Privacy Policy

Last updated: 10 August 2026

Relay Me sends email on your behalf to people who have agreed to receive it. This policy covers what we store, why, and for how long.

Email content

We do not retain the emails you send after processing. Message content lives in an encrypted-in-transit AWS S3 queue object only for as long as it takes to deliver, is sent through Amazon SES, and is discarded afterwards. What remains in Relay Me is metadata: that a send happened, when, to which mailing list, how many recipients it reached, and whether it succeeded.

Your account

When you create an account we store your email address, username, a hash of your password (never the password itself), and the workspace, mailing lists, sending identities, and CLI credentials you create. If you buy a plan, Paddle processes the payment and we store its customer, subscription, invoice, and status identifiers. We keep this while your account exists.

Recipients

When you add someone to a mailing list we store their email address and ask their permission. Until they agree, they receive nothing. They can decline, unsubscribe, or block future requests at any time using the links in the email we send them, without creating an account.

We record the fact and time of each of those decisions, because being able to show that someone agreed is the point of asking.

Analytics

We record which pages are visited on our website and documentation, and whether a visitor later creates an account. We use this to understand how people find us and which pages are worth keeping.

For this we store:

  • an opaque random identifier held in a cookie, which contains nothing but a random value;
  • the page visited, and the page you arrived from;
  • your browser's user-agent string;
  • a one-way hash of your IP address, never the address itself.

Analytics and security hashes use a random key for each month. Old rows and keys are removed under the retention schedule, after which those hashes cannot be tested against an address.

This is optional. Where consent is required, nothing above is recorded unless you agree, and declining does not affect your use of the product.

Security logging

Separately from analytics, we record sign-in attempts and their outcome: success, failure, verification, and rate limiting. Each entry includes a one-way hash of the originating IP address and the user-agent string. Failed attempts against addresses that do not correspond to an account are recorded without the address that was tried.

This uses no cookie and is not optional: it is how accounts are protected against password guessing and abuse, and it applies to everyone.

CLI downloads

When the command-line tool is requested through Relay Me we record which file, when, a bounded browser/referrer value, and a monthly one-way HMAC of the IP address. We keep no raw address. The download itself is served by GitHub Releases, whose own privacy terms also apply.

How long we keep things

DataRetention
Email contentNot retained beyond delivery or final failure
Send metadataLife of the account
Account and workspace dataLife of the account
Recipient consent recordsLife of the mailing list
Analytics1 year
Security logs1 year
CLI download analytics1 year
Analytics/security IP hash keysRemoved after their protected retention window

Where it is stored

Analytics and security logs are held on a separate database server from accounts and recipients. CLI download aggregates are held in the application database, using only monthly hashes rather than raw addresses.

What we do not do

  • We do not sell personal data or use it for advertising.
  • We use no third-party analytics or advertising service.
  • We do not fingerprint your device or track you across other websites.
  • Relay Me application databases do not store raw IP addresses.

We use service providers only to operate the product: Cloudflare for network delivery and protection, AWS for email and optional queue storage, Paddle for billing, and GitHub for CLI release files. They process the data needed for those services under their own privacy terms and our agreements with them.

Cookies

We set three first-party cookies:

CookiePurposeOptional?
SessionKeeps you signed inNo, the product cannot work without it
ConsentRemembers whether you accepted or declined analyticsNo analytics is recorded when declined
VisitorAn opaque random id used for consented analytics and signup attributionYes

Your rights

Depending on where you live you may have the right to access, correct, export, or delete your personal data, and to withdraw consent to analytics. Contact [email protected] and we will respond to your request.

Because IP addresses are stored only as monthly pseudonymous hashes, we cannot identify your analytics records from an IP address alone. A deletion request for account data will remove records tied to your account, but anonymous page views cannot be traced back to you by us.

Contact

If you accepted analytics and would like to stop, you can turn it off here. It takes effect immediately and nothing further is recorded.