RelayFox

Privacy Policy

A plain-language explanation of the data RelayFox needs to operate.

Last updated: July 13, 2026

Data we process

RelayFox stores webhook requests sent to URLs you create, including the request method, path, query parameters, provider-supplied headers, body, content type, size, and source IP. Platform credentials and internal infrastructure headers are filtered and are not intentionally stored.

If you create an account, RelayFox stores your account identifier, email address, plan, endpoint settings, team membership, and hashed API key records. RelayFox never stores the plaintext value of an API key after it is shown to you.

To prevent automated abuse, RelayFox may keep short-lived rate-limit counters keyed by a one-way HMAC of a network address. The raw address is not stored in those counters.

Why we use data

Data is used to receive and display webhooks, stream them to the RelayFox CLI, replay requests when instructed, manage accounts and subscriptions, prevent abuse, provide support, and understand aggregate product usage.

Retention and deletion

Anonymous endpoints expire after 24 hours. Account-owned endpoint URLs are permanent while the account is active. Captured request history is retained for up to 24 hours on Free and 30 days on Pro. Aggregate product events are retained for up to 180 days. Deleting an endpoint removes its captured request history. Operational backups may take additional time to expire.

Service providers

RelayFox relies on Vercel for hosting and analytics, Supabase for PostgreSQL, Clerk for authentication, Polar for subscription checkout and tax handling, and Resend for transactional email. These providers process only the data required to provide their services under their own terms.

Analytics and cookies

Vercel Web Analytics provides privacy-focused aggregate traffic and product-event measurement. With your permission, RelayFox also loads the Google Ads tag to attribute endpoint creation, first webhook capture, and purchases. Campaign parameters may be stored in local browser storage. RelayFox does not intentionally put webhook payloads, endpoint IDs, email addresses, or API keys into analytics events. Authentication and checkout providers may use cookies required for their services.

Your choices

You can delete endpoints from their settings. To request account deletion, data access, correction, or another privacy action, email support@relayfox.dev.

Sensitive data

Webhook URLs are secrets. Do not send passwords, payment card data, private keys, medical data, or other regulated data to RelayFox unless you have independently confirmed that your use is lawful and appropriate.