1. Status and privacy contact
For privacy requests concerning the RELAY service, use the secure Privacy Choices form. For product help, use Support.
2. Data handled by the website
The site does not use advertising tags, social pixels, external web fonts, marketing cookies or public account registration. It provides support, privacy-request and account-deletion forms.
| Data | Why | Handling |
|---|---|---|
| Basic server and security logs, such as IP address, request time, requested path, device/browser data and error or security signals | Deliver the site, maintain availability, detect abuse and troubleshoot | The host may process these under its infrastructure settings; the RELAY control service stores a daily rotating keyed hash of the requester IP for abuse protection and audit |
| Support request: email, category, subject and message | Create and manage a support case | Stored in the private control database outside the public website |
| Privacy or deletion request: email, country, right requested and optional scope | Track the request, verify account control and apply the relevant response deadline | Stored in the private control database with a public case reference and status history |
3. Data handled by the app
When a customer creates an account, RELAY processes the name and email they provide, password-verification data, secure session records, the household profile and members they create, responsibilities and related notes, and their app preferences. This information is used to provide the account and synchronize the household across signed-in devices.
The Camilleri demonstration is a separate fictional example. Demo household content remains separate from customer accounts. Optional product learning is off by default; if enabled, RELAY receives minimized feature, outcome, duration and deliberately submitted feedback signals. Responsibility titles, notes, household relationships and other private household content are excluded from product learning.
4. Purposes and lawful bases
| Purpose | Basis | Boundary |
|---|---|---|
| Create and authenticate an account, save a household and synchronize requested features | Perform the service requested by the customer | Only the account and household data needed for the selected features |
| Protect accounts, rate-limit abuse and troubleshoot faults | Legitimate interests in service security and reliability, and legal obligations where applicable | Restricted access, purpose limitation and retention controls |
| Optional product learning and deliberately submitted feedback | Consent | Off by default, withdrawable in the app, minimized and separated from private household content |
| Support, privacy rights, legal compliance and incident response | User request, legal obligation and legitimate interests where applicable | Case-bound access and documented holds |
5. Optional product learning and sentiment
Product learning is optional and disabled when a new account is created. A customer can enable or disable it in Privacy & Control and can delete eligible learning history from the device and RELAY service.
Allowed after opt-in
- rotating pseudonymous screen or feature identifiers;
- success, abandonment and error outcomes;
- coarse action duration;
- whether a continuity recommendation was completed;
- app version, platform, locale and accessibility settings when allowed;
- sentiment from feedback a person intentionally submits for analysis.
Excluded from product analytics and model training
- responsibility titles, descriptions, household relationships or document contents;
- names, contact details, precise location or advertising identifiers;
- medical, financial, legal, identity, insurance or voice content;
- personality, health, conflict, credit, employment, insurance or protected-trait inference;
- private household content used to train public models.
Reports may propose a product change, but they cannot autonomously rewrite or publish the live app. Privacy, accessibility and security checks plus human approval are required before a controlled experiment.
7. International transfers
Where information is processed across borders, RELAY uses applicable transfer safeguards, such as adequacy decisions, standard contractual clauses or other approved instruments, together with technical and organizational safeguards.
8. Retention and deletion
RELAY uses purpose-limited retention:
- account and household content: while the account is active, until the customer deletes it, subject to narrow legal exceptions;
- authentication sessions: until logout, account deletion, expiry or security revocation;
- raw learning events and reports: short-lived and separately deletable in Privacy & Control;
- security records: only as long as needed for security, accountability and legal duties;
- backups: access-restricted and aged out on a documented rotation;
- deletion evidence: minimal non-sensitive proof that a verified request completed.
A signed-in customer can delete the account and synchronized household data in the Household screen. A customer can also start a case through the public account deletion route. Data required by law or a valid legal hold is isolated and removed when the basis ends.
9. Your choices and rights
Subject to applicable law, people may request access, portable export, correction, deletion, restriction, objection, consent withdrawal, information about sharing, limits on sensitive-data use, and review of qualifying automated decisions.
RELAY provides in-app controls for account deletion, learning consent and learning-history deletion. Identity verification for other requests is proportionate and does not require unnecessary sensitive documents.
Visit Privacy Choices to submit a secure request and receive a case reference.
10. Children and teenagers
RELAY is designed for adults responsible for household continuity. It does not offer child accounts. An adult may record a child as part of an adult-managed household, so customers should minimize that information and avoid unnecessary sensitive details.
11. Security
The production service uses HTTPS, one-way password hashing, randomly generated session credentials, account-level data isolation, server-side authorization, rate limiting and restricted private storage. The mobile app stores its session credential using the operating system’s secure storage.
Support access is purpose-limited and should be case-bound. Read the Security page.
12. Changes, complaints and contact
Material changes will be dated, summarized and, where required, notified before they take effect. Consent will not be silently expanded through a policy update.
Country-specific regulator and complaint information is available through the country coverage tool.