Privacy
Last updated: 30 August 2026 · Applies to the Relay website, mobile app, and desktop controller.
The short version
Relay is local-first. Your source code, prompts, terminal input, files, and credentials stay on your own machine. We do not have servers that store them, and we cannot read them.
What the product handles — and where it stays
- Code, files, Git data, terminal output, agent conversations: processed only on your computer and your paired phone, end-to-end encrypted in transit. Never stored by Bytical.
- Relay tunnel: when your phone is away from your network, encrypted frames pass through our relay server. The relay sees only ciphertext and short-lived signed access tickets — it cannot decrypt content and stores none of it.
- Provider accounts (e.g. GitHub Copilot): remain configured on your own machine. Relay never receives or transmits those credentials.
First-party analytics (no third parties)
We run our own small analytics service. It is cookieless and stores no raw IP addresses. For website visits and app launches we record: page path, referrer, country (derived server-side), coarse device class, and a visitor hash that is salted and rotated daily so visits cannot be linked across days. Aggregate numbers are published openly at relay.bytical.ai/stats.
We use no Google Analytics, no advertising pixels, no fingerprinting, and no cross-site tracking of any kind.
What we never collect
- Source code, file contents, or file paths from your machine
- Prompts, agent conversations, or terminal input
- Tokens, keys, or credentials
- Precise location, contacts, or advertising identifiers
Data on your devices
Pairing credentials are stored in your phone's secure storage and your computer's local configuration. You can revoke any paired device at any time from the controller dashboard; revocation takes effect immediately.
Open source
Everything described here is verifiable in the public source code.
Contact
Questions: open an issue on GitHub, or reach Bytical at bytical.ai.