Privacy Policy
Draft privacy information for the local-first Project Relay software and any future optional services.
Relay is designed to keep your archive under your control.
This is a working draft, not a final privacy notice. It describes the current local-first design and the decisions that must be completed before any hosted or paid service is launched. It has not been reviewed by a lawyer.
Local data and optional projections
The local application and CLI may read the folders, transcripts, configuration files, and connector locations that you explicitly select. They may create normalized records, indexes, categories, receipts, backups, and diagnostic logs on your device. The public GitHub Pages site is documentation and does not receive the local archive by default.
If you choose a connector or hosted service, the selected destination may receive the records needed for that operation. The connector's scope, destination, and approval state should be visible before a write occurs.
Keep secrets and sensitive material out of public destinations
Do not place API keys, passwords, private transcripts, regulated records, or other sensitive material in the public repository, Pages bundle, issue tracker, or an unapproved connector. The local archive is your responsibility. Use encryption, operating-system access controls, and backups appropriate to the material you store.
Pages is a documentation surface
This site may receive ordinary web request data from its hosting, CDN, or browser environment. The final notice must identify the actual host, logs, cookies, analytics, contact forms, and retention settings in use at publication time. No analytics, advertising, or transcript ingestion should be implied by this draft unless the deployed configuration actually enables it.
Providers have their own privacy rules
When you enable GitHub, Notion, Slack, model providers, MCP servers, payment processors, or other third-party services, those services process data under their own privacy notices and contracts. Relay cannot change their retention, location, training, security, or deletion practices. Review each destination before granting access.
Local control comes first
You can ordinarily remove local archive records, backups, indexes, and connector configuration from your own device, subject to operating-system recovery and backup copies. A final hosted policy must explain account access, export, correction, deletion requests, backup expiry, incident notices, and any legal retention requirement before hosted storage is offered.
What must be confirmed before publication
- Identify the responsible legal entity and privacy contact.
- Inventory actual telemetry, cookies, hosting logs, crash reports, and support channels.
- Document provider destinations, processing purposes, regions, retention, and deletion paths.
- Choose the governing privacy law and publish rights and complaint routes with qualified legal advice.
- Version this notice and show it at the point where any hosted or paid processing begins.