Security and privacy
How Relay keeps collection narrow, credentials safe and contributors separate.
Before opt-in
- No contribution requests, no event buffering, no identifiers and no cookies.
- The only request the SDK can make is fetching consent text, and only when you ask it to.
Credentials
- Public keys identify your app. They cannot read data, administer anything or export.
- Server credentials are stored as SHA-256 hashes, can be rotated with a 24-hour overlap, and revoked instantly.
- Attestations expire after 5 minutes and are single-use.
- Contributor tokens last 15 minutes and are scoped to one contributor, one consent receipt and one collection scope.
- Allowed origins are a browser policy, never authentication.
Contributors
- Pass an opaque user ID as the subject, never an email or name. Relay stores only an HMAC of it, salted per app.
- The same person in two apps gets two unrelated pseudonyms, so they are never linked across apps.
- Pseudonymous data can still be personal data. Treat contributions with the same care as the rest of your user data.
On every batch
- Consent and scope are checked server-side. Tokens carry a version that withdrawal increments.
- Events are validated against your schema. Unknown fields are stripped and the event quarantined.
- Batches are idempotent and rate-limited.
Before anything is licensed
- A dataset must be approved, and an executed agreement must exist whose purpose the contributor consented to.
- An administrator must explicitly approve each export.
- Export files are never served from public URLs.