a situation is real. Until they are asked they see nothing about your vault; at that moment they are told how many items are involved and which categories, so they can judge whether the request is proportionate. They are never shown a title and never any content, at any point.
They can also set up a free standby account of their own, described below. If they do, they sign in as themselves rather than following a link you forwarded, and nothing secret is sent to them when your plan opens.
If someone named you
Someone can name you in their plan and give you a code that sets up a standby account. About you, we then hold:
- the name and contact details they entered for you — not what you told us
- a sign-in session, kept in a cookie that exists only to keep you signed in
- if you set up a passkey, the public half of it — never anything that could sign as you
- a scrambled form of any emergency code you were given, which we cannot turn back into the code
What you do is recorded in their log, not yours. When you accepted, when you answered a question, when you opened something they left you — all of it lands in the tamper-evident record described above, which belongs to the person who named you. That is how they know their plan works, and you should know it is the arrangement before you take part.
If you stand by for more than one person, none of them can learn about the others. There is no screen anywhere that shows one of them your other relationships.
You can step down from any circle at any time from your standby page, and you can close your account outright. Either way the people affected are told, because a plan that quietly gets weaker is the failure this product exists to prevent.
Records we keep
Every access and release event is written to a tamper-evident log so you can audit what happened. That log is append-only by design: entries are never edited or deleted, which means some record of an event survives even after you delete the underlying item.
Deleting your data
You can close your account yourself from your account page, at any time, and export everything first. It removes your vault, the people you listed, your passkeys and any emergency codes you had issued. If you would rather we did it, email us.
Some things deliberately survive, and this is the whole list. The append-only event log described above stays, and it contains no secret material. If you were standing by for someone else, their record of you stays on their list — unlinked from you and marked as no longer set up — because deleting it would quietly shrink their plan without telling them.
Two more survive that are worth naming plainly. We keep delivery records — the fact that an email reached, bounced from, or was refused by a particular address, including addresses of people you listed. They are held against the address rather than against your account, so closing your account does not remove them; they are what stops us sending forever to a mailbox that no longer exists. And backups of the database are kept for 35 days, so a deletion is gone from every copy only once that window has passed.
Separately: if you used the interest form on the caregivers page, the address and note you sent are stored so we can reply. That is not part of an account and is not removed by closing one — email us and we will delete it.
Who holds this data, and how to reach him
Relay is operated by Steve Harlow, an individual — there is no company. He is responsible for the data described above.
hello@relaystandby.com — read by a person. More at about.