Back to home

Privacy Policy

Last updated: September 9, 2026

At OpenRelay ("we", "our", or "us"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

1. Information We Collect

Information You Provide

  • Account information (email address, name, password)
  • Payment information (processed securely by our payment providers)
  • Communication data (support tickets, emails, feedback)
  • Provider information (hardware specifications, node configuration)

Information Collected Automatically

  • Usage data (API calls, deployment metrics, performance data)
  • Inputs and outputs (the content of your inference API requests and the responses returned, together with related usage metadata)
  • Device information (browser type, operating system, IP address)
  • Cookies and similar tracking technologies
  • Log data (access times, pages viewed, referring URLs)

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send technical notices, updates, and support messages
  • Respond to your comments, questions, and requests
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent fraudulent or unauthorized activity
  • Personalize and improve your experience

3. Information Sharing

We do not sell personal information that identifies you. As described in Section 14, we may create aggregated or de-identified data and use, license, or disclose it, including to third parties. We may also share information in the following circumstances:

  • Service Providers: With vendors who assist in providing our services, including our payment processor, our support and messaging tools, our product analytics provider (see Section 8), and our device identification provider (see Section 10)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you have given us permission to share

4. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes:

  • Encryption of data in transit and at rest
  • Regular security assessments and audits
  • Access controls and authentication mechanisms
  • Secure infrastructure with hardware-level isolation

5. Data Retention

We retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. We may retain aggregated or de-identified data, which does not identify you, for as long as we have a business purpose for it, as described in Section 14.

6. Your Rights

Depending on your location, you may have certain rights regarding your personal information:

  • Access and receive a copy of your data
  • Rectify inaccurate or incomplete information
  • Request deletion of your personal data
  • Object to or restrict processing of your data
  • Data portability
  • Withdraw consent at any time
  • Opt out of third-party website-visitor identification by visiting app.retention.com/optout

7. Cookies

We use cookies and similar tracking technologies to collect and track information about your browsing activities. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.

8. Analytics and Session Recording

We use PostHog, a product analytics service, to understand how our website and dashboard are used. PostHog processes this data on our behalf on servers in the United States. Analytics requests are served from our own domains rather than sent directly to PostHog, so blocking the PostHog hostname will not prevent this collection. Clearing cookies and site data for our domains resets the identifier described below, and you can ask us to stop collecting entirely using the contact details at the end of this section.

Through PostHog we collect:

  • Product usage: pages viewed, links and buttons clicked, referring URL, approximate location derived from IP address, and browser and device information
  • Errors: client-side errors and their stack traces, so we can find and fix broken pages
  • Session recordings: on openrelay.inc and app.openrelay.inc we record a reconstruction of your session, covering the content displayed on the page, your mouse movement, scrolling, and clicks. Text you type into form fields, including passwords, is masked before the recording leaves your browser. Recordings are not made on our beta or preview environments.

While you are signed out, this data is tied to a random identifier stored in your browser. When you sign in to the dashboard we associate it with your account, including your user ID, email address, and name, so that we can support you and understand how accounts use the product. Signing out clears the identifier so that another person using the same browser does not inherit your profile.

We do not sell this data or use it for advertising. To request access to or deletion of your analytics data, or to ask us to exclude your account from session recording, email privacy@openrelay.inc.

9. Website Visitor Identification

When you visit or log in to our Website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email address. We (or service providers acting on our behalf) may then send communications and marketing to those email addresses. You may opt out of receiving this advertising by visiting app.retention.com/optout. You may also opt out of the collection of your personal data in compliance with GDPR by visiting rb2b.com/rb2b-gdpr-opt-out.

10. Device Identification for Fraud Prevention

In our dashboard, once you are signed in, and specifically when you create an organization, add funds, or save a payment card, we use Fingerprint, Inc., a device intelligence service, to help detect fraud and account abuse. Fingerprint's script runs in your browser and reads signals about your browser and device, such as browser version, screen and hardware characteristics, and timezone, and returns a visitor identifier together with fraud-risk signals, for example whether the browser looks like it is running through a VPN, an emulator, or automation tooling. The data processed for this purpose is device data (hardware and operating system characteristics), browser data (version, configuration, and settings), network data (your IP address and signals derived from it, such as whether it belongs to a VPN, proxy, or data center), and the approximate location derived from your IP address. OpenRelay is the controller of this data and Fingerprint processes it on our behalf under its data processing agreement. The identifier does not carry your name, email address, or payment details.

We use the identifier and its fraud-risk signals to detect accounts linked to confirmed fraud and to secure your account. We do not use this data for advertising. Based on these signals we may decline a payment or place a new account in a review state until a person on our team has looked at it; an account is never suspended on these signals alone without that review. This processing relies on our legitimate interest in preventing fraud and abuse, so it does not require your consent.

Fingerprint processes this data on our behalf in the United States. Its handling of the data is governed by the Fingerprint Privacy Policy. Fingerprint retains the underlying identification events for 30 days. We keep the verified device identifier and its fraud verdict for as long as your account is active, and for one year afterward.

You can request access to or deletion of this data using the contact details in Section 15. A deletion request also triggers deletion of the corresponding record at Fingerprint through its API.

11. Third-Party Services

Our service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you access.

Fraud and abuse prevention. On our sign-in, sign-up, and payment pages we use Google reCAPTCHA and Cloudflare Turnstile to tell real people apart from automated traffic. These services run in your browser and send information about your device, browser, and interaction with the page to Google and Cloudflare, who return a risk assessment we use to decide whether to ask you for an additional verification step. We do not use this information for advertising or profiling. Google's handling of that data is governed by the Google Privacy Policy and Terms of Service, and Cloudflare's by the Cloudflare Privacy Policy.

12. Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will take steps to delete such information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

14. Aggregated and De-Identified Data

We may create aggregated, de-identified, or anonymized data derived from your use of the Services, including from the inputs to and outputs from inference requests and from usage data, so that it no longer identifies you or any individual. We may remove information that makes data personally identifiable, and we own the resulting aggregated or de-identified data. We may use, license, and disclose this data to third parties for any lawful business purpose, including to provide data products. We maintain this data in de-identified form and will not attempt to re-identify it or disclose it in a manner that could identify you.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Address: OpenRelay Inc., 548 Market St, San Francisco, CA 94104