Security and privacy

How Relay keeps collection narrow, credentials safe and contributors separate.

Before opt-in

  • No contribution requests, no event buffering, no identifiers and no cookies.
  • The only request the SDK can make is fetching consent text, and only when you ask it to.

Credentials

  • Public keys identify your app. They cannot read data, administer anything or export.
  • Server credentials are stored as SHA-256 hashes, can be rotated with a 24-hour overlap, and revoked instantly.
  • Attestations expire after 5 minutes and are single-use.
  • Contributor tokens last 15 minutes and are scoped to one contributor, one consent receipt and one collection scope.
  • Allowed origins are a browser policy, never authentication.

Contributors

  • Pass an opaque user ID as the subject, never an email or name. Relay stores only an HMAC of it, salted per app.
  • The same person in two apps gets two unrelated pseudonyms, so they are never linked across apps.
  • Pseudonymous data can still be personal data. Treat contributions with the same care as the rest of your user data.

On every batch

  • Consent and scope are checked server-side. Tokens carry a version that withdrawal increments.
  • Events are validated against your schema. Unknown fields are stripped and the event quarantined.
  • Batches are idempotent and rate-limited.

Before anything is licensed

  • A dataset must be approved, and an executed agreement must exist whose purpose the contributor consented to.
  • An administrator must explicitly approve each export.
  • Export files are never served from public URLs.