Privacy Policy

Last updated: March 8, 2026

Relic is a zero-knowledge secrets management platform operated by Cupola Labs, LLC. Our architecture is built so that your secrets are encrypted on your device before they ever reach our servers. We cannot access, read, or decrypt your secret values. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

Information We Collect

Account Information

When you create an account using Google or GitHub OAuth, we receive your email address, name, and basic profile information as provided by the OAuth provider. We do not create or store passwords.

Encrypted Data

Secret values are encrypted on your device using AES-256-GCM with keys derived via Argon2id before transmission. We store only the encrypted ciphertext and cannot decrypt your secret values. We also store project metadata such as project names, environment names, folder names, and secret key identifiers. Encryption keys are derived from your master password and are never transmitted to our servers.

Usage Analytics

We use PostHog to collect anonymized product analytics including feature usage patterns, page views, and error events. Analytics data does not include your secret values or encryption keys.

Billing Information

Payment processing is handled by Stripe through our billing provider Autumn. We do not store credit card details on our servers. We retain subscription status and billing history for account management purposes.

How We Use Your Information

  • Provide, maintain, and improve the Service
  • Authenticate your identity and manage your account
  • Process payments and manage subscriptions
  • Store and transmit your encrypted data as necessary to operate the Service
  • Analyze anonymized usage patterns to improve the product
  • Communicate with you about your account or changes to the Service
  • Enforce our Terms of Service and protect against misuse

Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:

  • Contract performance — Account information, encrypted data storage, and service operation are necessary to provide you with the Service
  • Consent — Analytics cookies (PostHog) are only set for EU/EEA users after explicit consent via our cookie banner
  • Legitimate interest — Security audit logs and fraud prevention, service improvement based on anonymized CLI/TUI telemetry (which can be opted out of via relic telemetry disable)
  • Legal obligation — Retaining billing records as required by applicable tax and financial regulations

Third-Party Services

Relic relies on the following third-party services, each receiving only the minimum data necessary for its function:

  • Convex — Backend infrastructure and encrypted data storage (United States)
  • Google OAuth — Account authentication
  • GitHub OAuth — Account authentication
  • PostHog — Anonymized product analytics
  • Autumn / Stripe — Payment processing and subscription management
  • Resend — Transactional email delivery
  • Cloudflare — CDN, DNS, and web application hosting (Global)

We do not sell, rent, or share your personal information with third parties for advertising or marketing purposes.

Data Storage and Security

  • All data is stored on Convex infrastructure located in the United States
  • Secret values are encrypted client-side before transmission using AES-256-GCM
  • Encryption keys are derived using Argon2id and never leave your device
  • All network communication is encrypted in transit via TLS
  • We maintain audit logs of actions performed on your projects for security purposes
  • OAuth authentication is handled through industry-standard protocols

Your Rights

You have the right to:

  • Access your data through the CLI, TUI, or web dashboard
  • Export your secrets in multiple formats
  • Delete your account and all associated data from your dashboard (Account > Danger zone > Delete account)
  • Revoke OAuth connections through your Google or GitHub account settings at any time
  • Request information about what data we hold about you by contacting us at support@withrelic.com

Additional Rights for EU/EEA Residents (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following additional rights under the General Data Protection Regulation (GDPR):

  • Right to rectification — Request correction of inaccurate personal data
  • Right to erasure — Request deletion of your personal data (available via the dashboard or by contacting us)
  • Right to data portability — Receive your data in a structured, machine-readable format (available via the CLI export feature)
  • Right to restrict processing — Request that we limit the processing of your personal data
  • Right to object — Object to processing of your personal data based on legitimate interest
  • Right to withdraw consent — Withdraw consent for analytics cookies at any time by clearing your browser storage or rejecting cookies when prompted
  • Right to lodge a complaint — File a complaint with your local data protection authority

To exercise any of these rights, contact us at support@withrelic.com. We will respond within 30 days.

International Data Transfers

Your data is stored on Convex infrastructure located in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards as required by applicable data protection laws to ensure your data is protected during transfer. Our third-party processors (Convex, PostHog, Stripe, Autumn, Resend, and Cloudflare) each maintain their own data processing agreements and transfer mechanisms in compliance with GDPR requirements.

Data Retention

  • Your account data is retained while your account is active
  • Upon account deletion, your personal data (email, name, profile), encrypted secrets, projects, API keys, and collaborator shares are permanently deleted
  • Audit logs are anonymized upon account deletion (your user ID is replaced with an anonymous identifier) and may be retained for a reasonable period for security and compliance purposes
  • A minimal anonymous record of account deletion is retained for legal purposes (deletion date, plan status, deletion counts — no personal information)
  • Billing records held by Stripe are subject to Stripe's own retention policies and applicable tax regulations

Cookies

We use the following types of cookies:

  • Essential cookies — Authentication, session management, and geo-detection for consent compliance. These are strictly necessary and do not require consent.
  • Analytics cookies — PostHog product analytics. For EU/EEA users, these are only set after explicit consent via our cookie banner. For users outside the EU/EEA, these are set by default.

We do not use advertising, marketing, or cross-site tracking cookies.

California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your personal information:

  • Right to know — You may request details about the categories and specific pieces of personal information we have collected about you
  • Right to delete — You may request deletion of your personal information (available via the dashboard or by contacting us)
  • Right to opt-out of sale — We do not sell your personal information to third parties. We never have and never will.
  • Right to non-discrimination — We will not discriminate against you for exercising any of your CCPA rights

To exercise your rights, delete your account from the dashboard or contact us at support@withrelic.com. We will respond within 45 days as required by the CCPA.

Children's Privacy

Relic is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected information from someone under 18, we will take steps to delete that information promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the “Last updated” date at the top of this page. For significant changes, we may provide additional notice through email or the Service.

Contact

For privacy-related questions or concerns, please contact us at support@withrelic.com.

See also our Terms of Service and Data Processing Agreement.