Information we process
We process the account details you submit (name, email, and a one-way password hash); product URLs, audience descriptions, categories, exclusions, domain-verification state, public-page evidence, moderation decisions, approved creative, slot locations, optional public network-region preferences, campaign credits, placement history, and aggregate impression and click totals. When live billing is enabled, the application stores Stripe Checkout and credit identifiers, but Stripe—not Project Relay—handles payment-card details.
Why we use it
We use this information to authenticate founders, confirm product control, build source-linked profiles, prevent prohibited or competing matches, coordinate approved recommendations, verify placements, settle campaign credits, measure aggregate delivery, investigate abuse, provide account exports, and operate the service securely. We do not sell founder or visitor data.
Public-page profiling and AI
Relay retrieves only the public HTTPS URLs a verified owner submits. Extracted product text may be processed by Firecrawl and private LWS-hosted AI services to create a structured profile and draft recommendation. Every retained claim includes a source URL, and a founder must approve creative before publication. Do not submit confidential, personal, or licensed material through a public product URL.
Widget measurement
The widget counts aggregate impressions and referral clicks, filters obvious bots, and stores totals against a placement. It does not set cross-site cookies, fingerprint visitors, build visitor profiles, or expose visitor identities to participating founders. Infrastructure security logs can temporarily include standard request metadata such as IP address, user agent, path, and timestamp.
Live Relay Network
The public network includes a product only while it participates in an active relay whose product domains, creative, and placement slot remain approved and verified, and only when both participating founders selected a supported public region. A founder chooses whether the region represents a broad team location or hosting region and separately chooses whether to publish their display name. The public feed can include product name, verified URL, public-page summary, categories, coarse city and country, relationship direction, approved headline, and activation time. It excludes email addresses, account identifiers, exact addresses, origin IP addresses, visitor data, payment details, and products without active links. Project Relay does not infer public locations from founder or visitor IP addresses.
Cookies and local storage
Signed-in founders receive an HTTP-only, same-site session cookie. It expires after 30 days and is cleared at logout. Local browser preferences store light or dark appearance and the analytics choice described below. The public widget does not set a Relay cookie.
Optional site analytics
Project Relay loads its dedicated Google Analytics 4 tag only after a visitor chooses “Allow analytics.” When allowed, it measures page visits and limited founder actions such as account creation, product submission, and checkout start. Advertising storage, ad personalization, and Google signals are disabled. Relay does not send form contents, email addresses, product submission text, or widget visitor activity to Google Analytics. Google may process page URL, referrer, browser and device details, and coarse network-derived location under its own privacy terms. Declining prevents the tag from loading. The persistent “Analytics choices” control lets a visitor change the choice on any page.
Service providers and disclosure
The production stack uses private LWS infrastructure for hosting and databases, Firecrawl for founder-approved public-page retrieval, and Stripe for hosted Checkout when billing is activated. We may disclose limited information when required by law, to protect users and the service, or to a vetted processor operating under appropriate instructions. A final subprocessor and international-transfer schedule remains a public-launch gate.
Retention and founder controls
Signed-in founders can download a machine-readable account export and permanently delete their Relay account. Application deletion removes the account, sessions, products, slots, creative, credits, placements, and associated aggregates. Stripe and infrastructure providers may retain independent payment, fraud, tax, backup, or security records under their legal obligations and retention policies. Moderation evidence needed for an active abuse investigation may be retained only as permitted by the final policy.
Security and choices
Relay uses scoped verification tokens rather than third-party passwords, server-side sessions, origin checks for state-changing requests, restricted outbound retrieval, and access-controlled operator actions. No online service can promise absolute security. Founders should use a unique password and promptly report suspected misuse to [email protected].
Also review the terms of service and acceptable-use rules.