Relay Terms and Conditions
1. Who we are and how to contact us
Relay is operated by Relay Social Ltd, a company incorporated in England and Wales. Registered office: Pine End Warren Lane, Oxshott, Leatherhead, England, KT22 0ST. Company number: 16715098. Email: team@relay-social.com. Website: www.relay-social.com.
2. Our contract with you
By creating an account or using Relay, you agree to these Terms. If you do not agree, do not use the service. We may update these Terms from time to time. When we do, we will post the revised Terms with a new "Last updated" date and, where changes are material, provide reasonable advance notice through the app or by email. Continued use after changes take effect constitutes acceptance.
3. Eligibility
You must be at least 16 years old to use Relay. Sign-up asks for your date of birth and will not create an account for anyone under 16.
It is a self-declared age gate: it stops a truthful under-16 from signing up, but it does not verify anyone's age, and someone who enters a false date of birth will get through. We do not currently use age-estimation or identity-verification technology. If we learn that an account belongs to someone under 16, we will delete their data and may close the account.
Relay's features, including location, work the same way for all users aged 16 and over.
Your birthday. The date of birth you give at sign-up is held on our servers and is not shown to anyone. The day and month of it appear to your friends — on your profile, in their calendar, and as a card in their Chats tab on the day — and your account displays a birthday treatment for the day. Nobody is notified about your birthday but you: the one push we send goes to you, on the morning itself. The year is never displayed.
4. Your account and security
You are responsible for safeguarding your login credentials and for all activity under your account. You must keep account information accurate and current. We may suspend or terminate accounts where we reasonably believe these Terms have been breached or account integrity is at risk.
5. Acceptable use
We protect free speech but ban illegal activity and clear abuse. Content that is lawful but offensive may stay up. Use Block and Report Abuse to manage your feed and flag problems.
You must not:
- post illegal content in the UK (e.g. CSAM, terrorism, unlawful incitement, criminal hate) or direct, credible threats;
- harass, dox, or impersonate others;
- solicit crimes, exploit minors, or share non-consensual intimate images or synthetic/"deepfake" sexual images of real people;
- hack, disrupt, scrape, or reverse-engineer the service (unless the law allows it);
- infringe others' rights.
In addition, because Relay includes location, event and joint-posting features, you must not:
- use location features to follow, track, monitor, ambush, intimidate or stalk another person, or to work out where someone lives, works or studies against their wishes;
- share, screenshot, republish or record another person's location outside the app, or build any log or record of another person's movements;
- create a second account, or ask another user to act on your behalf, in order to see the location of, contact, or appear in content with someone who has blocked you or removed you as a friend;
- pressure, coerce or repeatedly ask another person to turn on location visibility for you;
- add someone to a moment, event or chat in order to harass them, to attach their name to content they would not want their name on, or to put their face in front of an audience they did not choose;
- use comments to harass, pile on to or follow someone around the app — comments on moments and Thoughts are open to any Relay user, and being able to reach a stranger's post is not a reason to;
- create fake events, or use events, invitations, waves or hang-out notifications to spam people;
- collect, scrape or systematically record friend positions, event locations, attendance lists or venue data from the map.
We may refuse or reclaim usernames, including for impersonation or trade mark reasons. Zero tolerance for child sexual exploitation. See the CSAM Safety Policy.
Blocking. If you block someone, or they block you, then for as long as the block is in place: neither of you can see the other's location on the map, and neither can wave at the other; neither can invite the other to events or add the other to a moment; and neither can start a chat with the other. This applies immediately and in both directions, whichever of you did the blocking, and regardless of your map settings — a block overrides scope. Blocking does not automatically delete content you have already created together — use Report Abuse or remove yourself from the moment (section 10).
6. Meeting people in person
Relay is designed to help you arrange to see people offline. That means some of what happens as a result of using Relay happens in the real world, where we have no involvement and no control.
- We do not vet users, venues or events. We do not run background checks, verify identity beyond the self-declared date of birth described in section 3, or inspect any location, venue or event.
- Meet-ups are your decision and your responsibility. You are responsible for deciding who to meet, where to meet them, and whether to go.
- Venue and mid-point suggestions are informational only. Suggested venues are drawn from open mapping data (OpenStreetMap), which is contributed by volunteers. We do not endorse, recommend, inspect or guarantee any venue, and details such as opening hours, accessibility and whether a place still exists may be wrong or out of date. Check before you travel.
- Location data can be wrong, delayed or unavailable. Do not rely on Relay for anything safety-critical, time-critical or navigational. A friend shown as nearby may not be nearby. Someone shown as available may not be.
Basic precautions we ask you to take. Meet new people in public places. Tell someone you trust where you are going and when you expect to be back. Arrange your own transport. Do not feel obliged to attend an event because you RSVP'd, and do not pressure others to attend.
If you feel unsafe, leave and, if you are in immediate danger, call 999. You can report a user in-app at any time.
Subject to section 16 (Liability), we are not responsible for the conduct of other users, whether online or offline, or for anything that happens at a meet-up, event or venue arranged through Relay.
7. Friends, tiers and visibility
Friend requests need approval. Sending a friend request does not create a connection. The other person has to accept it, and until they do, nothing that depends on a friendship is shared — though the paragraph after next explains what is open to any account regardless.
Invite links. You can also connect by invitation. The app mints a personal link (relay-social.com/i/…) each time you open the invite sheet, to share as a link or a QR code. Someone who redeems it becomes your friend straight away, at the pal tier in both directions, with no request to accept — so only share a link with people you want connected to you. Each link works for up to ten people and expires 90 days after it was made. When someone redeems your link you are told who, by name; they are shown your name and photo before they confirm. On a new account the app looks for an invite on its own — in a link you tapped before installing and, on Android, in the referrer the Play Store passes along — and the manual "Got an invite?" sheet reads your clipboard once, when you open it, to spot a Relay link or code; anything else on the clipboard is ignored and nothing is stored. The Privacy Policy, section 1, covers what we keep.
People search is open, and so are posts. Users can be found in people search by people who are not already their friends, and being findable carries real consequences. Someone who finds you without being your friend can see your moments, your Thoughts and the comments on them — see section 10, which explains this in full and which you should read before you post. They can also open your profile and see your friends — who you are connected to, and how many. That list is open to any signed-in account. What they cannot see without an accepted friendship is your location, your events or your chats. Making your tiering private (below) hides which tier each person is in, not who they are.
Tiers. You can place friends into tiers (super friend, friend, pal). By default a tier is a visible label rather than a private note: the friend can see which tier you have placed them in, and friends can view the arrangement of your friends as you can view theirs. You can make your tiering private on the Customize page, which hides the tier labels, colours and ordering from other users — not the list of who your friends are, which stays open as described above. You can also turn tiering off entirely. Both choices are put to you explicitly when you set up your account, and you can change them at any time.
Reflections. If you use tiers and you have left them visible, a third control appears: you can change the tier label a particular person is shown, for each class of viewer. For any one relationship you can set what people who are not your friends see, what your pals see, and what your friends see. Leave a reflection unset and everyone in that class sees the real tier. Super friends are the exception — they always see the true value, and no reflection can change that.
A reflection changes what that viewer is shown and nothing else. They see the reflected label, and in the tethered home view they see your friend on the ring for that reflected tier, because that view is drawn from the tier the viewer is shown. It does not change the real tier, and it does not affect the map: map visibility is worked out from the real tier you placed someone in, never from the reflection you show them. If you have hidden your location from someone, showing them a friendlier label does not let them see you; if you have scoped the map to super friends, showing someone a super friend label does not put them inside that scope.
Tiers can also do practical work: you can switch map visibility off for whole tiers (section 8). Where you do, moving someone between tiers changes what they can see about you.
Removing a friend. You can remove a friend at any time. Removing a friend ends location visibility in both directions and removes them from your arrangement. It does not delete past moments, chats or events you shared.
8. Location features
Relay includes several distinct location features. They are separate, and they are controlled separately.
The map is opt-in in full. Until you turn it on, nobody can see you and Relay stores no position for you. There is no setting that turns you on by default. Separately, while the Map tab is open, your phone sends your current position to our servers roughly every 30 seconds so we can work out which friends are near you — even when you are not visible to anyone. That position is used for the answer and discarded; it is not stored and nobody sees it. What turning visibility on adds is that your position is kept, so that friends can see it.
Precise location, with your permission. The map uses precise GPS location from your device. We ask for that permission separately, we only use it while a location feature is on, and you can revoke it at device level at any time.
Friends only, never strangers. Your location is never visible to anyone who is not your friend. There is no public map, and no way for someone you have not added to see where you are.
Seeing is not being seen. Looking at the map does not put you on it. You can open the map, see which friends are nearby and message them while broadcasting nothing yourself. Being visible is a separate choice, and turning it off does not cost you the ability to see other people.
You choose the scope. By default the map applies to all of your friends. If you use tiers, each tier — pal, friend, super friend — has its own switch, and turning a tier's switch off hides you from everyone in it. "Super friends only" is pals off and friends off. The switches only ever narrow: there is no way to make yourself visible to someone who is not your friend.
You can hide from specific people. Separately from the scope you have chosen, you can hide your location from named individuals. Hiding wins: if someone falls inside your chosen scope but you have hidden from them, they cannot see you.
Hiding and blocking are different. Hiding affects location only, applies to one person, leaves everything else about the friendship untouched, and they are not told. Blocking is broader — it ends location visibility in both directions, stops waves, and cuts off chats, invitations and co-posting (section 5). If you only want to stop someone seeing where you are, hide. If you want them out of your experience, block.
If you turn tiering off. Tier-based scoping is no longer available. The map falls back to all of your friends, minus anyone you have hidden from. Turning tiering off therefore widens who can see you unless you were already on the widest scope — check your settings if you do it.
How you can tell you are visible. The Map tab carries a pill that always states your status — "You're visible", "Visible while open" (foreground-only permission), "You're hidden", or why you are not being shown at all. It is on the Map tab, not on every screen. The Map tab and its visibility settings tell you the truth at any time; the other tabs do not. A live location share in a chat is different — that one is announced by your phone (below).
Your device signals it as well, though the strength of that signal varies. Live sharing in a chat raises the prominent system indicator — the blue pill on iOS, the location icon on Android. Background map visibility uses low-power geofence and significant-location-change updates rather than continuous GPS, which is better for your battery and collects less about your movements; iOS marks that with a subtler status-bar indicator, and both platforms let you review recent location access app by app.
What no system indicator tells you is who can see you. The Map's visibility settings do, at any time, by name — and because visibility stays on until you turn it off (below), treat yourself as visible to your chosen scope from the moment you switch it on until the moment you switch it off.
What each feature does:
| Feature | What it shares | Who sees it | How to stop it |
|---|---|---|---|
| Map visibility | Your live or last-known position, to friends within 5km | Friends inside the scope you chose, minus anyone you have hidden from | Switch tiers off, hide from individuals, or turn visibility off on the Map tab |
| Live location (in chat) | Your position, updating continuously | Only the chat you sent it to | Stop it at any time; otherwise it ends when the duration you chose (15 minutes, 1 hour or 8 hours) runs out |
| Current location (in chat) | A single static pin of where you were when you sent it | Only the chat you sent it to | Cannot be recalled once sent, but you can delete the message |
| Send your location | A one-off share you choose to make | Whoever you send it to | As above |
| Waving | That you are nearby, via push notification | The friend you wave at | Only someone who can currently see you on their map can wave at you, so hide from them, turn visibility off, or block — there is no separate switch for waves |
| Proximity alerts | Nothing of yours. You are told that a friend who is already visible to you is nearby, and roughly how far away | You only | Turn the alerts off; they are off until you turn them on |
| Free to hang out | That you are free, to nearby friends you have chosen to be visible to. It requires map visibility to be on | Friends inside your chosen scope who are nearby | Turn map visibility off; the window goes with it |
| Picked place or meeting spot | The coordinates of the place you picked — not where you are | The chat you sent it to | Delete the message |
| Saved places | Nothing, until you send one. Your saved places are private to you | You only, unless you send one into a chat or attach it to an event | Delete the saved place |
| Event locations | The location attached to an event | People invited to that event | Remove or change the location on the event |
Live location runs for a set time. When you share live location in a chat you choose how long it lasts — 15 minutes, 1 hour or 8 hours — and you can stop it at any moment before then. It keeps updating while the app is in the background without any extra permission; while a share is running your phone shows its own live-location indicator, and on Android a persistent notification. The share ends when the time runs out, when you stop it, or if the app is closed completely.
Saved places. You can pin places you use often. That library is yours: it is stored against your account so it follows you between devices, and nobody else can read it — not your friends, not your super friends, not people you share a chat with. It exists independently of the map, so pinning a place does not make you visible and does not require location visibility to be on. The one way a saved place reaches anyone else is if you send it — choosing one as a meeting spot in a chat puts that place's coordinates in the message, like any other place you pick.
Proximity alerts and hang-out windows. Proximity alerts are off until you turn them on. When they are on, you are told that a friend who is already visible to you is nearby and roughly how far away, and tapping the alert opens the map on their pin — which you could already see, since the alert only fires for friends who are visible to you. They are not told that you were told. A hang-out window is the other direction — it tells nearby friends you are free — and it needs your map visibility to be on, because it works off the same presence the map does.
Visibility stays on until you turn it off. Closing the app, signing out, losing signal or a flat battery does not switch your visibility off; only you do, from the Map tab. What changes when the app is not in the foreground is how often your position updates. With background location permission it keeps updating, on a low-power basis, wherever you are. Without it, your position stops updating when you leave the app, but the last position we had for you stays visible to friends until it is a day old — shown as stale after two hours, and deleted after 24. If you want to be invisible, turn it off.
You can withdraw at any time. You can switch tiers off, hide from specific people, or turn visibility off entirely from the Map tab. You can also revoke Relay's location permission at your device level, which stops all location features.
Users aged 16 and 17. The same location rules apply as for everyone else. The map is opt-in, scope and hiding work identically, and there are no additional restrictions.
Accuracy. Location shown in Relay is approximate and may be delayed or out of date. See section 6.
9. Events, polls and invitations
Creating events. Events can be created directly, from a chat, or from an event poll. Once a poll has votes, the person who posted it (in an event's own chat, the event's creator) gets a "Draft event" button that opens the event form with the most-voted day, time and place already filled in; they check it and create the event. Nothing is created without someone pressing that button.
Polls. Anyone in a chat can vote in a poll placed in that chat. A poll is either single-choice or multi-select; that is the only setting. There is no anonymous poll: who voted for which option is visible to everyone in the chat, for chat polls and event polls alike. If you would rather the chat did not know your answer, don't vote.
RSVPs. You can respond going, undecided or not going. Not responding is not the same as declining, and organisers may follow up.
Plus-ones. Where an organiser enables plus-ones, invitees may bring additional people, within limits. A plus-one must be an existing Relay user and must already be a friend of the person bringing them. You must have accepted your own invitation before you can add anyone. A plus-one cannot in turn bring a plus-one. You cannot add someone who is not on Relay, and you are never asked to enter another person's details.
Reminders. Reminders are set per person: the reminder you choose applies to you, and changing it does not change anybody else's. The one exception is the organiser's. The reminder the organiser sets is also the event's default, so it applies to any invitee who has not chosen their own.
Event chats. Each event has its own chat, opened the first time someone sends a message in it. Its members are the people invited, minus anyone who has said they are not going. After the event has passed, that chat is archived. Archiving does not delete it; history remains available to participants unless it is deleted.
Turning an event chat into a group. The person who created the event — and only that person — can convert its chat into an ordinary group chat. Two effects are worth knowing: the chat will no longer archive after the event, and if it had already archived, converting it brings it back. The event stays attached to the new group, listed among that group's events. It becomes a permanent group like any other, and stays until someone deletes it. Nobody else in the chat can do this, and nobody can undo it.
Cancellation and turning up. We do not record who attended, enforce attendance, hold bookings, take payment for events, or act as an agent for organisers. An event on Relay is a plan between users, not a contract with us.
10. Moments and joint content
Moments require at least two people. You cannot post a moment alone. A moment appears on the account of every person credited on it, and displays their names and the date it was posted. A moment is a photograph; video belongs in chats, not in moments.
Takes. Each person credited on a moment may write their own take on it — the poster's and every tagged person's, shown in turn as equal voices rather than a caption with replies underneath. Writing one is optional: a moment can be posted with no takes at all, or with takes from only some of the people credited. You are responsible for your own take, not for anyone else's.
Consent. By posting a moment, you confirm you have the right to share the photograph, including the agreement of anyone identifiable in it. Do not post images of someone who has asked you not to.
Who can see a moment. Read this before you post. Moments are readable by any Relay account. Not only your friends, and not only the friends of the people you posted with — anyone signed in to Relay. The app is built around your friends and that is what you will see day to day, but the underlying content is not walled off from other users. Treat a moment as visible to the whole of Relay, because it is. The photograph itself is served from a web address that does not require a Relay sign-in, so anyone who has that address can open the image — it is not guessable, but it is not behind a login either.
The same is true of Thoughts, and of the comments on both. Your location, your events and your chats are not in this category — those are limited as described elsewhere in these Terms. It is posts that are open.
Likes and comments. Moments and Thoughts can be liked and commented on. Because posts are readable by any Relay account, a comment can come from someone you do not know. You can delete your own comments at any time. Nobody else can delete them for you — not the person who created the moment, not the other people credited on it. Deleting a comment that has replies removes those replies with it. If a comment breaks the rules, block the person or report it to us under section 12; that is the route, rather than the poster policing their own moment.
Who is on a moment. The "shared with" list on a moment shows the people credited on it — the same people whose faces appear on the card. It is not a list of who has seen it. Relay does not keep an audience list for a post, and cannot show you one.
Removing yourself. A tagged person on a moment with three or more people can remove themselves from it afterwards: your name and your take come off it, and the moment stays up for the others. On a two-person moment there is no removing yourself, because a moment cannot exist with one person on it — the only way off is to delete it, which either of you may do (below). And the person who created the moment can never remove themselves from it; they can only delete it.
Withdrawing a take without leaving. These are two different things. You can clear your take and stay on the moment — your words come off, your name and face stay on it. If you want off the moment altogether, remove yourself instead.
Deleting. Who can delete a whole moment depends on how many people are credited on it.
- Two people. Either of you can delete it outright, which removes it for both. You do not need the other's agreement, and you do not have to be the person who uploaded it.
- Three or more people. The person who created the moment can delete it for everyone. Everyone else credited on it can remove themselves, but cannot delete the moment for the others. The creator cannot remove themselves.
If you want a moment taken down entirely and you are not the person who can do that, remove yourself (where the moment has three or more people) and ask the creator to delete it. If that does not resolve it, contact us using the details in section 1 and we will deal with it — your right to have a photograph of you taken down does not depend on the app giving you a button for it (Privacy Policy, section 9).
Editing. The photograph in a moment cannot be changed after posting. Your own take can: you can add one later, update it, or clear it entirely, at any time. What you cannot change is anybody else's take, including one that is about you. If someone else's take on you is wrong, ask them to change it, remove yourself from the moment, or report it to us.
Thoughts. Thoughts are short text posts. Unlike a moment, a Thought is yours alone — you write it by yourself and nobody else is credited on it. Like a moment, it can be liked and commented on, and it is readable by any Relay account.
11. Daily poll and personality test
Daily poll. Relay asks one question a day. Questions are written by us, not by users, and we choose them.
- Answering is optional.
- After you answer, you can see how the world voted and how your friends voted.
- Vote to see. The app shows you your friends' answers only on days when you have voted yourself.
- Your own answer is visible to your friends, and it is not anonymous. The app shows it only to friends who have voted that day, but that is an app rule rather than a data rule: our access rules let any friend who has not blocked you read your answer for any day, so do not rely on vote-to-see for privacy. If you would rather nobody saw your answer, don't answer.
Personality test. Optional, and you can use Relay fully without ever taking it. If you take it, your results are stored on your profile record and shown to friends who have taken the test themselves, so the two of you can be compared. The app shows them only to friends, but the record itself is readable by any signed-in account, like the rest of your profile. There is no control that deletes your results, and deleting your account does not delete them either. Ask us using the details in section 1 and we will remove them, with or without closing your account.
12. Safety, moderation, and reporting
Use Block and Report Abuse to control what you see and to alert us. We review reports quickly, prioritising child safety and serious harms. Actions may include content removal, feature limits, suspension, or bans. We may act where we reasonably assess a risk of serious harm, even if content is not clearly illegal.
This applies to every format on Relay — photos, videos, voice messages, GIFs, text, takes, comments, group chat names and images, event details, poll options and location shares.
How moderation works. We review content when it is reported to us. We do not scan content in advance. This means reporting genuinely matters: if something breaks the rules and nobody reports it, we may not know.
Location-specific enforcement. We may restrict or remove access to location features specifically, without suspending an account, where we reasonably believe those features are being misused. We may also act on reports of offline conduct connected to Relay.
We don't routinely read user content. We may access specific items only to investigate reports, comply with the law, or protect security. We are not obliged to monitor all content and we do not undertake any general monitoring of user activity. Access is limited and logged.
Disagreeing with a decision. Appeals are handled by email rather than in the app. If you disagree with a decision — content removed that did not break the rules, or an account restricted that should not have been — email us at the address in section 1 and a person will review it again.
If you believe content infringes your rights, email the contact in section 1 with: (a) a link to the content; (b) a description of the work; (c) why you believe it infringes; and (d) your contact details. We may remove content and restrict or suspend repeat infringers.
13. Your content and licence to us
You own your photos, videos, voice messages, messages, takes and comments. You give us a worldwide, royalty-free licence to host, store, reproduce, adapt (for technical purposes such as resizing, transcoding and thumbnailing) and display them to run the service (including backups, delivery, and moderation). You also grant us the right to sub-license this licence to our service providers solely so they can help us run the service.
Joint content. For a moment made with other people, each person grants this licence for the part they contributed: their own upload, if they uploaded it, and their own take. Each person keeps control of their own contribution — you can update or withdraw your take at any time. Control of the moment as a whole is shared unevenly: see section 10 for who can delete it.
If you delete content, this licence continues only to: (a) honour re-shares until others delete them; (b) allow short-term caching/backups; (c) meet legal, safety, and dispute needs; and (d) keep non-revealing safety artefacts (e.g. hashes). We won't use deleted content for new features or marketing without your consent.
You must have rights to everything you upload.
14. Our intellectual property
Relay Social Ltd owns the service and all related intellectual property, including trademarks, logos, and design elements. We grant you a limited, revocable, non-transferable, non-sublicensable licence to use the app and website for personal, non-commercial purposes in accordance with these Terms. You must not copy, modify, distribute, sell, lease, reverse engineer, or attempt to extract the source code of the service except to the extent such restrictions are prohibited by law.
Map, venue and places data in Relay is derived from OpenStreetMap, © OpenStreetMap contributors, and is made available under the Open Database Licence. It remains the contributors' work, not ours. You may use it inside Relay for your own personal planning.
15. Service availability and changes
Relay is provided on an "as is" and "as available" basis. We may modify, suspend, or discontinue features or the service at any time (for example, for security, legal, or operational reasons). We will try to provide advance notice where practicable.
Location, map and notification features depend on your device, its settings, its battery, and mobile networks and third-party services outside our control. They may be delayed, inaccurate or unavailable.
16. Liability
Nothing here excludes liability we can't legally exclude (e.g. death/personal injury by negligence, fraud) or your consumer rights.
Otherwise, to the extent allowed by law, we're not liable for unforeseeable loss, business losses, loss of profits, data, goodwill, or other indirect/special losses. We'll use reasonable skill and care; if we don't, we're responsible for foreseeable loss caused by that failure.
Subject to the paragraph above, we are not responsible for: the acts or omissions of other users, online or offline; anything that happens at a meet-up, event or venue arranged through Relay; the accuracy, availability or timeliness of location, map or venue information; or a notification, reminder or location update that does not arrive, arrives late, or is wrong.
17. Termination
You may delete your account at any time in Settings. We may suspend or terminate your account immediately where we reasonably believe you have breached these Terms, created risk or possible legal exposure for us or others, or where required by law. Upon termination, your right to use the service ends, but sections that are intended to survive (including licences granted for the limited purposes above, safety reporting, and limitations of liability) will continue as necessary.
What deleting your account does. Deletion starts a 30-day cooling-off period. Your profile is cleared straight away — name, username, photo, description, date of birth, notification token, presence and invite links — and you can change your mind by signing back in at any point in those 30 days. After that your login is deleted and your friendships are dissolved. A stub of the account remains under its internal id, holding what deletion does not touch; the Privacy Policy, section 10, lists it.
Effect on joint content. Deleting your account does not remove you from moments. Your name on them becomes "Deleted User", but the moments stay, and so do your takes unless you clear them first — do that before you delete if you do not want your words left behind. Content uploaded by others that you appear in is not deleted either; use Report Abuse or contact us if you want it removed.
18. Complaints and disputes
Questions or complaints? See section 1 for contact details. Law of England and Wales applies. Courts of England and Wales have exclusive jurisdiction, subject to any mandatory consumer rights you have where you live.
19. Other important terms
If any provision is found invalid, the remainder remains in effect. We may assign our rights and obligations under these Terms in connection with a reorganisation, merger, or sale of assets; we will notify you if this happens. You may not transfer your rights without our written consent. These Terms constitute the entire agreement between you and us regarding the service. Third-party links may appear; we are not responsible for them. Your use of the app may be subject to Apple App Store/Google Play terms; if those conflict with these Terms, the store terms may apply to the extent required by the store. You must not use the service in violation of applicable export-control or sanctions laws.
Contact: see section 1.
Relay Privacy Policy
Relay Social Ltd controls your personal data under UK GDPR and the Data Protection Act 2018. We are registered with the ICO. This notice explains what we collect, how we use it, and your rights. We don't use data for advertising and we don't sell data.
Contact: see our Terms and Conditions, section 1. Our privacy leads are Scott Swanepoel and Rex Attwood. You can contact the ICO at ico.org.uk.
1. What we collect
Account data
- Email address, username, password (stored using industry-standard hashing).
- Date of birth. Collected at sign-up to apply our minimum age, and held on our servers. It is not displayed. Your friends see the day and month — on your profile, in their calendar and on the day in their Chats tab — and nobody is notified but you, with one push on the morning itself; the year stays with us.
Content and connections
- Photos you upload, and the takes written on them.
- Moments are joint content. A moment is a photograph created by two or more people. It carries the names of everyone credited on it and the date it was posted, and appears on all of their accounts. Takes are optional; anyone credited may write one, or none, and can clear their own at any time without coming off the moment.
- Who sees a moment. Any Relay account can. Posts are readable by anyone signed in to the service — not only your friends, and not only the friends of the people you posted with. What you see day to day is your friends, because that is how the app is arranged, but the content itself is not restricted to them. The photograph cannot be changed after posting, though each person can add, update or clear their own take at any time.
- Thoughts are short text posts written by one person. They are readable on the same terms as moments.
- Likes and comments on moments and Thoughts, including comments from people who are not your friends. You can delete your own comments; no one else can, and the poster has no power over comments on their own post. Deleting a comment deletes its replies.
- Messages you send in one-to-one, group and event chats: text, photos, videos, voice messages, GIFs, reactions, likes and polls. For group chats, the name, image and description given to the chat. While you are typing, a short-lived marker is written so the others can see it; it is removed when you send or stop, and it holds nothing but the fact that you were typing.
- Edited messages. Editing a message overwrites it. We do not keep the previous version, and the message is not marked as edited — so neither we nor anyone in the chat can recover or identify what was changed.
- Friend lists and interactions you initiate or accept. Friend requests require the other person's approval before any connection exists. Your list of friends is part of your profile record, which any signed-in account can read (see Discoverability, below).
- Invites. Each invite link you create is stored as a code with your account id, when it was made, when it expires (90 days) and the ids of the people who redeemed it, up to ten. If you joined through someone's invite, your profile record carries who invited you, when, and how the app found the code — link, Play Store referrer, clipboard or typed in; that stamp is written once and stays. The clipboard is read only when you open the "Got an invite?" sheet, and only a Relay link or code is kept from it, in memory, until you confirm; on Android the Play Store's install referrer is read once, at sign-up.
- Blocks. Who you have blocked and who has blocked you, held on your profile record — which any signed-in account can read — and in a separate permanent log of each block.
- Discoverability. Your name and username are findable in people search by users who are not your friends, and your profile shows your posts and your friends — who and how many — to whoever opens it. Your location, your events and your chats are not visible without an accepted friendship.
- Friend tiers. The tier you place each friend in (super friend, friend, pal). By default the friend can see the tier you have placed them in, and friends can view your arrangement of friends. You can make your tiering private on the Customize page, which hides the tier labels and ordering but not the list itself, or switch tiering off altogether. Tiers can also control map visibility, so moving someone between tiers may change what they can see about you.
- Reflections. Where tiers are on and visible, you can also store, per friend, a different tier label to be shown to people who are not your friends, to your pals and to your friends. We hold that setting. It changes what that viewer is shown — the label and, in the tethered home view, the ring your friend appears on — and nothing on our side: map visibility is always calculated from the real tier, and super friends are always shown the real value.
- Daily Poll responses: we display aggregated percentages for the world and for your friends. Your individual answer is visible to your friends. The app shows it only to friends who have voted that day, and shows you theirs only on days you have voted — but our access rules allow any friend who has not blocked you to read your answer for any day, so treat it as visible to friends, full stop. Answering is optional. Your own answers are kept and shown back to you as your poll history. They are not deleted with your account; they stay under the account's internal id (section 10).
Events and planning data
- Events you create or are invited to: title, description, date and time, location, colour, reminder settings and plus-one settings.
- Invitation lists, your RSVP (going, undecided, not going), and a per-person record of when you last opened the event.
- Votes you cast in chat polls and event polls, and the options that won. Polls are single-choice or multi-select, and never anonymous: who voted for each option is visible to everyone in the chat.
- Event chat content, which is archived rather than deleted once the event has passed. The person who created the event can convert its chat into an ordinary group chat, which stops it archiving — or brings it back if it had already archived — and attaches the event to that group.
- Reminder settings, which are held per person: yours applies to you and not to anyone else invited, except that the organiser's reminder is also the default for invitees who have not set their own.
- Plus-one records. Plus-ones must be existing Relay users, so you are never asked to give us details about someone who is not on Relay.
Location data
- Precise location from your device (GPS, Wi-Fi and network signals), stored only while your visibility is on or a location share is running. While the Map tab is open your position is also sent to our servers to find nearby friends, then discarded (section 3).
- Your last-known position, held briefly so the map can still show you when a live position is unavailable. It is deleted automatically 24 hours after it was last written, and anything older than 24 hours is ignored rather than shown. Relay keeps no trail of where you have been. Two location-derived records do exist and should be named: for nearby alerts, a note of when each friend was last near you, kept for seven days so the same friend is not announced twice; and when you send a picked place or meeting spot into a chat, your distance from that spot at the time is stored on the message.
- Locations you attach to an event or send in a chat, including a place you pick on the map rather than your own position.
- Saved places you pin for yourself, with whatever label and emoji you give them. These are stored against your account so they follow you between devices. They are private: our access rules permit only you to read them, and they are not shared with your friends or anyone else unless you send one into a chat or attach it to an event. Pinning a place does not require location visibility to be on and does not make you visible.
- Approximate location derived from IP address (city/region level), used for security and service delivery regardless of your location settings.
See section 3 for full detail.
Device and usage data
- Device model, operating system, app version, IP address, language, time zone.
- In-app events, crash logs, and performance metrics.
- Device identifiers required for essential security and service delivery (e.g. notification tokens).
- Reports you send us. If you report an issue or a bug, we store what you wrote, your account identifier and the time you sent it, and it is emailed to us. Nothing is attached automatically — no logs, no screenshots, no device or version details. If those would help us fix something, put them in the message.
Optional personality test
- If you choose to complete the optional personality test, we store your answers and results so you can view them alongside other users' results. Taking it is entirely optional. Results live on your profile record — readable, like the rest of the record, by any signed-in account, though the app shows them only to friends who have taken the test. They are not deleted with your account; ask us and we will remove them, at any time.
Device permissions we ask for
| Permission | Why | Required? |
|---|---|---|
| Camera | In-app camera for moments and chats | Optional, but you cannot post without it or photo access |
| Photo library | Selecting photos from the last 7 days for moments, and photos or videos for chats | Optional |
| Microphone | Voice messages | Optional |
| Location (while in use) | Map, waving, mid-points, live and one-off location shares in chat | Optional |
| Location (background) | Map visibility that keeps updating while the app is in the background | Optional. Without it your position stops updating when you leave the app; your visibility stays on and your last position stays visible for up to 24 hours (section 3) |
| Notifications | Messages, likes, comments, mentions, friend requests, event invites and reminders, waves, hang-out signals, nearby alerts, the daily poll and your birthday | Optional |
We do not collect your phone's contact list, your browsing history, your calendar outside Relay, or unrelated device metadata.
2. Why we use your data (and legal bases)
| What for | Legal basis |
|---|---|
| Run and secure the service — accounts, moments, feeds, chats, Daily Polls, friendships, events and the Event Planner | Contract / legitimate interests |
| Show your position to friends you have chosen, and show you theirs; waving; mid-point suggestions | Consent (see section 3) |
| Suggest venues at a mid-point between two people | Consent, plus legitimate interests in providing the feature |
| Keep users safe and meet legal duties, including child-safety and lawful requests | Legal obligation / legitimate interests; vital interests in emergencies |
| The optional personality test, if you choose to take it | Consent |
| Analytics and crash reports to improve performance | Consent outside the UK and US; in the UK and US, the statistical-research basis with an opt-out (see section 5). Necessary telemetry on legitimate interests |
| Service communications | Legitimate interests; consent where required |
| Marketing | Consent only, withdrawable at any time |
None of this is used for advertising or sold.
3. Location data — how it works
This is the most sensitive data Relay handles, so it gets its own section.
Visibility stays on until you turn it off. Closing the app, signing out, losing signal or a flat battery does not switch your visibility off; only you do, from the Map tab. With background location permission your position keeps updating while the app is in the background. Without it, your position stops updating when you leave the app, but the last position we had for you stays visible to friends until it is a day old — shown as stale after two hours and deleted after 24.
The map is off by default, and opt-in in full. We store no position for you until you turn visibility on. Turning it on is a positive choice, not a default you have to find and disable. The permission and the feature are both opt-in, and withdrawing either stops collection.
Precise location. The map uses precise GPS, Wi-Fi and network positioning — not approximate or city-level position. We store it only while your visibility is on or a share is running, and only for as long as that lasts. Separately, while the Map tab is open your phone sends your position to our servers roughly every 30 seconds to work out which friends are nearby, whether or not you are visible; that position is used to answer and discarded, not stored.
How you can tell it's active. The Map tab carries a pill that always states your status — "You're visible", "Visible while open", "You're hidden", or why you are not being shown. It is on the Map tab, not on every screen.
Your device signals it too. Live sharing in a chat raises the prominent system indicator — the blue pill on iOS, the location icon on Android. Background map visibility runs on low-power geofence and significant-location-change updates instead of continuous GPS, which uses less battery and collects less precise data about your movement; iOS marks it with a subtler status-bar indicator, and both platforms let you review recent location access per app.
No system indicator tells you who can see you. The Map's visibility settings do, at any time. Treat yourself as visible to your chosen scope from the moment you switch it on until the moment you switch it off.
Friends only. Location is never visible to non-friends. There is no public map.
Seeing is not being seen. Viewing the map does not require you to broadcast. You can see which friends are nearby while being visible to nobody, and turning your own visibility off does not take the map away from you.
Saved places are yours alone. Places you pin for yourself sync to your account and no one else can read them — the access rules permit only you. They are independent of the map: pinning your gym does not put you on the map, and does not require visibility to be on. The only route out is one you take deliberately, by sending a place into a chat or attaching it to an event, at which point that place's coordinates are in the message like any other place you pick.
Proximity alerts and hang-out windows. Proximity alerts are off unless you turn them on. When on, they tell you that a friend who is already visible to you is nearby and roughly how far away, and tapping the alert opens the map on their pin — which you could already see. The friend is not told you were alerted. A hang-out window works the other way — it tells nearby friends you are free — and requires your own map visibility to be on, since it runs on the same presence.
How you control who sees you. Two separate controls, which work together:
1. Scope. By default the map applies to all of your friends. If you use tiers, each tier has its own switch, and turning a tier off hides you from everyone in it — "super friends only" is pals off and friends off.
2. Hiding. Independently of scope, you can hide your location from named individuals. Hiding takes precedence: someone inside your chosen scope who you have hidden from cannot see you.
If you switch tiering off, tier-based scoping is no longer available and the map falls back to all of your friends, minus anyone you have hidden from. That can widen who sees you, so check the setting if you turn tiering off.
Worth understanding before you turn it on. Scope is a group setting, not a per-person one. Choosing "all friends" makes you visible to everyone in that group at once, minus anyone you hide from, and a new friend added later falls inside it automatically. If you would rather share with a small number of people, switch off every tier but the one they are in, or send a one-off location in a chat instead of using the map.
What is shared, and with whom:
| Feature | Data | Visible to |
|---|---|---|
| Map visibility | Live or last-known position | Friends inside your chosen scope, minus anyone you have hidden from, and only within a 5km radius |
| Live location in chat | Continuously updating position | Only members of that chat, for the sharing period |
| Current location in chat | One static position at the time you sent it | Only members of that chat |
| Waving | The fact that you are nearby | The friend you wave at |
| Proximity alerts | None of yours — you are told a visible friend is nearby, and roughly how far | You only |
| Free to hang out | That you are free, alongside the presence you are already sharing | Nearby friends inside your chosen scope |
| Picked place or meeting spot | The coordinates of the place chosen, not your own position | Members of that chat |
| Saved places | The places you pin, with your labels | You only, on every device you sign in on |
| Mid-point | Your position, used to compute a mid-point and query venues | The other person sees the mid-point and venue suggestions |
| Event location | The location on the event | People invited |
How long we keep it:
- Live position: retained only for as long as needed to display it, and no more than 24 hours afterwards.
- Last-known position: deleted automatically 24 hours after it was last written, or sooner if superseded by a newer position. Anything older than 24 hours is ignored and never shown to anyone. Deleted when you turn location off.
- Location attached to events or sent in chat: kept with that event or message until it is deleted.
- Nearby-alert ledger: when each friend was last near you, kept for seven days so the same friend is not announced twice.
- Server logs and diagnostics. We do not offer a location history as a feature — there is no movement trail in the app, and no way for you or anyone else to look up where you have been. Our own code does not write positions to logs, but the platforms we run on keep request logs as a by-product of serving the app, and a request can carry a position. That data is access-controlled, retained for 30 days, and used only for security, debugging and abuse investigation — never to build a profile of your movements.
Maps and venues are handled in-house. Addresses are the exception. Relay's servers do not send your coordinates to Google, Apple, Mapbox or any other commercial location provider. Here is what does leave your phone:
- Map tiles are served by our own worker, built on OpenStreetMap data via Protomaps. The map images you see come from our infrastructure, not a third party's. That worker runs on Cloudflare, so Cloudflare's network handles the requests for the map area you are looking at and the venue searches you make — under our contract with it, as a processor for us.
- Mid-point and venue suggestions are computed inside our own function. It takes both people's positions, works out the mid-point and finds venues near it, and returns only the mid-point and the venue list. The other person's raw coordinates never leave that function, and are never sent to you or to anyone else.
- Turning a position into an address is done by the geocoder built into your phone, which we call through the operating system rather than through a service of our own. On iOS that geocoder is Apple's and on Android it is Google's, and the platform may send the coordinate to them to return a street name. So a coordinate can reach Apple or Google — under your device's relationship with them and their privacy terms, not ours, and never routed through our servers.
- Searching for a place uses the same phone geocoder in the other direction. When you type an address or place name into map search or a location picker, the text you typed goes from your phone to Apple's or Google's geocoder, alongside a search of our own venue data. When you ask for directions to a place, its coordinates are handed to Apple Maps or Google Maps — that is the point of the button.
Keeping that list short is a deliberate design choice: the fewer parties that hold a coordinate, the fewer places it can leak from.
Withdrawing consent. Switch tiers off, hide from specific people, or turn visibility off entirely from the Map tab — or revoke Relay's location permission on your device. Turning the map off or revoking the permission stops collection.
Blocking. Blocking someone ends location visibility between you immediately and in both directions, and stops waves. It overrides your scope setting, so a blocked person cannot see you even if they would otherwise fall inside it. Hiding is the narrower option if you only want to stop someone seeing your location.
Risks we want you to be aware of. Sharing your position tells people where you are. Choose the narrowest scope that works for you, and review it from time to time — the Map's visibility settings show who can currently see you. Remember that a friend added later falls inside your existing scope automatically. If someone is pressuring you to share your location, you can hide from them or turn the map off without telling them, and you can block or report them.
4. Children and age limits
Relay is intended for users aged 16 and over. We do not knowingly collect data from children under 16. If we learn that we hold data about a younger child, we will delete it and may close the account.
Because 16- and 17-year-olds can use Relay, we have regard to the ICO's Children's Code, including age-appropriate information and data minimisation. Location, map and event features work the same way for users aged 16 and 17 as for everyone else: the map is opt-in, visibility stays on until it is turned off, and no additional restrictions apply.
The same is true of posts, and it cuts the other way. A moment or Thought posted by a 16-year-old is readable by any Relay account, and can be commented on by any Relay account, and their list of friends is open to any account in the same way. There is no younger-user setting that narrows this. Relay's design is built around friends, but a post is not limited to them.
5. What we do with your data
Analytics, for ourselves, and nothing else. Beyond what is essential to run and secure the service, we collect usage data for one purpose: understanding how Relay is used so we can improve it. We use it in-house.
We do not sell it. We do not license it. We do not share it with data brokers, advertisers or analytics partners for their own purposes. We do not use it for advertising or to profile you for advertising. There is no version of Relay in which any of that changes without us rewriting this notice and telling you first.
What "essential" means. Some processing happens whatever your settings: your account, your content, your friends, your messages, security and abuse-prevention data, crash-critical telemetry, and location if and only if you have turned it on. The app cannot work without these. We are not going to claim we hold nothing about you.
What "anonymised" means. We collect usage events tied to your account, then aggregate and strip them so they no longer identify you. Before that point the data is pseudonymised, not anonymous, and this notice applies to it. After it, it falls outside data protection law.
Turning analytics off, and how you were asked. This works differently depending on where you are, so we will set out both.
- Outside the UK and the United States, non-essential analytics are off until you agree. You are asked before anything is collected, and nothing is collected if you decline or ignore the ask.
- In the UK and the United States, they are on unless you turn them off, and you are given a notice rather than a request. In the UK we rely on the exception for statistical purposes introduced by the Data (Use and Access) Act 2025, which allows analytics of this kind — measuring how the app is used, in order to improve it — on the basis of clear information and an easy opt-out rather than prior consent.
Either way, the switch is in Settings → Account details, turning it off does not limit any feature, and a decision you have made explicitly is never overridden. Location matters more than language: a phone set to US English but physically in Europe is asked, not defaulted on.
If you would rather not think about which side of that line you fall on, open Settings → Account details and turn it off. That works everywhere.
6. Sharing your data
We do not sell personal data or share it for targeted or interest-based advertising. We also prohibit our service providers from using your data for their own advertising or marketing purposes.
We share limited data with service providers (processors) under written contracts requiring confidentiality, security, and processing only on our instructions. Categories include:
- Cloud hosting and storage.
- Content delivery, image processing and video and audio transcoding.
- Map tile delivery from our own worker, built on OpenStreetMap data via Protomaps. No commercial mapping provider receives coordinates from us. Address lookup is different: it is performed by your phone's built-in geocoder, so the coordinate may go from your device to Apple or Google under their terms rather than through our systems. See section 3.
- GIF search and delivery (KLIPY). When you search for a GIF, your search term goes to KLIPY through our servers, and your Relay account id goes with it — KLIPY uses it to keep your recent GIFs and to count what was sent. KLIPY does not see your device.
- Link previews. When a message contains a web link, our server fetches that page to build the preview card — so the site you linked sees a request from us — and your own phone fetches it as well while you are composing, so it sees a request from you too.
- Notification delivery (Google Firebase Cloud Messaging on both platforms, then Apple's push service on iOS). A message notification carries the sender's name and the message text, so that text passes through those services on its way to the phone.
- Email (Google, as our mail provider) for the messages we send you about verification, password resets and account deletion, and for the reports you send us.
- App integrity checks (Google Play Integrity on Android, Apple App Attest on iOS), which confirm to us that requests come from a genuine copy of Relay.
- Your phone's operating system, which we hand your recent chats' names and avatars to so that they appear in its share sheet and search (section 12).
- Security, fraud prevention, and moderation.
- Analytics, diagnostics, and crash reporting (Google Firebase/Google Cloud).
- Professional advisers and insurers.
We share your data with other users where you have chosen to: friends who can see you on the map, people in your chats, people invited to your events, people credited on a moment with you, and — unless you have made your tiering private — the people who see the tier you placed someone in, subject to any reflection you have set. Posts are the broadest of these: a moment or Thought you publish, and the comments on it, are readable by any Relay account rather than by a list of people you chose — as is your list of friends.
We may share data with law-enforcement or competent authorities where required or permitted by law, particularly regarding child-safety or serious harms. If we are involved in a reorganisation or sale, data may be transferred to the successor in accordance with this policy.
7. International transfers
Relay is built and operated from the UK, and we host in UK or European regions where our providers offer them. Some of the services we rely on are run by companies headquartered outside the UK, and support or engineering access from other countries can happen even where storage is in-region.
Where personal data is transferred outside the UK, we rely on UK-approved safeguards — the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses — and we assess the risks of those transfers. You can ask us for a copy of the relevant safeguards, with commercially sensitive details redacted. If you want to know where a specific category of your data is held, ask and we will tell you.
8. Data security
We use encryption in transit and at rest, secure storage, access controls, logging, and regular testing.
Chats are not end-to-end encrypted. They are encrypted in transit and at rest, and we do not routinely read them, but we are technically able to access specific content to investigate reports, meet legal duties, or prevent fraud, abuse or security incidents. Such access is limited and logged. We are telling you this plainly so you are not relying on a protection that does not exist.
Searching a chat reads that chat, by machine. When you search for older messages, the search runs on our servers rather than on your phone, because your phone only holds the recent ones. It checks that you are a participant, reads a batch of that chat's messages, matches your search term against them in memory and returns what it finds. Your search term is not stored, the results are not stored, and no person sees any of it. We are describing it because "the server searched your messages" is true, and you should hear it from us.
If we become aware of a personal data breach likely to risk your rights, we will assess and, where required, notify the ICO and affected users.
9. Your rights
You can access, correct, delete, or move your data, and object or restrict processing. You can withdraw consent at any time. To exercise rights, use the contact details in Terms section 1. You can also complain to the ICO.
Getting a copy of your data. Data export is handled by request rather than in the app. Ask us and we will put your data together and send it to you — we have a month to do that under UK GDPR, and no charge applies in normal circumstances. The right applies whether or not the app offers a button for it.
Joint content. A moment is content belonging to more than one person, and a photo of two people is personal data about both of them. What the app lets you do about that depends on how many people are credited:
- Removing yourself is available to a tagged person on a moment with three or more people. Your name and your take come off it. On a two-person moment there is no removing yourself — either of you can delete it instead — and the creator of a moment can only delete it, never leave it.
- Deleting the whole moment in-app is available to either person on a two-person moment, and to the creator on a moment with three or more people. A credited participant on a larger moment cannot currently delete it for everyone from within the app.
Your right of erasure is not limited by that. Where a moment is your personal data, your statutory right to have it erased applies whether or not the app gives you a button for it. If you cannot remove it yourself, contact us using the details in Terms section 1 and we will action it. The in-app controls and the legal right are not the same shape: the app's limits do not limit the right.
The consequence runs both ways: on a two-person moment, the person you posted with can delete something you value without asking you. Bear that in mind when you post.
Correcting content. You can add, update or clear your own take on a moment at any time, so your own words are always correctable, and clearing a take does not take you off the moment. What you cannot edit is someone else's take, including one written about you. If a take about you is wrong, ask the person who wrote it to change it, remove yourself from the moment, or contact us. The photograph itself cannot be changed once posted. If you believe we hold inaccurate personal data about you elsewhere, contact us and we will correct it.
Comments. You can delete any comment you have written. Nobody else can delete it, including the person whose post it is — so if a comment on your own moment is a problem, block the person or report it to us rather than expecting a control that does not exist. Deleting a comment also deletes the replies to it, which may be other people's words.
Chats. Deleting a message deletes it for everyone in the chat, not just for you. There is no delete-for-me-only option. Editing a message replaces it: the earlier version is not retained by us and cannot be recovered, and the message carries no mark to show it was changed.
10. Retention
| Data | Retention |
|---|---|
| Account data | While your account is active. Profile details are cleared the day you ask to delete; your login is deleted 30 days later, after a cooling-off period in which you can sign back in. A stub of the account — its internal id, personality results, moment and Thought counts, invite attribution, saved places and the date it was created — remains indefinitely (subject to legal holds/backups) |
| Content (moments, messages, Thoughts) | Until you delete it. Closing your account does not delete moments, Thoughts, comments or messages; they remain, attributed to "Deleted User". Deleted content may persist in backups for up to 30 days before ageing out |
| Archived event chats | Retained and available to participants; deleted when the chat is deleted, or on request |
| Events and RSVPs | Kept with the event; an event you were invited to remains with the other people on it after your account closes |
| Read receipts (last-read time per chat, last-opened time per event) | With the chat or event; visible to its other participants |
| Invite codes | 90 days from creation; deleted the day you ask to delete your account |
| Block log | Permanent |
| Nearby-alert ledger | Seven days |
| Live location | Up to 24 hours after sharing ends |
| Last-known location | Deleted automatically 24 hours after the last update, or sooner if superseded or if you turn location off |
| Saved places | Until you delete the place. Not deleted with your account — removed on request |
| Typing indicators | Removed when you send or stop typing; ignored by the app once stale |
| Daily poll answers | Kept as your poll history; not deleted with your account, removed on request |
| Personality results | Not deleted with your account; removed on request |
| Issue and bug reports | Kept while we work on the issue and for our own records; contains only what you wrote |
| Your phone's search index | Held on your device, not ours; cleared when you sign out or delete your account |
| Position data in platform request logs | 30 days |
| Safety/moderation records | As required by law and for legal claims |
| Analytics/diagnostics | Per tool settings, and only while consent is valid |
11. Your choices and controls
- Location: turn visibility on or off, switch it off for whole tiers, and hide from specific people, from the Map tab. Its visibility settings show who can currently see you at any time. Revoke the permission at device level to stop everything.
- Privacy settings: manage friend connections in the app and tiers on the Customize page. There is no setting that narrows who can see your profile, your posts or your friend list — any signed-in account can.
- Tiers: on the Customize page, make your tiering private if you do not want friends to see which tier you placed them in, or switch tiering off entirely if you do not want to place friends into tiers at all. If you switch it off, the map falls back to all friends — check your settings, because this can widen who sees you.
- Reflections: where tiers are on and visible, choose per friend what tier label people who are not your friends, your pals and your friends are shown. This changes what that person is shown only — it does not change who can see you on the map.
- Saved places: add or delete pinned places in the app. They are private to you; deleting one removes it.
- Nearby alerts: off unless you turn them on, in the Map's presence sheet.
- Analytics and personalised features: toggle in Settings → Account details at any time. In the UK and US analytics start on and you switch them off; elsewhere they start off and you are asked (section 5).
- Notifications: nearby alerts (off by default) and hang-out signals (on by default) each have a switch in the Map's presence sheet. Everything else — messages, waves, reminders and the rest — is controlled at device level; there is no per-type switch in the app.
- Account deletion: available in Settings. We will delete or anonymise your personal data unless we must keep it for legal or safety reasons.
12. Cookies and SDKs
In the app. We use essential SDKs for security and service delivery. We do not use advertising SDKs. Non-essential analytics and measurement are governed as described in section 5 — consent-first outside the UK and US, notice with an opt-out inside them — and you can change your preference at any time in Settings → Account details.
On this website. We set no advertising cookies and no analytics cookies. The site keeps four small values in your browser's own storage, and no cookies of ours: a flag recording that you have dismissed the storage notice, a flag recording whether you have ever used the colour toggle, and — for the current browser session only — which colour you chose and whether it is cycling. None of them identifies you, none is sent to us, and clearing your browser storage removes all of them. The site loads a web font from Google Fonts, which means your browser makes a request to Google to fetch it; no cookie is set by us in doing so. There is nothing here to opt out of, which is why the notice on this site is a notice rather than a consent request.
Your phone's own search index. So that Relay results appear when you search your device, we mirror a small amount into the operating system's index — Core Spotlight on iOS, AppSearch on Android. What goes in: for each friend, their username, name, profile description and avatar; for each chat, its title or the other person's name, its image, whether it is a group or an event chat, and up to eight participant names. What never goes in: the contents of any message. Archived chats are left out, as are blocked people from your friend list and one-to-one chats — though a blocked person who shares a group chat with you can still appear among that chat's participant names. The index lives on your device, not on ours, and it is cleared when you sign out — including when you delete your account, which signs you out.
Your phone's share sheet. So that Relay chats appear as targets when you share from other apps, we hand the operating system your most recent chats — their names, avatars and up to four participants' names — with no message content. On iOS the share extension also keeps its own small cache of recent chats, including each chat's last-message preview line, inside the app's own container on your device; it is cleared when you sign out.
13. Changes to this policy
We will post updates here and, for material changes, provide reasonable advance notice through the app or by email.
Contact: see our Terms and Conditions, section 1.
Relay Community Guidelines
Relay lets you share photos and videos with friends, message them, plan things, and find each other in person. These rules apply to all content and behaviour, in every format. We allow the widest range of lawful speech. If something breaks the rules below, report it in-app or contact us (see Terms section 1).
1. Be authentic and respectful
Share your own photos and videos. Don't impersonate others, mislead people, or manipulate engagement. Treat others with respect — no bullying, shaming, or targeted harassment.
This includes what you write on shared content. Every moment carries more than one name. Don't use your take to mock, expose or humiliate the person you posted it with, and don't add someone to a moment they wouldn't want their name on.
Remember how far a post goes. Moments and Thoughts are readable by any Relay account, not just by your friends or theirs. Posting a moment with someone puts their face in front of everyone, so ask yourself whether they would want that before you post, not after. You can update or clear your own take later, but you cannot edit anyone else's — so write about other people as carefully as if it were permanent, because for them it is.
Comments reach further than you might expect. Anyone on Relay can comment on anyone's post, which means you can turn up in a stranger's comments and a stranger can turn up in yours. Don't use that to pile on, follow someone around, or start something. The person whose post it is cannot delete your comment — only you and we can — so nobody is coming along behind you to tidy it up.
2. Keep it safe for everyone
- Child safety is paramount. Absolutely no sexualised or exploitative content featuring minors (under 18), including edited or generated images. Grooming or solicitation is banned and reported. See the CSAM Safety Policy.
- No threats of violence, encouragement of dangerous or criminal activity, or instructions to self-harm.
- If someone is in immediate danger, call 999.
3. Location: the rules
Location is the feature with the most potential to be misused, so these rules are strict.
- Don't track people. Don't use the map, waves or location shares to follow someone, work out where they live or work, turn up where they didn't invite you, or monitor their movements.
- Don't pressure anyone to share. Location visibility is a choice. Repeatedly asking, guilt-tripping or making it a condition of friendship is harassment.
- Don't pass it on. Don't screenshot, forward, post or otherwise share someone's location outside the app.
- Don't work around a block. Don't use another account, or ask a friend, to see the location of someone who has blocked you or turned you off.
- Turning it off is always allowed. Nobody is entitled to know where you are. You can hide from someone, switch it off for whole tiers, or switch it off entirely — at any time, without explaining and without telling anyone.
If someone is using location to make you uncomfortable, hide from them, block them, and report them. We act on this.
4. Events and meeting up
- Don't create fake events, or use invitations, waves and hang-out signals to spam people.
- Don't add someone as a plus-one without asking them.
- "Undecided" and "not going" are real answers. Don't pressure people into attending.
- Behaviour at an event arranged through Relay is still behaviour we will act on. Reports about what happened offline are taken seriously.
5. Daily poll and Thoughts
- The daily poll shows your answer to your friends — the app shows it to those who also voted that day, but treat it as visible to friends. Answering is optional, and nobody is owed your answer.
- Don't pressure people to vote, and don't use someone's answer to mock or target them.
- Thoughts are readable by anyone on Relay, not only your friends. The same rules on respect, harassment and other people's personal information apply to them as to anything else.
6. No illegal or highly regulated content
Don't post content that is illegal where you are or where your audience is. This includes CSAM, extremist content, and content that facilitates crime. Don't share others' personal data without permission — including their location, their address, or where they are going to be.
7. Adult content and nudity
We don't allow sexually explicit content, in any format — photo, video, voice message or GIF. Non-sexual nudity may be removed if it is likely to be viewed by or to risk harm to younger users, or where context is unclear.
8. Intellectual property and authenticity
Only post photos and videos you have the right to share, and only where the people in them are happy for you to. Don't upload other people's content without permission. Don't use deceptive edits to mislead others.
9. Spam and platform abuse
No spam, scams, or mass solicitation. Don't use automation, scraping, or exploits — including collecting friend positions, event details or venue data from the map. Don't interfere with the app's normal operation.
10. Safety tools, reporting, and appeals
- Block: blocking someone stops you seeing their content and stops them interacting with you. It ends location visibility in both directions and stops waves, immediately and whatever your map settings say. It also prevents them inviting you to events or adding you to a moment.
- Hide: if you only want to stop someone seeing your location, and don't want to cut them off entirely, hide from them instead. They aren't told.
- Remove yourself: if you're tagged on a moment with three or more people, you can take yourself off it. On a two-person moment the way out is to delete it, which either of you can do; the person who created a moment can only delete it, not leave it. You can also clear your take and stay on the moment, if it's the words you want gone rather than your name.
- Comments: you can delete your own, and only your own. If a comment on your post is a problem, block the person or report it — you can't remove it yourself, so tell us and we will act on it.
- Location controls: switch visibility off for whole tiers, hide from specific people, or turn it off entirely — at any time, from the Map tab. It stays on until you turn it off; closing the app doesn't. If you switch tiering off, the map falls back to all friends, so check it.
- Report: use the in-app Report Abuse tool or contact us using the details in Terms section 1. We prioritise serious harms and child safety. We may remove content, restrict features, or suspend accounts.
- Disagreeing with a decision: appeals are handled by email rather than in the app. Email us and a person will review it again. We may limit what we tell you in child-safety cases, where notifying an offender could increase risk.
11. Enforcement and transparency
We enforce these Guidelines consistently and explain our reasons where possible. Repeated or severe violations can lead to permanent bans. We may restrict access to location and event features specifically, without a full suspension, where those features are being misused. Moderation is carried out by people. We review content when it is reported to us rather than scanning it in advance, so reporting genuinely matters — if you don't report something, we may not know about it.
12. Updates
We update these Guidelines as our features and legal obligations evolve. We will post the updated date at the top.
Contact: see our Terms and Conditions, section 1.
Relay CSAM Safety Policy
Relay has zero tolerance for Child Sexual Abuse Material (CSAM) and child exploitation. We cooperate fully with UK child-protection bodies and law enforcement.
1. Prohibited content and behaviour
We prohibit:
- Any sexualised or exploitative images of minors (under 18), including edited, AI-generated, cartoon, or drawn depictions.
- Grooming, sexualisation, or exploitation attempts, including "age-play" or "barely legal" framing.
- Solicitation or sharing of child imagery, sextortion, trafficking, or instructions for obtaining CSAM.
- Links to CSAM or to services trading CSAM.
- Using Relay's location, event or meet-up features to arrange, attempt or facilitate contact with a minor for a sexual or exploitative purpose.
- Requesting, pressuring or manipulating a minor into sharing their location, meeting in person, or attending an event.
Where content features a person who appears to be a minor, we will treat it as involving a minor even if an asserted age conflicts with the appearance.
2. How our design reduces risk
Relay supports photos in moments, and photos, video, voice messages and GIFs in chats. We do not restrict formats. Our risk reduction comes from the structure of the product.
What is visible, and to whom, shapes the rest of this section. A signed-out stranger can see nothing, and there is no feed of strangers, no content browsing and no recommendation system — but any signed-in account can read any moment or Thought and comment on it. A minor's posted photograph is reachable by an adult who has never been accepted as their friend. The mitigations below are real, and this is what they do and do not cover:
- No reach and no algorithm. Nothing is amplified, nothing is recommended, and there is no feed of strangers. Content is reachable but not distributed: an adult cannot be served a minor's post, and would have to go looking for a specific account. There is no mechanism by which an adult can build an audience of minors.
- Contact requires an accepted friendship. Location, events and chats are not visible to a non-friend. A friend request must be sent and accepted before any of that is shared, and a request can simply be refused. Posts and a user's list of friends are the exceptions — both are open to any signed-in account.
- Mutual posting. A moment requires at least two people and appears on all of their accounts, which makes covert one-way collection of a minor's images structurally harder.
- Location is opt-in in full. The map is off until a user turns it on, and stays on until they turn it off — it does not reset when the app closes, for anyone. Users can switch visibility off for whole tiers of friends, and can hide from named individuals regardless. Visibility is further limited to a 5km radius, so proximity — not just permission — gates who can see anyone.
- 16+ minimum age, enforced at sign-up on a self-declared date of birth. See Terms section 3 for what that does and does not achieve.
- No older uploads. Content cannot be posted from more than seven days ago, which limits the use of Relay to distribute pre-existing material.
Residual risks
- Posts are open to every account on the service. A 16-year-old's moment or Thought can be read by any signed-in adult, friend or not, and there is no setting that narrows it. Nothing pushes that content towards anyone, which is the limiting factor, but nothing prevents it being read either.
- Comments come from anywhere. Any account can comment on any post. That is a direct channel from an unknown adult to a minor's content, and it does not require the minor to accept anything first. The minor cannot delete the comment themselves; they can block the account and report it, and we act on those reports.
- Video, audio and live location increase risk relative to a photo-only service.
- Offline meeting is the product's purpose, which makes grooming toward a meet-up the primary risk vector rather than a peripheral one. Section 4 addresses this.
- Adults can find minors by name or username in people search, read their posts and see who their friends are without asking, and send a friend request. Acceptance is required before location, events or chats are shared, but the initiating contact and the reading are possible without it.
- Users aged 16 and 17 use the same settings as adults. No age-specific location restrictions currently apply. The age gate rests on a self-declared date of birth, so we cannot rule out younger users who enter a false one.
- Moderation is reactive. Content is reviewed when it is reported, not before it is posted. See section 3.
3. Detection and enforcement
Detection rests on user reports and human review. Content is reviewed when it is reported to us rather than checked before it is posted or sent. That makes reporting essential, and we ask every user to report anything that concerns them.
- All formats — images, video, voice messages, GIFs, text, takes, comments, group chat names and images, event details and poll options — are reviewed on report by the founders, who carry out moderation themselves (see section 8).
- Reports are prioritised. Child-safety reports are escalated ahead of all other categories and actioned same-day wherever practicable.
On detection we will:
- remove the content immediately;
- permanently ban involved accounts and relevant devices where proportionate;
- preserve minimal necessary evidence (e.g. timestamps, account ID, IP/device information, content hashes) securely for reporting and law enforcement;
- report to UK child-safety authorities and law enforcement as appropriate, using their public reporting routes — the National Crime Agency's CEOP Command for grooming and child-risk cases, and the Internet Watch Foundation for imagery. We are not currently an IWF member and hold no formal arrangement with either body; these are the channels open to any provider, and we will use them.
We do not notify offenders where doing so could compromise safety or an investigation.
4. Offline meeting risk
Relay's purpose is to result in people meeting in person. We treat attempts to use that purpose to reach a child as among the most serious violations we handle.
- Grooming behaviour aimed at producing an offline meeting is banned whether or not any prohibited image is ever shared.
- We act on reports about offline conduct connected to Relay, including conduct at an event arranged through the app.
- We may remove access to location, event and meet-up features from an account under investigation, without waiting for a final determination.
- If a child is in immediate danger, call 999.
5. Reporting to Relay and to authorities
- In-app: Settings → Report Abuse.
- Email: see Terms section 1 (use subject "Child Safety – Urgent").
- Emergency: if a child is in immediate danger, call 999.
We escalate and prioritise child-safety reports for same-day action wherever practicable.
6. Working with UK and international bodies
Relay is a new and small service. We do not hold membership of, or a formal arrangement with, any of the bodies below. What we commit to is using their established reporting routes and cooperating fully with any request they make of us:
- CEOP (National Crime Agency) — for grooming and child-risk cases. Open to any provider, and the route we would use first.
- Internet Watch Foundation (IWF) — for reporting child sexual abuse imagery. We are not an IWF member and do not receive their hash lists or takedown notices.
- Ofcom — as our regulator under the Online Safety Act.
- Police forces and other competent authorities — on request, or where we identify a risk to a child.
7. Data handling and privacy
We retain only the minimal evidence necessary to meet our legal obligations and to support law enforcement and legal claims. Evidence is stored securely with restricted access and deleted when no longer legally required. Our Privacy Policy explains additional safeguards.
8. Governance and accountability
Child-safety escalations are handled by the founders directly, following written procedures, with record-keeping and periodic review. Relay is a small team: a report reaches someone who can act on it the same day. Appeals are handled by email rather than in the app; Terms section 12 explains how to challenge a decision.
Our reviewers are trained on the specific risk patterns introduced by location sharing and offline meeting arrangement, not only on content review.
Contact: see our Terms and Conditions, section 1.
Questions?
If you have any questions about our legal policies, please contact us.
Email: team@relay-social.com