Privacy
Last updated 7 August 2026
Relay is early. This page describes exactly what the software does today. Where something is a limitation rather than a protection, it says so.
What we cannot read
The secret content of every vault item — the password, the account number, the note — is encrypted in your browser with a key we never receive in usable form. Our servers store only the ciphertext and a copy of that key wrapped by AWS KMS. We cannot decrypt your secrets, and neither can anyone who obtains our database.
What we can read
This is the part most services leave vague, so to be direct: the labels you give an item are not encrypted. We store, in readable form:
- the item title and service name (e.g. “Chase”)
- the website address you associate with it
- its category and how critical you marked it
- which items you said depend on which others
- your email address, and when you last checked in
- the names, emails and phone numbers of people you designate
So we can tell that you store a Chase account. We cannot tell you anything about it. If the mere existence of an account is sensitive to you, do not label it accurately.
Automated analysis
Relay ranks your items by consequence and works out which credentials others depend on. That analysis runs over the labels above and never over your secrets — the component that performs it is technically prevented from decrypting anything. Some of it uses a third-party language model (OpenAI), which therefore receives item labels but never secret content.
Who else is involved
- Amazon Web Services — database and key management (United States)
- Vercel — hosting and privacy-friendly, cookieless analytics
- OpenAI — the labels-only analysis described above
- Resend — sending email such as invitations and alerts
We do not sell your data, we do not share it for advertising, and there are no advertising or tracking cookies on this site.
People you designate
When you name a recipient or a trusted contact, we store their name and contact details and may email them. A trusted contact is only ever asked whether a situation is real — they are never shown your vault, before or after. A recipient sees only what you granted them, and only after the conditions you set are met.
Records we keep
Every access and release event is written to a tamper-evident log so you can audit what happened. That log is append-only by design: entries are never edited or deleted, which means some record of an event survives even after you delete the underlying item.
Deleting your data
Email us and we will delete your account and vault contents. The append-only event log described above is the one exception, and it contains no secret material.