Privacy

Written to be read. Where a sentence here is uncomfortable, that is because the thing it describes is, and hiding it in longer words would not change it.


What we send to other companies

The words you write in an alert condition, and the subject and body of a broadcast, are sent to Voyage AI to be turned into the numbers this product matches on. There is no way to run this product without doing that, so it is said here first rather than in a list of subprocessors at the bottom.

The same words are also sent to Google, through its Gemini API, before matching. An alert condition's title and description, and a broadcast's subject and body, are each distilled down to their substance — so a pasted job description matches on the role it describes rather than on the company's boilerplate. A broadcast's subject and body additionally get a first-pass check for content that should not be sent at all. None of this has to run for the product to work the way Voyage above does — skipping it still matches, just on the raw text instead of a distilled version of it — but it is the same words reaching a company, so it belongs in this list rather than a separate one that implies otherwise.

That matters more here than it would elsewhere, because of what people write: death notices, medical fundraisers, welfare appeals. Our account with Voyage is set to opt out of retaining what we send. We have not set up an equivalent opt-out with Google — the free tier of the Gemini API we currently use does not offer one. We cannot audit either company's promise, and neither can you — which is the honest position rather than a reassuring one.

The complete list of who receives what you write is five companies. Nobody else does. (Signing in with Google is a separate flow, covered below under what we collect — it confirms who you are and never sends your alert conditions or messages anywhere; the Gemini calls above are the only way Google sees what you write.)

  • Voyage AI — your alert condition and broadcast text, to generate the embeddings matching runs on.
  • Google — your alert condition and broadcast text, to distill it before matching, and a broadcast's text to screen it before it can be sent.
  • Resend — an email address and a message, to deliver it.
  • Paystack — an amount and a reference, to take a payment. Your card number reaches them and never reaches us.
  • Fly.io — everything, because they run the servers and the database the rest of this sits on.

We do not sell anything about you to anybody, and there is no advertising or analytics product in this list because there is none in the product.

What the anonymity actually is

A broadcaster never sees your email address, and you never see theirs. Replies travel through a masked address that belongs to one delivery and nothing else.

This is a trusted proxy, not encryption. Your address is hidden because this product chooses not to reveal it, not because it is mathematically out of reach. It is stored, it is readable by the people who run the database, and a court order or a breach would expose it. Anyone telling you an arrangement like this is "anonymous" without that sentence is selling you something.

One thing we cannot strip: a signature you type yourself. We remove quoted history from a reply, because a mail client wrote that. "Best, Wanjiru, 0712 345 678" is your own sentence and indistinguishable from the message.

What we collect, and what we do not

  • An email address, from signing up with "Log in with Google".
  • Your name, if you sign up with Google — it sends us the name on the Google account along with the address, and we store it the same way we would if you had typed it in yourself.
  • What you write — alert condition descriptions, anchor words, broadcast subjects and bodies. This is the substance the product matches on, so it is necessarily read and processed.
  • Payment references and amounts, never card numbers.
  • Verification documents, only if you choose to send one.

There is no phone number on this list, because email is the only channel this product sends on. If that ever changes, this paragraph changes before it ships, not after it.

Signing up with Google asks Google for your email address, that it is verified, and your name — nothing else. We never see your Google password, your contacts, your files, or anything else in the account. Google's own privacy policy governs what happens on their side of that exchange.

Why we are allowed to hold it

Where the law asks for a reason to process your data — the GDPR in the EU, the UK GDPR in Britain, Kenya's Data Protection Act, and their equivalents elsewhere — these are ours:

  • To run the service you asked for. Matching your alert conditions, sending what matches, taking a broadcaster's payment, showing a broadcaster their own results. Without this there is no product.
  • Our legitimate interest in keeping it working and honest: stopping fraud and abuse, enforcing the tier and rate limits, securing the servers, and keeping the staff audit log.
  • Your consent, for the parts that are yours to switch on — publishing an alert condition to Explore, and, where your words carry health, bereavement or relationship detail, processing that category of information at all. Withdrawing it is the same switch, turned back off.
  • A legal obligation, for the few records a tax authority or a court can require us to keep.

Some of what you write is, in the law's terms, special-category data — health above all, through medical fundraisers. We process it because you chose to write it into an alert condition or a broadcast for the one purpose this product serves, and for nothing else. An alert condition you publish to Explore, you have made public yourself.

How long we keep things

  • Message content — the body of a broadcast and every reply in its threads — is removed 90 days after that conversation's last activity. Not its creation: a thread still moving keeps its words.
  • Verification documents — an ID, a death notice, a business registration — are deleted 30 days after a reviewer finishes with them. They are never emailed to anybody at any point.
  • Public attachments are not deleted on a timer. They were sent to real inboxes, and removing our copy would not unsend them.
  • Runs, charges and delivery records are kept for as long as the account is open. Deleting them would make a charge from last year impossible to explain to the person who paid it. Closing the account removes them along with everything else — see the Terms.
  • The staff audit log is exempt from all of the above and is never edited or deleted. A trail that erases itself on a timer is not one.

Explore, and why three categories can never be in it

An alert condition is private by default. Turning on Explore publishes an anonymised preview of it — the description, its category, its country — to anybody at all, signed in or not. Never your name, your address, or anything that resolves to your account.

dating, bereavement and medical fundraiser can never be published this way, whatever the setting says, because for those the description is itself the exposure. A carefully anonymised bereavement notice still names the person it is about.

A reported public alert condition leaves Explore immediately, not after a review. The review happens afterwards and can put it back.

What you can do without asking us

  • Deactivate any alert condition from a link in any email, with no login.
  • Stop near-miss summaries per alert condition or entirely, the same way.
  • Block a broadcaster, a category, or everything, without deleting anything.
  • Take an alert condition out of Explore at any time. Most were never in it — it is off by default.
  • Read, correct or delete what is on your account, from your account.

Age

This is not for anybody under 18. We store the fact that you confirmed it and the date you did, not your birthday — a birthday is more about you than the question needs.

Where it is processed, and under whose law

Relayvant is available worldwide. It is operated by Relayvant Ltd, at the address in the footer, and that company decides how and why your data is used — the data controller, in the law's words.

The servers, and the four companies above, are not all in one country, and none of them has to be in yours. Your data is processed wherever they run — for most of them, outside your country, and today mostly the United States. When it leaves a region whose law restricts the transfer, that transfer needs a safeguard the law recognises: standard contractual clauses, an adequacy decision, or a certification scheme. Putting those in place with each provider is part of opening beyond Kenya, and is still in progress.

The law that applies to your data is at least the law where you are — the GDPR in the EU, the UK GDPR in Britain, Kenya's Data Protection Act (2019), the state privacy laws in the US. The practices set out on this page apply wherever you are, not only where we are.

Your rights, and how to use them

Wherever you are, you can:

  • See what we hold about you, and get a copy of it.
  • Correct anything wrong, or delete it — closing the account does this in full, and the Terms spell out exactly what goes.
  • Object to or restrict some processing, and withdraw a consent you gave, without it unpicking what happened while it was in force.
  • Take your data elsewhere in a portable form.
  • Not be sold. We do not sell or share personal data, for advertising or anything else, so there is nothing to opt out of — but the right to say so exists, and this is us saying it.

Most of this you can do yourself, from the account, without asking. For the rest, reply to any email from us. If we get it wrong, you can complain to a data protection authority — your own country's, or Kenya's Office of the Data Protection Commissioner.

Cookies

The site sets a cookie to keep you signed in for the session and to carry the anti-forgery token that protects a form submission. If you tick "remember me" when you sign in, a second cookie keeps you signed in on later visits until it expires or you sign out. That is all of them: neither tracks you, neither is shared, and there is no advertising or analytics cookie because there is neither in the product. Your theme choice is kept in the browser, not in a cookie, and never leaves it.

One thing we are still working out

Tax law in some countries requires keeping a record of a payment — an amount, a date — for years after it is made. This product is built to delete billing history when an account closes (the Terms). Where those two rules meet, the law wins, and we will say so on the Terms page before it changes anything for you.