Relayium

Privacy Policy

Last updated: 2026-08-13

Relayium is built so that your files and ephemeral text stay yours. Local browser sessions are direct; cross-network browser sessions may carry end-to-end encrypted ciphertext through TURN; CLI text is direct-only; and stored download links hold only zero-knowledge encrypted file ciphertext.

This page explains the little data the service does handle, and the data it deliberately never sees.

Local-network content is not stored

When you transfer files or exchange text between devices on the same network, no account is needed and Relayium does not store the content. The signaling service temporarily handles connection metadata such as IP addresses, room membership, device names, presence, capabilities, and WebRTC negotiation so the devices can connect directly.

What an account stores (only if you sign in)

Same-network (LAN) sessions need no account. To create a cross-network pairing code for a browser or CLI session, the code creator must sign in; the person joining with that code does not need an account. Creating a stored download link also requires signing in. If you sign in, we store the minimum needed to run an account:

Stored transfer (download links)

When you use the optional stored download-link mode, your browser encrypts your files with AES-256-GCM before they leave your device. The decryption key exists only in the URL fragment — it is never sent to the server. This means:

Content we cannot read

Relayium servers never receive the following in plaintext and cannot decrypt them:

Cross-network relay (TURN)

Cross-network browser file and text sessions use a TURN server by design. TURN carries only end-to-end encrypted ciphertext and transport metadata. We attribute relayed-byte totals and timestamps to the code creator's account for quotas and abuse prevention, without inspecting message or file plaintext. CLI text is direct-only and does not use or count against TURN. Live text requires both participants to be online; Relayium provides no offline delivery or server-side message history, though either endpoint may copy or retain what it receives.

Usage metering and quotas

Paid plans mean the service has to count how much of it each account uses. While you are signed in, we keep a running per-account record of the bytes you upload and download through Relayium, the size of the ciphertext your stored links are holding, and the relayed-byte totals attributed to pairing codes you created. These counters outlive the transfer that produced them — we keep them as monthly per-account totals — because they are what enforces the usage, storage and relay quotas included in your plan, and what our billing and account records rest on. A paid subscription is a fixed price for a plan, not a per-byte charge.

Cookies and local storage

We use one session cookie to keep you signed in. In your browser's local storage we keep a random device id so a device you registered can be recognized. We do not use advertising or tracking cookies.

Third-party services

A few third parties are involved only when you choose to use them:

Payments

You only share payment data if you buy a paid plan. We never receive or store your full card number.

The Relayium app

Our native apps handle a little device-level data that the website does not:

Data retention and deletion

Account data is kept while your account exists. You can delete your account and its data at any time from your account settings, in the app or on the web. Deletion starts a 30-day grace period during which you can undo it by signing back in; after that, your account and personal data are permanently removed. Aggregate usage counters we must keep for billing and abuse-prevention are anonymized so they are no longer linked to you.

Your rights

You can access, correct, export, or delete your account data, and object to or restrict certain processing. Most of this you can do yourself in your account settings; for anything else, email support@relayium.com. We do not sell your personal data. Where the GDPR or similar laws apply, our basis for the little data we process is performing the service you asked for and our legitimate interest in keeping it secure and preventing abuse.

Children

Relayium is not directed to children. We do not knowingly collect personal data from anyone under 13, or under the minimum age of digital consent where you live. If you believe a child has given us data, contact support@relayium.com and we will delete it.

Changes to this policy

We may update this policy as the service evolves. When we do, we will change the "Last updated" date above.

Contact

Questions about privacy? Email support@relayium.com.