Privacy Policy

Last updated: August 30, 2026

1. Introduction

Prelay is built around data minimization. This Privacy Policy explains what personal data is collected when you use Prelay Cloud and the Prelay Cloud dashboard, why it is collected, and how it is handled. It reflects the product's core promise: the service never receives the contents of your notifications.

This policy covers Prelay Cloud and the dashboard. The self-hosted software is open source and is operated by you; for those deployments, you are the data controller and Prelay is not involved in processing your data.

2. Who we are

"Prelay" is the operator of Prelay Cloud. For any privacy questions, or to exercise your rights, contact us at [email protected].

3. What we collect

We collect only the minimum data needed to operate the service:

  • Account data. Your email address, a display name, and a hashed password. We never store passwords in plaintext.
  • Device data. Per device: a name you provide, the device's public encryption key and its fingerprint, an FCM registration token, status, and a "last seen" timestamp.
  • API tokens. The first characters (prefix) and a hash of each API token, plus its scopes and creation/revocation state. Full tokens are shown once and never stored.
  • Usage counts. Aggregated monthly counts of notifications and devices, used to enforce plan quotas and show usage in the dashboard.
  • Billing data. Your Stripe customer identifier and subscription state, processed by Stripe. We do not store your payment card details; those are held by Stripe under their own privacy policy.

4. What we never collect

By design, we do not and cannot collect the following:

  • Notification contents. Prelay Cloud is zero-knowledge: notifications are encrypted before they reach us and decrypted only on your device. We never receive, store, or are able to read message contents.
  • Message history. There is no history, log, or archive of your notifications.
  • Behavioral analytics. We do not run advertising, profiling, or behavioral analytics, and we do not use advertising identifiers or track you across websites.
  • Location or contacts. The service does not collect location data, contacts, or phone numbers.

5. Why we process your data (legal bases)

  • To provide the service. Processing is necessary for the performance of our contract with you (account, device routing, token management, quotas).
  • Security and abuse prevention. Our legitimate interest in keeping the service safe — rate limits, spam and fraud detection.
  • Legal obligations. Where we are required to retain records, for example invoices for tax purposes.

6. Who we share data with

We do not sell personal data. We share the minimum necessary data with sub-processors needed to operate the service:

  • Stripe — payment processing and subscription management. Stripe receives your billing and payment details and is an independent processor under its own policy.
  • Google (Firebase Cloud Messaging) — push delivery to your Android devices. FCM receives only encrypted notification payloads and routing metadata; it never receives plaintext contents.

We may also disclose data where required by law, or in response to a valid legal request, and only to the extent permitted.

7. Data retention

  • Account and device data. Retained while your account is active and deleted (or anonymized) when you close your account, subject to legally required retention.
  • Delivery records. Ephemeral routing metadata that expires automatically (on the order of hours to a day). No notification content is ever stored.
  • Token hashes. Retained for revocation checks; removed when the token is revoked or the account is deleted.
  • Billing records. Retained as required by tax and accounting law.

8. International data transfers

Our sub-processors (Stripe, Google) may process data in countries outside your own, including outside the European Economic Area. Where personal data is transferred from the EEA or UK, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, or the processor's certification under a recognized mechanism.

9. Your rights

Depending on where you live, you may have rights under GDPR or similar laws, including the right to:

  • access and obtain a copy of your personal data;
  • correct inaccurate data;
  • request deletion ("the right to be forgotten");
  • restrict or object to processing;
  • data portability;
  • withdraw consent where consent is the basis of processing.

To exercise any of these rights, email [email protected]. We will respond within the period required by law. Note that because notification contents are never stored, there is nothing for us to return or delete on that front — deletion applies to the account, device, token, and billing data described above.

You also have the right to lodge a complaint with your local data protection authority.

10. Security

We apply strong encryption (X25519 + ChaCha20-Poly1305), hash all credentials and tokens at rest, and minimize the data we hold. These measures are implemented in the open-source codebase, so they can be inspected by anyone.

11. Children

The Service is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.

12. Cookies and local storage

The dashboard keeps your session in browser storage so you stay signed in. We do not use advertising cookies or third-party analytics cookies.

13. Self-hosted deployments

This policy does not apply to self-hosted deployments of the Prelay software, which you operate and control. When you self-host, you are responsible for how you handle the data in your own deployment.

14. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where practicable, notify you through the Service.

15. Contact

For privacy questions or to exercise your rights: [email protected].