Effective 13 September 2026 · Version 1.1
Privacy Policy
What Relay collects, what it doesn't, and what could be handed over if we were compelled.
The short version
- An account is a username and an email address. No real name, no phone number.
- Our servers never see your messages in readable form, and keep no record of who you exchanged them with.
- Compelled to hand over everything we hold about a user, we could produce a username, an email address, and an undelivered message we can't read. Not a contact list, not a history, not a single readable word.
- The waitlist on this website is the one list we keep, and we delete it after launch.
Who we are
Relay is operated by Morgan Daly, in Queensland, Australia. For anything in this policy, including a request about your data, write to privacy@relaymsg.app — that address reaches a person, not a ticketing queue.
We're responsible for the account email and the waitlist. For messages sent through the app we're a conduit: we carry encrypted data we can't read and don't keep.
Your account
An account is a username, an email address, and a password. We store the username and the address. The password is stored only as a hash — we never see it, and we can't recover it for you.
Your username is public. It's how people add you, and it appears in invite links you share. Pick it with that in mind.
Your email address isn't public, and we don't send marketing to it. Use any address you like — a forwarding alias works as well as your everyday one, and we'd rather you did that than hand us something you care about. Nothing in Relay checks who you really are.
We also hold a push token for each of your devices, issued by Apple, so we can wake the device when something arrives for it. It's tied to your account and goes when the account does.
Phone number sign-in is planned. When it arrives this policy will be updated before it ships, and the change called out at the top of this page.
Your messages
Messages are encrypted on your device with the Signal Protocol — a post-quantum key exchange, then the Double Ratchet — to keys held only on the devices in the conversation. Your keys are generated on your phone and never leave it, which is also why we can't recover anything for you.
While a message is in transit our servers hold an encrypted payload and the public key material needed to deliver it. Once your phone collects it, the payload is deleted. There is no message history on our side to keep, search, or surrender.
Attachments work slightly differently: a file has to stay available long enough for the other device to fetch it, so attachment data is held — encrypted, and unreadable to us — for up to 30 days, then purged whether it was collected or not.
What we never receive
- Your address book. Relay never reads or uploads your contacts.
- Your message content. Encryption happens on your device, to keys we don't hold.
- Who you talk to. Messages aren't stored against a sender or a recipient.
- Your location. The app requests no location permission of any kind.
- Usage analytics. No analytics SDK, no crash reporter, no attribution framework is bundled in the app.
Notifications
Push notifications route through Apple, which is unavoidable on iOS. We send Apple a content-free wake-up signal — no sender, no preview, no conversation reference. Your device fetches and decrypts the message itself, then draws the notification.
Apple can observe that a device received a push. Apple's handling of that is governed by Apple's privacy policy, not ours.
Where your data is
Some of what Relay depends on runs outside Australia. Apple's push infrastructure is global, and the service that sends the waitlist email may be hosted overseas.
Where that happens, everything in this policy still applies. Your messages stay encrypted end to end throughout, so a provider carrying or hosting them cannot read them — which is the point of encrypting before anything leaves your phone rather than trusting the infrastructure in between.
Keeping it safe
Connections between the app and our servers are encrypted in transit, and the message payloads they carry are separately encrypted end to end. Access to our infrastructure is limited to the people who need it to run the service.
On your device, the message database is encrypted with SQLCipher, so the history sitting on your phone isn't readable by anything that manages to get at the file.
The strongest protection here isn't a policy commitment — it's that we don't hold the material in the first place. A breach of our servers exposes ciphertext we can't read ourselves.
If a breach ever did occur that was likely to cause you serious harm, we'll notify you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires — promptly, and without waiting to have every detail.
This website
No cookies, no analytics, no tracking pixel, no session identifier, no advertising tag. Web fonts are currently served by Google Fonts, which means Google receives a request from your browser when you load a page here; we're moving those files onto our own server.
Our host keeps short-lived access logs for operational and abuse-prevention purposes. These contain IP addresses and are retained for 30 days, then deleted.
The waitlist
If you enter an email address on this site, we store that address and the date you submitted it. We use it for exactly one thing: a single message telling you Relay is available.
No newsletter, no sharing, no profile. Within 30 days of launch, the entire list is deleted. You can have your address removed sooner by writing to privacy@relaymsg.app — no verification loop, no retention offer.
The lawful basis is your consent, given by submitting the form, and you may withdraw it at any time.
Legal requests
We respond to valid legal process, and we can only produce what exists. For a Relay user that's the email address on their account, and any undelivered message as encrypted data we can't read. There's no message history or contact list to disclose.
Where we're legally permitted to tell you your data was requested, we will.
Your rights
You can ask what we hold about you, ask us to correct it, and ask us to delete it. Write to privacy@relaymsg.app and we'll act within 30 days. For the app these requests are largely moot — beyond the account email there is nothing tied to you.
In Australia the Australian Privacy Principles set those rights out. In the UK or EU the equivalents are the UK GDPR and GDPR.
Complaints
If you think we've handled your data badly, tell us first at privacy@relaymsg.app. We'll acknowledge within five working days and give you a considered answer within 30.
If that answer doesn't satisfy you, you can take it to the Office of the Australian Information Commissioner, or to your national data protection authority if you're in the UK or EU. You don't need our permission, and you don't have to come to us first.
Children
Relay isn't directed at children under 13, and we don't knowingly collect their data. Since we collect no identifying data beyond an email address, we have no mechanism to determine a user's age, and we don't attempt to build one.
Changes
If this policy changes in a way that affects what we collect, we'll say so plainly at the top of this page and in the app before the change takes effect. Previous versions stay available so you can see what changed.