Privacy
Privacy policy
RelayLink carries briefings between people through their AI assistants. This page says what we hold to do that, why, for how long, who else touches it, and what you can do about it. Last updated 4 September 2026.
Who we are
RelayLink is operated from Richmond, Virginia, United States. Questions about this policy or about your data go to hello@relaylink.ai, or by post to 406 Shafer St, Richmond, VA 23220. We answer within thirty days. The terms of service sit beside this policy and say what we ask of you in return.
What we collect
There are three kinds of people RelayLink holds data about, and they are not the same.
If you have an account
- Your email address and the name you go by. The address is how you sign in and where notifications go; the name is what recipients see as the sender.
- Sign-in codes, stored as a keyed hash and valid for ten minutes. There are no passwords.
- An API key, if you issued one, stored as a SHA-256 hash. We cannot show it to you again.
- Connected assistants: which applications you have authorised and the tokens issued to them, which you can see and revoke on your connections page.
- Your contacts: requests you have sent or accepted, and anyone you have blocked.
- A sign-in cookie on the account portal, named
relaylink-signin, which expires after eight hours of inactivity. It is the only cookie we set, and the public pages set none.
If somebody sends you a briefing and you have no account
- Your email address and the name the sender gave, so the briefing can reach you. This creates a provisional record that lets you read and reply without registering. You can sign in with that address at any time and it becomes your account.
- The link in your email is a token that opens the briefing for thirty days. A reply by email is accepted for sixty days after that.
- Every email carries an unsubscribe link. Using it blocks that sender; we tell them nothing.
The briefings themselves
- The content of every briefing and reply, with its provenance labels: which words a person wrote, which an assistant drafted and a person approved, and which are inferred. The labels are the product, and they are stored with the text.
- What happened to it: sent, the notification email accepted or refused, the link opened, read by an assistant, acknowledged, replied. These are timestamps. We do not record the IP address, device or browser behind any of them, and opening a link is never shown to the sender as evidence that you read it.
- Replies sent by email are read once, turned into a reply on the thread, and the email's own headers are kept only as far as needed to recognise a duplicate delivery. Attachments are discarded.
- Your assistant's session is never sent. A briefing is composed from it by you and your assistant; RelayLink receives what you approve and nothing before that.
If you joined the founding list
- The email address you typed, an optional second address for the person you want to pair with, and the use you picked from a list. Nothing else, and the list is kept apart from accounts: it does not make you a user, and nobody can send you a briefing because of it.
Operational data
- Server logs for thirty days, in Microsoft Azure. Logs never contain recipient addresses or the tokens in links; tests hold that line.
- Performance telemetry (which pages and endpoints were slow or failed), with any token in a path redacted before it leaves the app.
- Your IP address is used to rate-limit public pages and sign-in attempts. It is held in memory for the length of the limit and is not written to the database.
- Database backups for fourteen days, so a fault can be undone.
How we use it
To deliver briefings and replies to the people you address, to let you and your assistant read what you have received, to sign you in, to stop abuse of the service, to tell you about the service when you have asked us to, and to keep the service running. We do not use the content of briefings to train models, to build profiles, or to advertise. There are no advertisements and no third-party analytics on this site.
Who else sees it
- The person you address. That is the point. What they receive is exactly the briefing you approved, with its provenance labels, and nothing from your private session.
- Their assistant, and yours. An assistant connected to RelayLink can read the briefings in its owner's inbox and draft replies. What an assistant's provider does with what it reads is governed by that provider's own terms, not by this policy, and you choose which assistant to connect.
- Microsoft Azure hosts the service and the database, in the United States.
- Mailgun sends every notification email and receives every emailed reply on our behalf, and keeps its own delivery logs under its own policy. We turn off Mailgun's click and open tracking: no link in a RelayLink email is rewritten through a tracker.
- Nobody else. We do not sell data, share it with advertisers, or hand it to a partner. We would disclose data if the law required it, and we would tell you unless the law forbade that too.
How long we keep it
- Briefings, replies and their delivery record are kept for as long as either party's account exists. Correspondence belongs to both people in it, so one person leaving does not erase the other's copy.
- When you close your account, we delete your address, your name, your keys, your sign-in codes, your unsent drafts and your connected assistants, and we revoke every token. Your past briefings stay attributed to a closed account, so the people you wrote to keep their record. Blocks you placed on others stay; blocks others placed on you stay too.
- Sign-in codes live ten minutes. Assistant access tokens live one hour and are refreshed while the connection is in use. Briefing links live thirty days, with a sixty-day grace for email replies.
- Logs, thirty days. Backups, fourteen days.
- The founding list is kept until the launch it exists to announce, and any entry is deleted on request.
What you can do
- See everything: your account page exports your account and all of your correspondence, including briefings other people sent you, as a file you keep.
- Correct your name on your account page. Your address is your identity here and changes by writing to us.
- Disconnect an assistant from your connections page, at any moment, without the assistant's cooperation.
- Stop a sender with the unsubscribe link in any email, or the block on any thread. Blocking is silent.
- Close your account from your account page. It asks you to type your address, because it cannot be undone.
- Ask us anything at the address above. If you are in the United Kingdom or the European Economic Area, you also have the rights the UK GDPR and the GDPR give you, including to complain to your supervisory authority; writing to us first usually resolves it faster.
How we protect it
Everything travels over HTTPS. Sign-in is by emailed code, so there is no password to steal. Keys and codes are stored as hashes. Assistant access is by OAuth tokens that you can revoke. Content from other people is rendered so it cannot run as code, and every page that shows it forbids scripts entirely. The database accepts no passwords at all: the service and its deployment pipeline authenticate as identities, and the only firewall rule admits nothing without one. We will tell you about a breach that affects you without undue delay.
Children
RelayLink is not directed at children under sixteen and we do not knowingly hold their data. If you believe we do, write to us and we will delete it.
Changes to this policy
When this page changes materially we will email account holders before the change takes effect, and the date at the top always says when it was last revised. The current version is the one at this address.