Privacy Policy

This Policy explains what SignalRelay collects, why it is used, when it is shared, how long it is kept, and the choices available to you.

Last updated: August 13, 2026

Scope

This Policy applies to the SignalRelay website, accounts, hosted product, HTTP API, MCP endpoint, support, and billing operations. It does not control the privacy practices of an outside provider, producer, Agent, or customer application.

Data we collect

Account and security data

We collect your email address, account identifiers, verification state, linked GitHub or Google identity identifiers, security settings, session data, and security event history. Passwords, tokens, and recovery codes are stored as secure hashes or keyed digests where the product design allows it.

Relay and Signal data

We store Agent and Relay configuration, encrypted Relay credentials, Signal payloads, CloudEvents attributes, provider and delivery metadata, source IP addresses, timestamps, Claim leases, outcomes, and failure reasons. The content can contain personal data that you or an outside producer chooses to send.

Billing and usage data

We store your selected plan, trial and access state, Stripe customer and subscription identifiers, subscription status, billing-period dates, accepted Signal usage, and billing audit records. Stripe receives and processes payment details. SignalRelay does not store a complete payment card number.

Support and technical data

We collect messages that you send to Support and normal service logs such as request time, IP address, route, status, and safe error category. Logs and operational metrics are designed not to include Signal bodies or credentials.

How we use data

  • create, verify, secure, and support your account;
  • accept, store, route, claim, retain, and delete Signals;
  • process subscriptions, enforce plan access, and send usage notices;
  • detect abuse, rejected signatures, duplicate delivery, and security risk;
  • diagnose failures, answer support requests, and improve reliability; and
  • meet legal duties and protect the service, customers, and other people.

SignalRelay does not sell personal data and does not use customer Signal content for advertising.

Service providers and disclosure

We share data only as needed to operate the service, follow your direction, or meet a legal duty.

  • Stripe processes Checkout, subscription management, and payment data.
  • Fly.io hosts the application and processes network and application data.
  • Cloudflare provides DNS and can process network request data.
  • Brevo delivers verification, security, usage, and operational email.
  • GitHub and Google process OAuth data when you choose those sign-in or linking options.
  • Database, backup, and support providers process the limited data needed for their function.

These providers have their own terms and privacy policies. Stripe explains its payment-data practices in the Stripe Privacy Policy. Fly.io explains its hosting practices in the Fly.io Privacy Statement.

We can disclose data if required by valid legal process, to investigate abuse or fraud, to protect rights or safety, or as part of a business transfer. We do not give personal data to another party for its own advertising.

Cookies and similar storage

SignalRelay uses necessary first-party cookies and browser storage for sign-in, session security, registration intent, recent authentication, and interface operation. Disabling these values can prevent account access. SignalRelay does not currently use public-site ad cookies or third-party marketing analytics. Stripe-hosted pages can use cookies under Stripe's policy.

Retention and deletion

Signal history follows the effective plan: 7 days for Solo, 30 days for Builder, 90 days for Studio, and 7 days during collection-only access. Internal Operator access uses 180 days. Account security events are kept for 90 days. A shorter effective retention period can remove older Signals on the next retention run.

We keep account data while the account is active and as needed to provide support. We can keep billing, audit, security, backup, and legal records after account deletion when needed for finance, fraud prevention, dispute handling, security, or law. Deleted data can remain in protected backups until the backup expires.

Your choices and requests

You can update profile and security settings in the product. You can ask to access, correct, export, or delete personal data by emailing support@signalrelay.dev from the account email. We can ask you to verify account control. Your location can give you additional privacy rights. We will handle a valid request as required by applicable law.

Security

SignalRelay uses encrypted transport, signed ingress, scoped credentials, encryption for stored Relay secrets, credential hashing or keyed digests, access controls, and security event records. No system is completely secure. Protect your credentials, use only the data needed for a Signal, and contact Support promptly about suspected unauthorized access.

Children

SignalRelay is a developer service for adults and organizations. It is not directed to a person under 18, and we do not knowingly collect a child's personal data.

United States processing

SignalRelay and its providers can process data in the United States and other countries where they operate. The privacy and data-protection rules in those places can differ from the rules where you live.

Policy changes

We can update this Policy. We will post the new date and give notice of a material change when practical. Review this page when you make a material change to the type of data sent as a Signal.

Contact

Send privacy questions or requests to support@signalrelay.dev with “Privacy” in the subject.