Privacy Policy — RelayBird
Effective date: 2026.06.09 Last updated: 2026.06.09
This Privacy Policy explains how Mihaly Szakacs ("RelayBird", "we", "us") collects, uses, and protects personal data in connection with the RelayBird webhook-relay service available at relaybird.dev (the "Service").
1. Who is responsible (Controller)
The controller of your account data is:
- Mihaly Szakacs
- Szentendre, Hungary
- Contact: support@relaybird.dev
For the contents of the webhook events you send through the Service, you (our customer) are the controller and we act as your processor — see Section 9.
2. What data we collect
Account data. When you sign in with Google, we receive and store your **email address and a Google account identifier**. We do not receive your Google password.
Authentication data. API keys you create are stored only as a hashed value; we cannot recover the original key. Login sessions use a signed session cookie.
Event data you transmit. When your sources receive webhooks, we store the request body, content type, selected HTTP headers, and timestamps, plus the delivery records (status, attempt count, response codes, errors) needed to deliver and retry them. We deliberately **do not store the Authorization or Host headers**. This event data may contain personal data of *your* end users — see Section 9.
Usage data. We keep per-account monthly event counts to enforce plan limits.
Configuration data. Sources, destinations, routing filters, and alert webhook URLs that you configure.
Operational logs. Our servers and reverse proxy may record technical logs (including IP addresses and request metadata) for security, debugging, and abuse prevention.
3. How we use data
- To provide and operate the Service (receive, store, route, deliver, retry, and
display your webhook events).
- To authenticate you and secure your account.
- To enforce plan limits and quotas.
- To send operational failure alerts to the webhook URL you configure.
- To process payments and manage subscriptions (via our payment provider — Section 6).
- To maintain security, prevent abuse, and comply with legal obligations.
4. Legal bases (GDPR Article 6)
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to secure the Service, prevent abuse, and improve
reliability (balanced against your rights).
- Legal obligation — e.g. tax and accounting records.
- Consent — where specifically requested; you may withdraw it at any time.
5. How long we keep data (Retention)
- Webhook event data is automatically deleted based on your plan:
Free — 3 days, Pro — 30 days after receipt.
- Database backups are retained for [7] days and then deleted.
- Account data is kept while your account is active.
- Aggregate usage counters are retained to operate billing and limits.
- When you close your account, we delete or anonymise your personal data within
[30] days, except where we must retain it to meet a legal obligation.
6. Sharing and sub-processors
We do not sell personal data. We share data only with service providers acting on our behalf or as necessary to run the Service:
- Hosting: Hetzner Online GmbH (servers located in the EU).
- Authentication: Google (Sign in with Google).
- Payments: Polar, acting
as merchant of record, which processes your payment and billing data under its own privacy terms.
- Monitoring: [Healthchecks.io, UptimeRobot] for uptime and backup monitoring.
- Destinations you choose: we deliver your event data to the destination URLs
you configure (e.g. your own servers, Slack, Discord). You are responsible for those destinations.
A current list of sub-processors is available on request at support@relaybird.dev.
7. International transfers
Where a provider processes data outside the European Economic Area, we rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses or an adequacy decision).
8. Security
We use HTTPS/TLS in transit, store API keys only as hashes, sign outbound webhooks with per-destination HMAC secrets, restrict administrative access, and take regular encrypted backups. No method of transmission or storage is 100% secure, but we work to protect your data using appropriate technical and organisational measures.
9. Your end users' data (our role as processor)
The contents of the webhook events you route through RelayBird may include personal data of your own users. For that content, **you are the controller and RelayBird is the processor**: we process it only to provide the Service (store, route, deliver, retry, and display it to you) and according to your instructions. If you require a Data Processing Agreement (DPA), contact us at support@relaybird.dev. You are responsible for ensuring you have a lawful basis and any necessary consent to transmit personal data through the Service; we process it only on your instructions and are not responsible for the content, legality, or accuracy of the data you send.
10. Your rights
Subject to applicable law (including the GDPR), you may have the right to access, rectify, erase, restrict, or object to processing of your personal data, and to data portability. You may also lodge a complaint with your supervisory authority — in Hungary, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH). To exercise your rights, contact support@relaybird.dev.
11. Cookies
We use a single strictly necessary signed session cookie to keep you logged in to the dashboard. We do not use advertising or third-party tracking cookies.
12. Children
The Service is not directed to, and may not be used by, individuals under the age of 18.
13. Changes to this policy
We may update this policy from time to time. Material changes will be announced via the Service or by email, and the "Last updated" date will change.
14. Contact
Questions about this policy or your data: support@relaybird.dev.