Stores encrypted vault data and operational metadata for sync.
What we collect
Relay stores the minimum data needed to operate secure bookmark sync:
| Data | What it is | Readable by Relay? |
|---|---|---|
| End-to-end encrypted vault | Your bookmarks, encrypted on your device before upload. | No |
| Local Undo point | One readable bookmark snapshot kept in this browser so Relay can reverse the most recent protected local change. It is never uploaded or included in diagnostics. | No, local only |
| Account identity | Your chosen username, which is also the sharing handle, stable account ID, Support ID, account status, discoverability choice, and authenticated activity timestamps. | Yes |
| Browser UUID | A random install identifier used for browser limits and service protection. | Yes, random |
| Optional passkey records | A credential public key, credential metadata, browser UUID, and one server-side share of an encrypted local unlock wrapper. | Verification only |
| Shared Context Capsules | An encrypted bookmark collection plus a random link identifier, bookmark count, optional expiry and import limit, import count, and revocation time. | Contents: No |
| Short-lived sync metadata | Minimal technical metadata used for rate limits and reliability. | Limited |
| Account activity and support | Daily product-action counters, Relay version, and browser family where the browser permits technical data; temporary operation and safe error codes only while support diagnostics are enabled. | Limited |
| Trusted sharing | Contact relationships, public sharing keys, encrypted shared profiles, and recipient-wrapped collection keys. Private sharing keys remain encrypted in the vault. | Metadata only |
What we do not collect
Relay does not collect, store, or transmit your legal name, email address, plaintext recovery key, WebAuthn PRF output, biometric data, device PIN, browsing history, location data, or advertising identifiers. Relay's servers never receive or store readable bookmark contents. The extension does intentionally keep one readable Undo point in this browser until it is replaced by a later protected change or local Relay data is cleared; anyone with access to the browser profile or extension storage may be able to read it. Relay also stores your chosen username and the limited account metadata described above.
Relay's use of information received from browser APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Relay uses this data only to provide or improve the encrypted bookmark sync and sharing features shown to the user. Relay does not use or transfer it for personalized advertising, creditworthiness, or unrelated purposes, and does not allow humans to read encrypted bookmark contents.
Optional technical data in Firefox
Relay for Firefox requires account registration information and encrypted bookmark data to provide sync. Technical and interaction data is optional and is never required to sync. It can include the Relay version, browser family or user-agent details, aggregate product actions, service-health measurements, and safe support error codes.
If you decline or revoke Firefox's optional technical and interaction permission, Relay marks requests as functional-only. The extension omits those technical fields, and Relay's gateway strips them again and skips service metrics and account-action telemetry before processing the sync request. A missing permission check or Firefox error is treated as declined. The random browser ID, account state, last-seen time, and encrypted vault operations remain necessary for authentication, browser limits, and sync.
Enabling temporary support diagnostics asks Firefox for this optional permission. Diagnostics can retain operation names and safe error codes for the selected 1, 3, or 7 days. Turning diagnostics off removes the optional permission. You can also review or revoke it at any time from Firefox's Add-ons and themes page under Relay's Permissions and data.
How encryption works
Your bookmarks are encrypted on your device before they leave the browser.
- Your recovery key derives the local encryption key.
- Each passkey added in a compatible Chromium browser receives a separate envelope encrypted by credential-bound WebAuthn PRF output.
- Relay encrypts bookmark data before upload.
- The server stores only the encrypted result and required operational metadata.
- Relay does not store your decryption key or a readable copy of your bookmarks.
Shared Context Capsules use a fresh random encryption key created in the extension. That key stays after the # in the link and is not sent to Relay's server. Recipients decrypt and preview the collection in their browser without creating an account.
Relay can open your device share sheet for a private recovery link, with a local clipboard fallback. Relay's servers do not receive or store the destination, shared contents, or recovery secret. The private secret remains after the # in the recovery link and is read locally by the recovery page. Compatible Chromium builds can accept it directly into the installed extension. Firefox's first release cannot accept website handoff, so users copy or download the Recovery Kit and enter its password in Relay. Any app you select may store and access the link.
Third-party services
Handles Relay Pro payments. Relay does not receive card details.
May process standard request metadata when you install Relay, visit Relay web pages, or download a manual release.
Relay does not include advertising networks, tracking pixels, analytics SDKs, or remote scripts. Where browser data permission allows it, sync requests contribute only aggregate service-health counts; the extension's activity timeline stays local.
Data retention
Your encrypted vault and account identity are retained until you delete your account. Daily account activity supports operations and account assistance. Optional diagnostic events expire no later than the selected seven-day maximum. Trusted-contact and synced-share records disappear when revoked or when a related account is deleted. Shared Context Capsules remain until they expire, reach their import limit, are revoked, or the owner deletes the Relay account. Pro Time Machine snapshots expire after their restore window. Payment records are handled by Stripe according to Stripe's retention requirements.
Your rights
You can delete your account and encrypted cloud vault at any time from Relay settings. Local bookmarks remain in the browser. Account identity, passkeys, contacts, synced shares, Context Capsules, and active vault data are removed with the account. Limited pseudonymous security and audit records may retain a stable account identifier for abuse prevention and operational integrity, while billing records may be retained for financial and legal obligations. These records are kept only for those purposes under Relay's retention controls. Support can locate an active account using the Support ID shown under Identity & sharing. Relay support will never ask for your recovery key, sharing private key, or readable bookmark export.
Security review
Relay limits source access to reduce cloning and repackaging risk. The trust boundary is documented at relayextension.com/trust, the security model is documented at relayextension.com/security, and approved independent reviewers may receive source access under written terms.
Changes to this policy
If this policy changes materially, we will update the date on this page.
Contact
Questions or concerns? Visit relayextension.com/support.