RELAY handles exceptionally sensitive personal data — your accounts, documents, and final instructions. We treat that responsibility seriously. This policy explains exactly what we collect, how we store it, and who can ever access it.

1. Who We Are

RELAY is a digital legacy vault service operated in the United States. Our application is accessible at evereaseos.polsia.app. We enable users to securely store account credentials, important documents, trusted contact information, and personal instructions — and to designate trusted contacts who may be notified if the user becomes unresponsive.

Contact us at: evereaseos@polsia.app

2. What We Collect

Account information: Your email address, name (optional), and a hashed version of your password. We never store passwords in plaintext.

Vault contents: The credentials, documents, and personal instructions you choose to store. These are stored in our database and are only accessible to you while logged in.

Trusted contacts: Names, email addresses, and relationship descriptions you provide for up to 3 trusted contacts.

Check-in activity: Timestamps of when you have checked in, your configured check-in interval, and the date your next check-in is due.

Subscription information: Your subscription status, plan type, and Stripe subscription identifiers. We do not store full payment card numbers — payment processing is handled by Stripe.

Usage data: Server logs may capture IP addresses, browser type, and request timestamps for security and debugging purposes. These are not used for advertising.

3. How We Use Your Data

We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Vault Data — Sensitive Content

Your vault contains sensitive personal data including account passwords, legal documents (wills, deeds, insurance), identity documents, and final instructions. We store this data in an encrypted PostgreSQL database hosted by Neon (neon.tech). Access to vault contents requires a valid authenticated session.

Your vault contents are never shared with anyone except:

5. Trusted Contact Notifications

If you miss a scheduled check-in and the 48-hour grace period passes without you responding, RELAY automatically sends an email to your trusted contacts notifying them that you have not checked in. This notification does not include your vault contents. It notifies them of the missed check-in date and encourages them to reach out to you directly.

6. Third-Party Services

Stripe: We use Stripe to process subscription payments. When you subscribe, your payment information is processed directly by Stripe under their privacy policy (stripe.com/privacy). We receive only subscription status and identifiers — never your card details.

Neon PostgreSQL: Our database is hosted on Neon's infrastructure in the United States. Your data is encrypted at rest and in transit.

Render: Our application server is hosted by Render (render.com). Application logs are stored by Render for debugging purposes.

Email delivery: Notification emails to trusted contacts are sent through our email provider. Recipient email addresses are used solely for delivering these notifications.

7. Data Retention

We retain your account data and vault contents for as long as your account is active. If you delete your account, all vault data (accounts, documents, contacts, check-in history) is permanently deleted within 30 days. We may retain anonymized aggregate metrics indefinitely.

8. Your Rights

You have the right to:

California residents have additional rights under the CCPA, including the right to know what personal information is collected and the right to opt out of the sale of personal information (we do not sell personal information).

EEA and UK residents have rights under GDPR, including the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at evereaseos@polsia.app.

9. Security

We implement reasonable technical and organizational measures to protect your data, including:

No security measure is perfect. In the event of a data breach that is likely to result in risk to your rights, we will notify affected users within 72 hours of discovery, consistent with applicable law.

10. Children

RELAY is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately.

11. Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via email. The "Last updated" date above reflects when the current version was published. Continued use of RELAY after changes constitutes acceptance of the updated policy.