Privacy
Privacy Notice
FiniteRelay is built to minimize what the service can learn. This notice explains the personal data that still has to be processed.
Effective August 15, 20261. Controller and contact
T4 Radius AS, Borgenveien 120, 1388 Borgen, Norway, is the controller for the processing described here. Organization number: 935394708.Contact auth@finiterelay.com for privacy questions or requests.
2. Data we process
| Category | Examples | Why |
|---|---|---|
| Account data | Email, user ID, authentication provider, display name, plan | Sign-in, account management, and support |
| Billing data | Stripe customer and subscription IDs, status, plan, billing period, usage and credits | Checkout, entitlements, invoices, refunds, fraud prevention, and accounting |
| Relay metadata | Pseudonymous locator, type, creation and expiry time, size, consumed status | Deliver one-time Relays, enforce expiry, show account history, and meter usage |
| Encrypted payloads | Client-side encrypted message or file bytes | Store and deliver the Relay you request |
| Security data | Pseudonymous rate-limit buckets, request time, status, technical logs, and limited webhook event records | Prevent abuse, diagnose failures, and protect the service |
| Guide measurement and advertising | Consent choice, page events, approximate location, browser or device details, and advertising identifiers where permitted | Understand Guide use, fund editorial content, measure ads, and respect privacy choices |
| Communications | Email address and the content of support requests | Respond and resolve account, billing, or legal questions |
Stripe processes payment-card and payment-method details on its hosted checkout. FiniteRelay does not receive or store full card numbers.
3. What client-side encryption changes
Message and file encryption happens in your browser using AES-256-GCM before upload. For a standard Relay link, the decryption key is in the URL fragment and is not included in the request sent to our servers. Passphrases are processed locally and are not sent to FiniteRelay. We therefore store ciphertext rather than readable Relay content, but encryption does not make account, billing, traffic, or operational metadata anonymous.
4. Legal bases
- Contract: operating accounts, Relays, subscriptions, capacity packs, and support you request.
- Legitimate interests: securing the service, preventing misuse, maintaining reliability, and understanding aggregate operations with minimal data.
- Legal obligations: tax, accounting, payment, fraud, and lawful authority requests.
- Consent: optional Guide analytics, advertising storage, advertising user data, and personalization where consent is required.
5. Retention and deletion
- Active Relay payloads are kept until the chosen expiry or successful retrieval, whichever happens first.
- Text payload rows are atomically removed on retrieval. Encrypted file payload records are removed from active availability on retrieval; encrypted storage objects are queued for deletion after a bounded download and retry window.
- Incomplete file-upload reservations expire quickly and are queued for storage cleanup.
- Account and entitlement records remain while the account is active and are then deleted or restricted when no longer needed, subject to legal obligations and backup cycles.
- Billing and transaction records are retained for the periods required by accounting, tax, dispute, and fraud-prevention law.
- Operational and security logs follow documented provider retention settings and are kept only as long as reasonably necessary.
You can request account deletion by emailing us. Deletion cannot restore or affect a Relay payload that has already expired or been consumed.
6. Service providers and disclosures
We use a limited set of providers to operate FiniteRelay:
- Supabase: authentication, PostgreSQL database, and private encrypted-object storage.
- Vercel: application hosting, routing, security controls, and operational logs.
- Stripe: checkout, payment processing, subscriptions, invoices, tax tooling, and the billing portal.
- Google: a certified consent platform and, only on Guide pages when enabled, Analytics measurement and AdSense advertising.
We may also disclose limited information when legally required, to protect rights and safety, or in a business reorganization subject to appropriate safeguards. We do not sell Relay content or decryption material. Advertising providers may treat some disclosures as targeted-ad sharing under certain regional laws, so applicable consent and opt-out controls are provided on Guide pages.
7. International transfers
Our providers may process data in countries outside Norway or the EEA. Where required, transfers rely on an applicable adequacy decision, contractual safeguards, or another lawful transfer mechanism used by the relevant provider. Contact us if you need more information about a transfer.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to withdraw consent without affecting earlier lawful processing. You may complain to the Norwegian Data Protection Authority or your local supervisory authority. We may need to verify your identity before acting on a request.
9. Children
FiniteRelay is not directed to children and is not intended for anyone who cannot enter the agreement required by our Terms. Do not use the service to send personal data about children unless you have a lawful basis and appropriate authority.
10. Security and updates
We use access controls, private storage, authenticated deletion workflows, rate limits, and client-side authenticated encryption. No system is risk-free. We will update this notice when processing materially changes and communicate significant changes where required.