PRIVACY · RELAYUNE
Relayune Privacy Policy
This Policy explains what personal data Relayune collects, why it is used, how long it is retained, and how you can manage or delete it.
Controller and scope
The controller/operator is Ernest / giraffe-tree, an individual developer based in Shanghai, China and operating as Relayune. Contact: giraffetree1@gmail.com. Where applicable law requires a postal address, you may request it by email after necessary identity verification.
This Policy applies to the Relayune website, web app, desktop app, and directly related support communications. Codex, Kimi Code, Claude Code, model providers, and external links have their own privacy policies, which this Policy does not replace.
Data we collect
Data you provide
- Account data: your normalized email address and a randomly salted scrypt digest of the password you set. We do not store the plaintext password.
- Support data: emails, issue descriptions, and troubleshooting materials you choose to send.
Data generated by the Service
- Device and pairing metadata: random user, device, browser, pairing, and request identifiers; device/browser labels; a content-key identifier that cannot recover the key; authorization and recent-use times.
- Authentication and security data: SHA-256 digests of login/session, device, and browser-authorization tokens; public pairing shares and mutual confirmations; and short-lived hashes of email and source address for login attempts. Nginx processes source IP addresses to establish network connections; when TLS or reverse-proxy errors occur, a source IP and request URI may enter a restricted infrastructure error log.
- Routing and operational metadata: ciphertext direction, type, size, queue state, timestamps, expiry, sequence, presence, latency, request method, route template, response status, and duration.
- Encrypted business data: messages, history, attachments, project paths, session data, approvals, and agent output are stored or relayed as A256GCM envelopes. The server cannot decrypt their content.
We do not intentionally collect precise location, contacts, payment-card data, or advertising identifiers, and we do not train models on business content.
Data kept only on your devices
The browser stores a non-exportable content key, the original browser-authorization token, a random device identifier, and pairing state in IndexedDB. The desktop app stores the device token and a separate content key for each browser in an authenticated encrypted vault in its application-data directory; it does not use macOS Keychain or Windows Credential Manager.
These original keys and tokens are not uploaded to the server or written to app configuration, logs, or plaintext files. Clearing site data, uninstalling the desktop app, or deleting the encrypted vault may remove access. Re-pair through the product flow instead of copying keys.
Purposes and legal bases
| Purpose | Main data | Legal basis |
|---|---|---|
| Create accounts, sign in, pair devices, and provide remote access | Email, authentication digests, device/routing metadata, ciphertext | Performance of our contract with you |
| Prevent abuse, troubleshoot, and secure the Service | Short-lived network hashes, security events, redacted logs | Contract performance and our legitimate interests |
| Answer support, deletion, and rights requests | Contact, communication, and verification data | Contract, consent, or legal obligation |
| Comply with valid legal process | Minimum data relevant to the request | Legal obligation |
We currently do not run advertising, behavioral profiling, or marketing email and do not sell personal data. If non-essential analytics or marketing are introduced, we will update this Policy first and seek consent where required.
Retention
- Email-verification links, password-setup sessions, and pairing sessions: up to 10 minutes.
- Web login sessions: up to 8 hours.
- Failed-login rate-limit hashes: up to 15 minutes.
- Infrastructure error logs: rotated daily and normally retained for up to about 11 days.
- Remote-command delivery window: up to 24 hours. After expiry, a command is not delivered, but its opaque record may remain with the active account to preserve encrypted history and queue consistency.
- Account, device, browser authorization, encrypted catalogs/events/responses, and required metadata: while the account or authorization remains active. Revocation stops further access and new writes, but historical ciphertext may remain until a deletion request or routine cleanup.
- Support communications: normally no more than 24 months after the last contact, unless a legal dispute requires longer retention.
Verified deletion requests are normally completed in live systems within 30 days. Backup copies, if any, are overwritten through ordinary rotation within no more than 90 days unless longer retention is legally required. Data is deleted or de-identified when no longer necessary.
Security measures and limits
Measures include HTTPS, RFC 9382 SPAKE2 PAKE, HKDF key separation, AES-256-GCM business envelopes, a separate key per browser, token digests, least-privilege MongoDB access, loopback-only services, and redacted logs. Ordinary application logs do not record request bodies, Authorization, cookies, pairing codes, or business plaintext; infrastructure error logs may contain the network information disclosed above.
No system is perfectly secure. The server can still see login email, random identifiers, ciphertext size and direction, timestamps, and presence, so traffic analysis is outside the end-to-end encryption boundary. The current PAKE dependency has not completed an independent cryptographic audit. Report potential security issues to giraffetree1@gmail.com.
This design does not protect a compromised browser, desktop app, local Agent, browser extension, dependency supply chain, or user screen. The web app loads frontend code from the server; a strongly malicious server that replaces that code could exfiltrate content after browser-side decryption. Users who must resist that threat should prefer a signed, independently verifiable native client or extension with pinned release keys and frontend versions.
International access and transfers
The production server is in China. If you access from another country or region, account data, routing metadata, and ciphertext may be transferred to China. We rely on contract performance, security safeguards, and applicable legal requirements and transfer only what is needed to provide the Service.
Codex, Kimi Code, Claude Code, or model providers you choose may process content received by the local agent in other countries. That processing is between you and the third party. Review its data regions, transfer mechanisms, and account controls.
Your rights and choices
Depending on applicable law, you may request information, access, correction, a copy, deletion, restriction, or objection; withdraw consent; and complain to a competent authority. Withdrawal does not affect processing already lawfully completed.
You can revoke individual browsers in the desktop app or clear site data to remove local browser credentials. For account-level access, correction, or deletion, email giraffetree1@gmail.com from your registered address. We will verify identity and normally respond within 30 days. Complex requests may be extended where law permits, with an explanation. We will not discriminate against you for exercising privacy rights.
Children
Relayune is intended for users 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe a minor provided data, contact us so we can investigate and delete it where appropriate.
Changes and contact
We may update this Policy. Material changes will normally be announced through the Service or registered email at least 15 days in advance, except where law or urgent security needs require immediate effect. We maintain a version number and last-updated date.
Send privacy questions, security reports, or rights requests to giraffetree1@gmail.com. The Chinese and English versions share the same intent. If they conflict, the Simplified Chinese version controls to the extent permitted by law.