Relay/privacy
DocsBlogGet started →
PRIVACY POLICY

Your data, in plain English.

Last updated: July 17, 2026

This policy covers relayevals.com and the scriptonia CLI, operated by Relay Labs, Inc. ("we"). The short version: we store what the product needs to work, we don't sell it, and you can have it deleted with one email.

What we collect

Account. Your email and name from Google sign-in. No passwords are stored — authentication is Google OAuth.

Customer signal you submit. Text you add via scriptonia add (tickets, transcripts, notes) is stored and embedded so it can be retrieved by meaning. This is the product; we only store what you explicitly send.

Generated artifacts. Contexts, plans, comments, and usage metering (credits) tied to your account.

Verification input. The default scriptonia verify path is deterministic and local-first; it does not upload your repository. If you explicitly enable semantic evaluation, only the bounded evidence bundle for that check is sent through the authenticated Relay gateway for processing.

Sandbox execution input. If an authorized server or CLI explicitly calls our sandbox execution API, the submitted code, selected language, and resulting output are processed for that request. The sandbox API is not used automatically by brain building, planning, or verification. We retain only hashes, status, byte counts, timing, and billing/security metadata for duplicate prevention and auditing; submitted code and returned output are not persisted by Relay.

Payments. Handled by Polar. We never see or store card numbers — we receive your email, plan, and subscription status.

What we don't collect: your full source repository by default, analytics trackers, or advertising identifiers. Initialization scans repository structure locally; planning may send a bounded repository map, not the full source tree, so generated steps can reference real files. Code reaches the sandbox service only when an authorized caller explicitly submits it for execution.

How it's processed

Signal is processed by AI models to produce contexts and plans, and opt-in bounded evidence can be processed to produce advisory semantic judgments: Anthropic (Claude) for context enrichment, and OpenAI for embeddings, plan synthesis, connected Deep Brain extraction, and semantic evaluation, under their API terms — neither trains on this data. Hosting and storage run on Supabase (Postgres) and our hosting provider. Background jobs run on Inngest. These processors receive only what they need to perform their function.

Optional code execution runs through E2B, which provisions an isolated, transient sandbox for the requested run. The submitted code and execution output pass through E2B infrastructure under its terms and privacy policy. Relay does not forward the host process environment or provider credentials into the sandbox, and the server-side E2B credential is never returned to the browser or caller. Outbound internet egress is denied, unauthenticated public traffic is disabled, and submitted code is not run if Relay cannot verify the provider's deny-all policy and application-level isolation.

What we never do

We don't sell your data. We don't share it with advertisers. We don't train models on your signal or submitted sandbox code. One customer's signal or sandbox result is never visible to another account.

Retention & deletion

Data is retained while your account is active. Email sathwik07@relayevals.com from your account address and we'll delete your account and all associated signal, contexts, plans, stored execution metadata, and billing records we are not legally required to retain within 30 days, confirmed in writing.

Questions

sathwik07@relayevals.com — a human answers, usually the same day. If we change this policy, the date above changes and material changes are announced on the blog.