Legal

Privacy Policy

This Privacy Policy describes how Strategic Products LLC, d/b/a RelayPDF (“RelayPDF,” “we,” “us”) handles personal data when you visit relaypdf.com, create an account, call api.relaypdf.com, or otherwise use the Service. It should be read with the Terms of Service and the Data Processing Addendum. If you do not agree, do not use the Service.

Last updated: August 26, 2026

1. Who we are

RelayPDF is a document API operated by Strategic Products LLC, a Florida limited liability company. We convert HTML, Markdown, URLs, Office files, and related inputs into PDFs and other files for engineering teams and software agents.

1583 Hansen Street, Sarasota, FL 34231, United States

Privacy and general inquiries: support@relaypdf.com

Security reports: security@relaypdf.com

1.1 Controller and processor

For account, billing, website, and support data, RelayPDF is the controller. For personal data inside the documents and payloads you submit so we can generate files for you, you are the controller (or a processor for your own customers) and RelayPDF is the processor. That processor relationship is described in the DPA.

1.2 Laws we consider

Depending on where you or your end users are located, this includes the EU/UK GDPR, the UK Data Protection Act, the California Consumer Privacy Act as amended by the CPRA, other U.S. state privacy laws, and Florida law applicable to a Florida company.

2. Information we collect

We collect only what we need to run, bill, secure, and support the Service.

2.1 Account and identity

When you register we collect first name, last name, email address, and authentication identifiers from Clerk (including a Clerk user id). If you sign in with a social provider, Clerk may also pass the name and email that provider supplies.

2.2 Billing

We keep wallet balances, top-up and auto-reload settings, Stripe customer and (where used) subscription or payment-method references, invoices metadata, and a millicent ledger of credits and debits. Card numbers are handled by Stripe, not stored by us.

2.3 Customer content (processor data)

To fulfill a request we process whatever you send: HTML, Markdown, URLs and fetched page content, Office or PDF uploads, Handlebars templates and template data, barcodes inputs, zip members, conversion files, optional AI prompts, webhook URLs, and the generated outputs. We do not use this content to train public AI models.

2.4 Operational and security data

We store hashed API keys, key names and prefixes, last-used times, request metadata (timestamp, endpoint, source type, status, latency, error codes, approximate byte sizes), IP addresses as needed for abuse prevention, rate-limit counters, device-login codes for the CLI, and webhook delivery attempts. We do not log full HTML or file contents.

2.5 Support communications

Emails to support@relaypdf.com and security@relaypdf.com are received so we can respond. Transactional mail (wallet top-up, auto-reload, payment required) is sent from noreply@relaypdf.com.

2.6 Website

The marketing site and dashboard set cookies required for authentication and security (Clerk session cookies). We use Google Analytics 4 to measure visits, page views, and similar usage on relaypdf.com. We use the Google Ads tag and the X Ads (Twitter) Universal Website Tag, plus the X Conversion API, to measure whether a visit or sign-up followed an ad. Those platforms may set cookies or use click IDs, IP address, user agent, requested URL, and a hashed email after sign-up. Server logs on Vercel and Cloudflare may include IP address, user agent, and requested URL.

2.7 Children

The Service is for adults. We do not knowingly collect data from children. If you believe we have, contact support and we will delete it.

3. How we use information

We use personal data to:

We do not sell personal information. We do not use customer document content for advertising.

  • Create and authenticate accounts, issue and revoke API keys, and operate the dashboard, CLI login, and MCP flows
  • Generate, convert, merge, protect, and deliver files you request, including 24-hour downloads and async callbacks
  • Store templates you save, and run optional AI template generation when you ask for it
  • Debit the wallet only for successful jobs, process Stripe top-ups and auto-reload, and send related transactional email
  • Enforce rate limits, prevent abuse (including blocking private-network URL fetches), debug outages, and secure the Service
  • Respond to support and security reports
  • Meet accounting, tax, and legal obligations, and enforce the Terms
  • Understand how the marketing site and dashboard are used (page views and similar analytics via Google Analytics)
  • Measure advertising performance (Google Ads and X Ads conversion tags; hashed email and click IDs only for that measurement)

5. Sharing

We share data with subprocessors only to operate the Service, and with others only as described here.

5.1 Service providers

Current providers include Vercel (website and dashboard), Cloudflare (API, Chromium PDF and screenshots, LibreOffice/wkhtml containers, R2 file storage), Supabase (Postgres), Clerk (authentication), Stripe (payments), Resend (outbound email), inbound support email, Google (Google Analytics and Google Ads conversion measurement on the website), X Corp. (X Ads pixel and Conversion API on the website), and, when you use AI template generation, Vercel AI Gateway and xAI. The DPA lists subprocessors for customer content.

5.2 Legal and safety

We may disclose information to comply with law, enforce the Terms, or protect RelayPDF, customers, or the public from harm or fraud.

5.3 Business transfers

If we sell or reorganize the business, personal data may transfer to the successor under comparable protections.

6. International transfers

RelayPDF is established in the United States. Personal data is processed in the United States and on global infrastructure (including Cloudflare’s network). If you are in the EEA, UK, or Switzerland, this is a transfer to a third country. We rely on the EU Standard Contractual Clauses (and UK addenda where required) with subprocessors, adequacy decisions where they exist, and contractual and technical safeguards. You are responsible for transfers you cause by submitting EU/UK personal data into the Service.

7. Retention

We keep data only as long as needed for the purposes above.

When retention ends we delete or irreversibly anonymize the data, except copies that are not reasonably accessible in encrypted backups until those backups rotate.

  • Generated files requested as a download URL or async job: automatically deleted after 24 hours
  • Binary responses: not retained as a durable file after the response is sent
  • Saved templates and account profile: until you delete them or we close the account, then a short residual period in backups
  • API metadata logs (no HTML/file bodies): retained for billing disputes, abuse investigation, and reliability, typically up to 24 months unless a longer period is required
  • Wallet ledger and invoices: retained as required for tax and accounting (often seven years in the United States)
  • Support email: retained as needed to resolve the thread and for a reasonable archive period

8. Security

Controls include TLS in transit, hashed API keys, least-privilege access to production systems, schema validation, rate limits, rejection of private-network URL fetches, 24-hour object expiry, and provider-managed encryption at rest where the infrastructure supports it. No internet service is perfectly secure. You must protect keys and dashboard access.

Report vulnerabilities or suspected incidents to security@relaypdf.com.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal data, to restrict or object to certain processing, to withdraw consent, and to appeal a denial. California residents also have rights to know, delete, and correct personal information, and to opt out of “sale” or “sharing” as those terms are defined in California law. We do not sell personal information. We use Google Ads and X Ads tags to measure whether an ad led to a visit or sign-up; that can include sharing a click ID, IP address, user agent, and hashed email with those platforms for conversion measurement.

To exercise rights, email support@relaypdf.com from the address on the account. We will verify the request. We may decline requests that are unlawful, excessive, or that would expose another person’s data or our security measures.

EEA/UK users may lodge a complaint with their local supervisory authority. California users may contact the California Attorney General. These rights do not reduce any non-waivable consumer rights under Florida law.

10. Cookies

We use strictly necessary cookies and similar storage for login, CSRF/session integrity, and load balancing. Clerk sets authentication cookies. Stripe sets cookies on Checkout when you pay. Google Analytics, Google Ads, and X Ads may set cookies or use similar storage (including an X click-id cookie) to measure site usage and ad conversions. You can block cookies in your browser; the dashboard will not function without the authentication cookies. Blocking analytics or ads cookies does not affect API generation.

11. Third-party sites

Documentation and the marketing site may link to GitHub, npm, Stripe, Clerk, or other sites. Their privacy practices are their own.

12. Changes

We will post updates on this page and change the “Last updated” date. Material changes may also be noted by email or in the dashboard. Continued use after an update means you accept the revised policy.

13. Contact

Strategic Products LLC, d/b/a RelayPDF

1583 Hansen Street, Sarasota, FL 34231, United States

Email: support@relaypdf.com

Security: security@relaypdf.com