Legal · privacy

Privacy policy.

Effective 2026-04-19. Operator: Cumulus (hi@cumulush.com).

Who we are

Relay is operated by Cumulus (hi@cumulush.com, 5757 Woodway Drive, Houston TX 77057, US). Relay provides an HTTP API and MCP server that AI agents use to sign their users up to third-party products on behalf of their end-users. We are a data processor for integrator tenants and a data controller for our own account records.

What we collect

  • Account data. Email address, optional name, WebAuthn public credentials, IP address + user agent for active sessions, agent token hashes (SHA-256; we never store plaintext).
  • Integration metadata. Tenant slug, domain, webhook URL, HMAC signing secret (stored encrypted at rest via AES-256-GCM), product catalog entries, billing subscription state.
  • Signup ledger. For each signup an agent dispatches: provider slug, input fields, resulting account id + API key (encrypted), and the audit event. Third-party API keys pass through Relay exactly once and are not persisted.
  • Agent inbox.Inbound emails addressed to a user's Relay alias are stored in full (headers + plain-text body) so the agent can read and extract verification codes. Retained 90 days.
  • Billing data. Stripe customer id, subscription state, per-action quota counters, per-action overage invoice items. We do NOT store card numbers — Stripe holds those directly.

How we use it

  • Deliver the service: authenticate requests, dispatch signups, route inbound email.
  • Bill integrators for billable actions and per-action overage.
  • Detect abuse: per-user monthly action counter, audit log.
  • Contact account owners for operational and billing notices.
  • Investigate security incidents.

We do not sell personal data. We do not use it to train AI models.

Subprocessors

Data may be processed by the following subprocessors, each under a data processing agreement:
  • Neon — managed Postgres hosting (data at rest).
  • Vercel — application hosting + edge network (compute, logs).
  • Resend — outbound transactional email (verification codes, receipts).
  • SendGrid — inbound email parsing (the agent inbox).
  • Stripe — subscription and overage billing; stores card numbers.
  • Sentry — error and performance monitoring.
A full current list lives at /trust.

Retention

  • Account records — while the account is open. Deleted within 30 days of closure.
  • Audit log — 12 months from event timestamp.
  • Inbound emails — 90 days.
  • Session records — until expiration or revocation.
  • Billing records — 7 years for tax and accounting compliance.

Your rights

Subject to applicable law (GDPR, CCPA, and similar), you can request access, correction, deletion, export, or restriction of processing of your personal data. Email privacy@cumulush.com from the address associated with your account. We aim to respond within 30 days.

International transfers

Data is stored in the United States. For EU/UK transfers we rely on Standard Contractual Clauses with each subprocessor.

Changes

Material changes to this policy will be announced via email to account owners at least 14 days before they take effect. Non-material changes (clarifications, subprocessor additions under similar protections) take effect on publication.

Contact

privacy@cumulush.com for privacy requests · security@cumulush.com for security issues · hi@cumulush.com for general inquiries.