Privacy Policy
Last updated June 23, 2026
Relay (“we”, “us”) provides AI phone-receptionist services to businesses. This policy explains what data we process and why. Questions: kupuelel@gmail.com.
Information we process
To operate the service we process: (a) account information for the operator (email); (b) business information you enter to configure a receptionist; (c) calendar/booking data needed to check availability and create, change, or cancel appointments on a connected account; and (d) call records (timestamps, duration, cost, and transcripts/summaries generated by our telephony provider) used to show usage and billing.
Google user data
When you connect Google Calendar, we request only the scopes needed to check free/busy and manage events you book through the service (calendar.events and calendar.freebusy). We use this access solely to read availability and to create, update, or delete the appointments handled by your receptionist. We do not sell Google user data, do not use it for advertising, and do not share it with third parties except the subprocessors below as required to provide the service. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time in your Google Account’s security settings or by disconnecting the calendar in the app.
How we secure and protect data
We apply layered safeguards to all data, with specific protections for sensitive data such as connected-account credentials and Google Calendar data:
Encryption in transit. All data is transmitted over encrypted connections (HTTPS / TLS 1.2+). Credentials and user data are never sent over unencrypted channels.
Encryption at rest. Sensitive data — including Google OAuth access and refresh tokens and any booking-provider credentials — is encrypted at rest using AES-256-GCM authenticated encryption, with an application key held separately from the database. Our database and storage providers (Supabase, Vercel) additionally encrypt all stored data at rest in their respective regions.
Access control and tenant isolation. Every record is scoped to the owning account and enforced by per-row access policies (row-level security), so one operator can never access another operator’s data. Sensitive credentials are decrypted only on our servers, only at the moment they are needed to carry out an action you initiated, and are never exposed to the browser or any client-side code.
Least privilege. We request only the minimum Google scopes required (free/busy and the events your receptionist books), and you can revoke access at any time from your Google Account or by disconnecting the calendar in the app.
Operational safeguards. Access to production systems is restricted and authenticated, and we log security-relevant events. If we become aware of a breach affecting your data, we will notify affected users without undue delay.
Subprocessors
We rely on: Supabase (database/auth), Vercel (hosting), Retell AI (telephony/voice), Anthropic (prompt generation), and the booking system you connect (Google Calendar and/or Square). Each processes data only as needed to deliver the service.
Retention & deletion
Connection tokens are kept until you disconnect the provider or delete the project. Call records are retained to support usage history and billing. To delete your data, delete the relevant project or contact us at the email above and we will remove it.
Changes
We may update this policy; material changes will be reflected by the “last updated” date above.