Microsoft Edge privacy

Your bookmarks sync. Your contents stay private.

Relay for Microsoft Edge encrypts bookmark contents on your device before upload. This notice explains the narrow permissions, local data, service data, and controls behind that promise.

Effective and last updated: July 26, 2026

The short version

Readable bookmarks on Relay serversNo
Name or email for a Relay accountNot required
Advertising or cross-site trackingNo
Cloud account deletionInside Relay
Scope and purpose

One purpose: private bookmark sync

Relay synchronizes Microsoft Edge bookmarks with an end-to-end encrypted bookmark vault that is created and unlocked on your device. Preview, Profiles, Tidy, Undo, recovery, and encrypted sharing exist to support that bookmark workflow.

Relay does not use bookmark or account data for advertising, credit decisions, data brokerage, unrelated profiling, or cross-site tracking. Relay does not inspect the pages you visit and does not collect Microsoft Edge browsing history.

Extension access

Why Relay requests each permission

bookmarks

Reads and updates the local Microsoft Edge bookmark tree for Preview, encrypted sync, Profiles, Tidy, Undo, and restore. It is not used to read browsing history or page content.

storage

Keeps local session state, a random installation ID, plan cache, sync metadata, protected-operation credentials, and the local Undo point described below.

alarms

Resumes user-enabled Pro auto-sync after Microsoft Edge suspends the Manifest V3 worker. The alarm contains no bookmark content or advertising identifier.

relayextension.com host access

Lets the extension use relayextension.com as its WebAuthn relying-party domain for passkeys. Relay has no content scripts and does not read or change website pages.

Narrow by design: Relay requests bookmarks, storage, alarms, and host access limited to https://relayextension.com/*. It does not request arbitrary website access.
Encryption boundary

What is readable, where, and when

Microsoft Edge makes the local bookmark tree available to Relay because you granted the bookmarks permission. Relay can therefore process readable titles, URLs, folder names, and structure on your device while it previews or performs a requested bookmark operation.

  1. Your Recovery Kit password derives the vault encryption key locally.
  2. Relay encrypts bookmark titles, URLs, folders, profiles, and restore snapshots before upload.
  3. Relay's servers store ciphertext plus the limited metadata described in this notice.
  4. Decryption happens inside the extension after you unlock Relay.

Relay's servers never receive or store readable bookmark contents, your plaintext Recovery Kit password, or the encryption key. The extension holds the password in Microsoft Edge extension-session storage only while you are signed in and clears it when Relay locks or the session ends.

Local Undo is intentionally readable.

Before a protected Sync, Tidy, profile switch, or restore, Relay can keep one readable snapshot in local Microsoft Edge extension storage. It may contain titles, URLs, folder names, and structure. It is never uploaded or included in diagnostics, is replaced by a later protected change, and is removed when Relay's local data is cleared. Someone with access to your Microsoft Edge profile or extension storage may be able to read it.

Account and sign-in

Usernames, passwords, and passkeys

A Relay account does not require your legal name, Microsoft account, or email address. Relay does store the username you choose. That username is the exact-match sharing handle and is associated with a stable account ID, Support ID, account status, discoverability choice, and authenticated activity timestamps. Discoverability is off by default.

Your username lets Relay find the account's registered passkey credentials before Microsoft Edge opens the passkey prompt. Relay stores each passkey's public key, credential identifier and limited credential metadata, plus a credential-bound encrypted vault-unlock envelope. Relay receives the signed WebAuthn response needed to verify the credential.

Microsoft Edge, your operating system, and your chosen passkey provider handle the passkey prompt. Relay's servers never receive your fingerprint, face scan, device PIN, plaintext password, or WebAuthn PRF output. A passkey is optional; password sign-in remains available.

Recovery

The Recovery Kit remains yours

The Recovery Kit is created on your device and contains the secret needed to unlock the vault. Relay cannot recreate it, reset its password, or decrypt the vault for support.

If you choose to make a private recovery link, Relay places the username and Recovery Kit password after # in the URL and opens the device share sheet, with a local clipboard fallback. URL fragments are not sent in normal web requests. Relay's recovery page removes the fragment from the visible address, processes it locally, and can hand valid details to the installed extension through an origin- and path-scoped message. The handoff can remain in Microsoft Edge extension-session storage for no more than 15 minutes.

Relay's servers do not receive the recovery-link destination or fragment. Any email, messaging, notes, or storage service you choose may store and access the complete link. Anyone who obtains it can unlock the vault, so keep it in a private account you control.

Encrypted sharing

Shares reveal contents only to the intended recipient

Context Capsules

Relay creates a fresh encryption key locally. The server stores the encrypted collection, random identifier, bookmark count, expiry, import limit and count, and revocation state. The decryption key stays after # in the share link and is not sent to Relay.

Trusted profile sharing

Relay stores contact relationships, public sharing keys, encrypted profile payloads, bookmark counts, versions, and recipient-wrapped collection keys. The matching private sharing key stays inside the encrypted vault.

A recipient can read a collection only after receiving and using the required key. Revoking a capsule or profile share stops future Relay delivery; it cannot erase a copy a recipient already imported or saved.

Necessary service data

What Relay can read to operate the service

Data Why it is used Bookmark contents included?
Account identity Chosen username, stable account and Support IDs, account status, discoverability, creation time, and last authenticated activity support sign-in, sharing, account controls, and assistance. No
Installation and plan state A random installation ID, plan and limit state, Relay version, Microsoft Edge family label, and minimal sync timestamps enforce device limits and keep features consistent. No
Reliability and abuse controls Rate-limit records, coarse latency and status, daily action success or failure counts, feature counters, safe error categories, and last-active times help operate and protect Relay. No
Optional diagnostics When you enable support diagnostics for 1, 3, or 7 days, Relay can retain operation names, safe error codes, Relay version, and the Microsoft Edge family label for that selected period. No
Billing state Stripe customer and subscription identifiers, plan status, and entitlement timing connect an optional Pro purchase to the correct encrypted vault. No

Relay does not include an advertising network, tracking pixel, website analytics SDK, or remote extension script. Service providers may process standard transport and security data such as IP address, request time, user-agent information, and error status to deliver and protect their services.

Service providers

Who handles which part

Supabase

Hosts Relay's database and server functions. It stores the encrypted vault, encrypted shares, account and credential records, billing state, and operational metadata.

Cloudflare

Provides edge routing, rate limiting, security controls, and operational services. It may process standard network request metadata while protecting Relay endpoints.

Netlify

Hosts Relay's public, passkey, recovery, and capsule pages. It may process standard web-delivery and security logs. Those pages contain no advertising or analytics scripts.

Microsoft Edge Add-ons

Distributes, reviews, and updates the extension. Microsoft may process store, installation, update, and diagnostic information independently under Microsoft's terms and privacy practices.

Microsoft Edge and passkey services

Microsoft Edge, the operating system, and your selected passkey provider perform credential prompts and may synchronize a credential. Relay receives cryptographic verification data, not biometrics or a device PIN.

Stripe

Processes the optional Relay Pro subscription, currently US$18 per year. Stripe receives card and checkout details; Relay does not receive full card numbers. Stripe and Relay retain billing records as required for payments, support, accounting, and law.

These providers process data under their own security, retention, and legal obligations. Relay limits what it sends to the function each provider performs.

Retention

How long data remains

Your controls

Review, limit, revoke, or delete

You can delete the Relay account and encrypted cloud vault from Settings > Account > Delete account & vault. This removes the active cloud vault, account identity, passkeys, contacts, synced shares, and Context Capsules. Any linked Pro subscription is canceled as part of the protected deletion flow. Your local Microsoft Edge bookmarks remain in place.

Removing the extension alone removes local extension data but does not delete the cloud account. Use the in-product deletion control first if you also want the cloud account removed. Limited pseudonymous security or audit records may retain a stable account identifier for abuse prevention and operational integrity, and billing records may remain for financial and legal obligations.

Support and contact

Ask for help without sending secrets

For privacy requests, account questions, or complaints, email support@relayextension.com or visit Relay support. Include the Relay version, the visible error, and the Support ID shown in Identity & sharing when available.

Relay support will never ask for your password, Recovery Kit, passkey biometrics, device PIN, full bookmark export, sensitive URL list, or payment-card details.

If this policy changes materially, Relay will update the effective date on this page.