Legal

Privacy Policy

Last updated: July 9, 2026

Overview

Relay ("we", "us") is an AI chief of staff for founders. This policy explains what data we collect, how we use it, and the controls you have. Relay is currently operated as a private alpha; this policy is maintained by the Relay team to answer common privacy questions and is not an independent certification.

Data we collect

  • Account data: your email, display name, and avatar from your sign-in provider.
  • Gmail content (if you connect Gmail): message metadata (sender, recipients, subject, timestamps, labels) and message bodies for the threads Relay needs to classify, summarize, and draft replies.
  • Relay-generated data: classifications, decisions, drafts, feedback events, and audit log entries you create by using the product.
  • Operational logs: minimal request logs required to run and secure the service.

How we use your data

  • Provide the core product: classify inbox items, draft replies, and surface decisions for your approval.
  • Improve your Relay by learning from your Accept / Reject / Edit feedback. Corrections are applied only after you confirm.
  • Operate, secure, and debug the service.

We do not sell your data, and we do not use your Gmail content or Relay-generated data to train foundation models for third parties.

Google user data (Gmail)

Relay's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • Relay only requests the Gmail scopes needed to read, modify, and send messages on your behalf.
  • Gmail data is used solely to provide user-facing features you have requested (classification, drafting, replying).
  • Gmail data is not used for advertising and is not sold or transferred to third parties except as required to run the service (see Subprocessors) or by law.
  • Humans do not read your Gmail data except where required for security, to resolve a support issue you raise, or to comply with the law.

Subprocessors

Relay relies on the following providers to operate the service:

  • Lovable Cloud (Supabase): database, authentication, and server infrastructure.
  • Google: OAuth and Gmail API access when you connect Gmail.
  • Model providers via Lovable AI Gateway: LLM inference for classification and drafting. Prompts contain the minimum content needed for the task.

Storage, encryption, and retention

  • Data is stored in managed Postgres with encryption at rest and TLS in transit.
  • Google OAuth refresh tokens are encrypted (AES-256-GCM) before being written to the database.
  • Row-level security scopes every record to its owning user.
  • You can disconnect Gmail at any time from Settings; this revokes Relay's access token and stops future syncs.
  • On account deletion, your profile, decisions, drafts, feedback, and stored Gmail-derived records are removed within 30 days.

Your controls

  • Trust levels (Observe, Recommend, Draft-and-Notify) control how much autonomy Relay has. Drafts require your approval before sending.
  • You can revoke Relay's Google access from your Google Account at any time: myaccount.google.com/permissions.
  • You can request export or deletion of your data by contacting us.

Contact

For privacy questions, data requests, or security reports, contact the Relay team at the support email listed on the Google OAuth consent screen for this app.