← Relay

Privacy Policy

Last updated 27 July 2026

Relay is a personal task and reference app. This policy explains what it stores, where that data lives, who else processes it, and what you can do about it. It is written to be specific rather than reassuring: every service named below actually receives data, and none are listed that do not.

Who is responsible

The data controller is Michael Fraser Buffini, Route de Lausanne 20D, 1180 Rolle, Switzerland. You can reach us at support@relaygtd.com.

Relay is offered from Switzerland and is subject to the Swiss Federal Act on Data Protection (FADP). If you are in the EU or UK, the GDPR and UK GDPR also apply to your data and this policy is written to meet them.

What Relay stores

Category What it is Why
Account Your email address, display name and profile photo URL, taken from the Google account you sign in with, plus an internal user id. To identify your account and sign you in.
Your content Everything you write: tasks, projects, reference items, notes, project outcomes and scratchpads, checklists, dates, horizons, and the workspaces, contexts and contacts you define. Contacts hold whatever names you type into them. This is the product. Without it there is nothing to show you.
Files Files you upload, drop onto the app, share to it, or send as email attachments. So attachments and reference material stay with their item.
Settings Your time zone, locale, theme, list preferences and the dates you last ran a daily or weekly review. So the app behaves consistently across your devices. The time zone in particular is needed to work out what "today" means for you.
Notification tokens A device identifier issued by Firebase Cloud Messaging. To send reminders and keep home-screen widgets current.
Subscription status Your plan, its status and renewal dates. Payment card details are never sent to or stored by Relay. To know whether your subscription is active.
Connection tokens Access tokens for services you choose to connect. Held on the server only; the app itself cannot read them. To sync with a service after you have connected it.
Your capture address A private, randomly generated @in.relaygtd.com address, and a count of how many messages it has accepted recently. So forwarded email reaches your Inbox, and so the address cannot be flooded.

Relay has no analytics and no advertising. There is no tracking of how you use the app, no third-party analytics SDK, no advertising identifier, and no profiling. Nothing about you is sold or shared for marketing, by us or by anyone else.

Where your data is stored

Relay runs on Google Cloud and Firebase. Your database records and your uploaded files are stored in Zurich, Switzerland (Google's europe-west6 region).

Relay's server-side code runs in Zurich too, in the same europe-west6 region, so your data is not routed through the United States in normal use. Until August 2026 part of it ran in Google's us-central1 region and this section said so; that processing has moved.

Two exceptions we would rather name than gloss. Google's Gemini API, which powers the optional AI prompts, and Google's own authentication and push-notification services are global and may process a request outside Europe. Google Cloud is certified under the EU-US and Swiss-US Data Privacy Frameworks, and Google's standard contractual clauses apply.

Who else processes your data

These are our processors. Each acts on our instructions and only to provide part of Relay.

Processor What it receives When
Google Cloud / Firebase Everything listed above. Authentication, database, file storage, server-side processing, push notifications and crash reports. Always. Relay cannot run without it.
Google Gemini The text of the one item you are asking about — usually a title, and for a project audit its outcome, notes and child items. Only when you press the prompt button. Relay never sends your text to the AI on its own — there is no background analysis, no timer and no send-on-save. You can switch the feature off entirely in Settings, and then nothing is sent at all.
Mailgun (EU region) Any email you forward to your capture address, including its attachments. Only for messages you send there. Mailgun handles no other data.
Google Calendar, Google Tasks Read access to your calendar and read/write access to your tasks. Only if you connect them, and each is connected separately — granting one does not grant the other.
Todoist, Notion, Linear The items Relay syncs with that service, in whichever direction that integration works. Only if you connect them.

About the AI feature specifically

Relay's AI prompts are deliberately narrow. They ask you questions about what you have written; they never rewrite your words, and they never create or complete tasks for you.

The text is sent to Google's Gemini API, on a paid plan. That distinction matters and is why we mention it: under Google's terms for paid use, your prompts and the responses are not used to train or improve Google's models, and they are not read by human reviewers for that purpose. Google may retain them briefly to detect abuse, as its terms describe. On the free tier of the same API none of that would be true, which is why Relay does not use it.

Nothing is sent unless you press the button, and switching the feature off in Settings stops it entirely.

Relay uses no third-party AI provider, no model aggregator or gateway, and no self-hosted model. Google's Gemini API is the only model service it talks to.

Limited Use

Relay's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Raw or derived user data received from Google Workspace APIs is used only to provide the features you can see in the app. It is never used, transferred, or sold to create, train, or improve any foundational or generalized artificial intelligence or machine learning model.

Why we are allowed to hold it

How long it is kept

Until you delete it. Your data stays for as long as your account exists, including after a subscription lapses, so that everything is still there if you come back.

When you delete your account, everything goes: your content, your files, your settings, your capture address, and the tokens for any connected service, which are also revoked at the provider. Deletion is immediate and cannot be undone — there is no trash to recover from.

If you delete your account, links in a previous export stop working. An export lists your files as links, and deleting the account deletes the files those links point at. Download anything you want to keep before deleting.

Your rights

You can, at any time:

A lapsed subscription never blocks reaching, exporting or deleting your own data. Whatever else a paywall gates, it does not gate that.

If you think we have handled your data badly, please tell us first at support@relaygtd.com. You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or, if you are in the EU or UK, to your national data protection authority.

Security

Data is encrypted in transit and at rest. Access is enforced by server-side rules that scope every record and every file to the account that owns it, so one account cannot read another's data even if the app asked it to. Sensitive credentials — your connection tokens and your capture address — are readable only by Relay's server code and are denied to the app entirely.

No system is perfect. If we discover a breach affecting your data we will tell you and the relevant authority as required by law.

Children

Relay is not intended for children under 16, and we do not knowingly collect their data.

Changes

If this policy changes materially we will tell you in the app or by email before the change takes effect. The date at the top always reflects the current version.