Privacy and data handling
What is shared and who receives it
Code runs through Xcode on your Mac. The source you select, source bundles, native tool results, previews and screenshots pass through the Cloudflare-hosted relayard service and are delivered to the third-party AI or MCP client you authorize. These materials may contain personal data. The client handles received data under its own policies. Review the selected permissions and this disclosure before choosing Allow selected access and data sharing. This is not end-to-end encryption.
Cloud storage and expiry
The cloud stores your email, device and endpoint aliases, access grants, credential hashes and operation metadata. Native text results have up to five minutes of access in the device Durable Object relay after verified receipt. With the selected permissions, native images and source bundles have up to 24 hours of logical access in private Cloudflare R2 storage; authorization expiry or revocation may end access earlier. General operation receipt metadata and retry identities expire after 24 hours. Account-level business-project associations and minimal work-tracking records (project and device identifiers, opaque operation identifiers, selection generations and status) remain until account deletion. These records enforce the account project limit and preserve unresolved-work safeguards; they do not retain source bodies, images or native result text. Active or unknown work is not automatically treated as completed when a receipt expires.
Image URLs are signed read capabilities valid for at most 15 minutes: anyone holding an unexpired link may read that image while its account, device, endpoint and original authorization remain valid. Do not share them publicly. Logical expiry blocks access; scheduled cleanup and any configured bucket lifecycle remove physical bytes asynchronously. Expiry is not instantaneous physical deletion, and it does not erase copies already received by an authorized client or establish the retention of provider backups.
Purchases and subscriptions
Apple processes App Store payments. relayard does not receive your payment-card details. To verify and restore Pro access, the service receives Apple-signed purchase information, including the product, transaction and original transaction identifiers, purchase and expiry dates, revocation status and store environment. An app account token links that purchase history to your relayard account. The service stores subscription records in Cloudflare D1 and checks Apple server notifications to update access after renewals, expiry or refunds.
Successful account deletion removes the account-linked subscription and project records. To prevent reuse of retired purchases, keyed purchase and account-token markers remain until 180 days after the later of deletion or the last verified subscription expiry. These markers do not contain your email, raw account token or signed purchase payload. Notification identifiers and digests used to prevent duplicate processing expire after 180 days. Scheduled cleanup removes expired records. Deleting the account does not cancel your Apple subscription; manage or cancel renewal in Apple subscription settings.
Storage on your Mac
Completed operation results and images in the Mac app are pruned after seven days or when the retained history exceeds 300 entries. Pruning runs when the app launches and when operation history is written, rather than continuously while the app is closed. You can clear completed results earlier in the app. Active operation records are preserved. Credentials are held in Keychain.
Local source change-set stages expire after 24 hours, but expiry alone does not delete their bytes. Use the explicit local prune action to remove eligible expired stages. Recovery journals and their associated backups are preserved for local review and are not erased automatically by stage expiry or account deletion; retain them until you explicitly review and remove them locally.
Diagnostics and service providers
No advertising or analytics SDK is included. The service does emit operational authentication and diagnostic logs, including request correlation identifiers, coarse events and error codes. Their retention follows the operator's configured Cloudflare logging policy and applicable provider policies; no fixed log-retention period or storage region is promised here. These logs are designed to exclude credentials, email codes, source bodies and image payloads.
Email codes are delivered by Cloudflare Email Service via the native Worker email binding. The code expires after ten minutes and can be used once.
Use projects and data you are authorized to share. Review source and screenshots for personal data or secrets before granting access.
Delete your account or revoke access
Delete your account from the Mac app or account page after signing in again. Deletion blocks new remote access and revokes devices before account records are removed. An interrupted deletion can be retried from the same signed-in browser or Mac app. OAuth protocol storage expires under its configured retention; revoked grants cannot execute through the relay. Local project files, recovery records and copies already received by a client are not deleted by account deletion.
Contact: support@txyou.com