Reads and updates the local Microsoft Edge bookmark tree for Preview, encrypted sync, Profiles, Tidy, Undo, and restore. It is not used to read browsing history or page content.
One purpose: private bookmark sync
Relay synchronizes Microsoft Edge bookmarks with an end-to-end encrypted bookmark vault that is created and unlocked on your device. Preview, Profiles, Tidy, Undo, recovery, and encrypted sharing exist to support that bookmark workflow.
Relay does not use bookmark or account data for advertising, credit decisions, data brokerage, unrelated profiling, or cross-site tracking. Relay does not inspect the pages you visit and does not collect Microsoft Edge browsing history.
Why Relay requests each permission
Keeps local session state, a random installation ID, plan cache, sync metadata, protected-operation credentials, and the local Undo point described below.
Resumes user-enabled Pro auto-sync after Microsoft Edge suspends the Manifest V3 worker. The alarm contains no bookmark content or advertising identifier.
Lets the extension use relayextension.com as its WebAuthn relying-party domain for passkeys. Relay has no content scripts and does not read or change website pages.
bookmarks, storage, alarms, and host access limited to https://relayextension.com/*. It does not request arbitrary website access.
What is readable, where, and when
Microsoft Edge makes the local bookmark tree available to Relay because you granted the bookmarks permission. Relay can therefore process readable titles, URLs, folder names, and structure on your device while it previews or performs a requested bookmark operation.
- Your Recovery Kit password derives the vault encryption key locally.
- Relay encrypts bookmark titles, URLs, folders, profiles, and restore snapshots before upload.
- Relay's servers store ciphertext plus the limited metadata described in this notice.
- Decryption happens inside the extension after you unlock Relay.
Relay's servers never receive or store readable bookmark contents, your plaintext Recovery Kit password, or the encryption key. The extension holds the password in Microsoft Edge extension-session storage only while you are signed in and clears it when Relay locks or the session ends.
Before a protected Sync, Tidy, profile switch, or restore, Relay can keep one readable snapshot in local Microsoft Edge extension storage. It may contain titles, URLs, folder names, and structure. It is never uploaded or included in diagnostics, is replaced by a later protected change, and is removed when Relay's local data is cleared. Someone with access to your Microsoft Edge profile or extension storage may be able to read it.
Usernames, passwords, and passkeys
A Relay account does not require your legal name, Microsoft account, or email address. Relay does store the username you choose. That username is the exact-match sharing handle and is associated with a stable account ID, Support ID, account status, discoverability choice, and authenticated activity timestamps. Discoverability is off by default.
Your username lets Relay find the account's registered passkey credentials before Microsoft Edge opens the passkey prompt. Relay stores each passkey's public key, credential identifier and limited credential metadata, plus a credential-bound encrypted vault-unlock envelope. Relay receives the signed WebAuthn response needed to verify the credential.
Microsoft Edge, your operating system, and your chosen passkey provider handle the passkey prompt. Relay's servers never receive your fingerprint, face scan, device PIN, plaintext password, or WebAuthn PRF output. A passkey is optional; password sign-in remains available.
The Recovery Kit remains yours
The Recovery Kit is created on your device and contains the secret needed to unlock the vault. Relay cannot recreate it, reset its password, or decrypt the vault for support.
If you choose to make a private recovery link, Relay places the username and Recovery Kit password after # in the URL and opens the device share sheet, with a local clipboard fallback. URL fragments are not sent in normal web requests. Relay's recovery page removes the fragment from the visible address, processes it locally, and can hand valid details to the installed extension through an origin- and path-scoped message. The handoff can remain in Microsoft Edge extension-session storage for no more than 15 minutes.
Relay's servers do not receive the recovery-link destination or fragment. Any email, messaging, notes, or storage service you choose may store and access the complete link. Anyone who obtains it can unlock the vault, so keep it in a private account you control.
Shares reveal contents only to the intended recipient
Relay creates a fresh encryption key locally. The server stores the encrypted collection, random identifier, bookmark count, expiry, import limit and count, and revocation state. The decryption key stays after # in the share link and is not sent to Relay.
Relay stores contact relationships, public sharing keys, encrypted profile payloads, bookmark counts, versions, and recipient-wrapped collection keys. The matching private sharing key stays inside the encrypted vault.
A recipient can read a collection only after receiving and using the required key. Revoking a capsule or profile share stops future Relay delivery; it cannot erase a copy a recipient already imported or saved.
What Relay can read to operate the service
| Data | Why it is used | Bookmark contents included? |
|---|---|---|
| Account identity | Chosen username, stable account and Support IDs, account status, discoverability, creation time, and last authenticated activity support sign-in, sharing, account controls, and assistance. | No |
| Installation and plan state | A random installation ID, plan and limit state, Relay version, Microsoft Edge family label, and minimal sync timestamps enforce device limits and keep features consistent. | No |
| Reliability and abuse controls | Rate-limit records, coarse latency and status, daily action success or failure counts, feature counters, safe error categories, and last-active times help operate and protect Relay. | No |
| Optional diagnostics | When you enable support diagnostics for 1, 3, or 7 days, Relay can retain operation names, safe error codes, Relay version, and the Microsoft Edge family label for that selected period. | No |
| Billing state | Stripe customer and subscription identifiers, plan status, and entitlement timing connect an optional Pro purchase to the correct encrypted vault. | No |
Relay does not include an advertising network, tracking pixel, website analytics SDK, or remote extension script. Service providers may process standard transport and security data such as IP address, request time, user-agent information, and error status to deliver and protect their services.
Who handles which part
Hosts Relay's database and server functions. It stores the encrypted vault, encrypted shares, account and credential records, billing state, and operational metadata.
Provides edge routing, rate limiting, security controls, and operational services. It may process standard network request metadata while protecting Relay endpoints.
Hosts Relay's public, passkey, recovery, and capsule pages. It may process standard web-delivery and security logs. Those pages contain no advertising or analytics scripts.
Distributes, reviews, and updates the extension. Microsoft may process store, installation, update, and diagnostic information independently under Microsoft's terms and privacy practices.
Microsoft Edge, the operating system, and your selected passkey provider perform credential prompts and may synchronize a credential. Relay receives cryptographic verification data, not biometrics or a device PIN.
Processes the optional Relay Pro subscription, currently US$18 per year. Stripe receives card and checkout details; Relay does not receive full card numbers. Stripe and Relay retain billing records as required for payments, support, accounting, and law.
These providers process data under their own security, retention, and legal obligations. Relay limits what it sends to the function each provider performs.
How long data remains
- Active account: the encrypted vault, account identity, passkey records, contacts, and active synced shares remain until you delete them or delete the account.
- Local session: the locally held password is cleared when Relay locks or the Microsoft Edge session ends.
- Local Undo: one readable snapshot remains until replaced by a later protected change or Relay's local extension data is cleared.
- Passkey ceremonies and recovery handoff: short-lived challenges, confirmation codes, and staged handoff data expire automatically; staged recovery details remain for no more than 15 minutes.
- Context Capsules: encrypted capsule data remains until its expiry, import limit, revocation, or owner-account deletion.
- Diagnostics: opt-in diagnostic events expire no later than the selected seven-day maximum.
- Pro restore history: encrypted snapshots expire after the 30-day restore window.
- Operations and billing: coarse account activity, pseudonymous security and audit records, and billing records may remain under Relay's retention controls when needed for support, abuse prevention, service integrity, financial records, or legal obligations.
Review, limit, revoke, or delete
- Keep exact-match sharing discoverability off or change it in Identity & sharing.
- Turn temporary support diagnostics on for 1, 3, or 7 days, or turn them off sooner.
- Review and revoke individual passkeys without removing the account's remaining sign-in methods.
- Revoke contacts, encrypted profile shares, and Context Capsules.
- Lock or sign out of Relay to clear the active local unlock session.
- Clear Relay's local extension data to remove the local Undo point and local session state.
You can delete the Relay account and encrypted cloud vault from Settings > Account > Delete account & vault. This removes the active cloud vault, account identity, passkeys, contacts, synced shares, and Context Capsules. Any linked Pro subscription is canceled as part of the protected deletion flow. Your local Microsoft Edge bookmarks remain in place.
Removing the extension alone removes local extension data but does not delete the cloud account. Use the in-product deletion control first if you also want the cloud account removed. Limited pseudonymous security or audit records may retain a stable account identifier for abuse prevention and operational integrity, and billing records may remain for financial and legal obligations.
Ask for help without sending secrets
For privacy requests, account questions, or complaints, email support@relayextension.com or visit Relay support. Include the Relay version, the visible error, and the Support ID shown in Identity & sharing when available.
Relay support will never ask for your password, Recovery Kit, passkey biometrics, device PIN, full bookmark export, sensitive URL list, or payment-card details.
If this policy changes materially, Relay will update the effective date on this page.