Relaystation logo Relaystation

Privacy Policy

Last updated: July 13, 2026

This Privacy Policy describes how Relaystation ("Relaystation," "we," "us," or "our") collects, uses, discloses, and safeguards information in connection with the Relaystation API, MCP server, dashboard (app.relaystation.ai), and related services (collectively, the "Service"). It applies to developers, AI agents acting on behalf of a developer or organization, and any individual whose information passes through the Service — for example, a person completing identity verification or receiving a document for signature.

1. Scope

Relaystation is pay-per-call infrastructure for AI agents and developers, reachable via a hosted MCP server, a REST API, and the x402 payment protocol. Because the Service can be used without creating an account (the "lodestone" x402 path) or with an account (OAuth via Google/GitHub, or an API key), this policy covers both modes.

2. Information We Collect

Account and authentication data. If you sign in with Google or GitHub, we receive your name, email address, and account identifier from that provider. If you use an API key, we store the key (hashed) and associate it with your account and usage.

Payment and billing data. For prepaid-balance/API-key usage, Stripe processes card payments on our behalf; we receive transaction confirmations, billing metadata, and your ledger history, but we do not store full card numbers. For x402 per-call payments, we receive the paying wallet address and on-chain transaction data (USDC/EURC on Base) — the wallet itself is the identity, and no other account information is required.

Content you send us. Depending on which tools you call, this can include: files and data stored in a Baton (Drop, Pass, Scratchpad, Checkpoint, Ledger); documents submitted for conversion, OCR, or e-signature; images, audio, or video submitted for processing; text submitted for translation, summarization, classification, or other language tasks; and data submitted for SQL/ETL operations. We process this content to perform the requested operation and, for storage products (Batons), retain it according to the lifecycle you configure (see Section 6).

Identity verification and screening data. If you or your end users use idverify or screen_name, we collect and process government-ID images, biometric liveness/face-match data, and name/identity information submitted for sanctions and PEP screening. This is sensitive personal data and is handled under stricter controls described in Section 7.

Messaging data. If you use Courier (ask_operator, notify_operator, message_agent), we process the message content and the destination contact information (Telegram handle, email address, or phone number) needed to deliver it, and any reply received.

Agreements and arbitration data. If you use contracts/arbitration tools, we store the terms, parties, signatures, and any dispute record associated with an agreement.

Technical and usage data. We automatically collect API request logs, tool-call metadata, IP address, timestamps, error data, and similar diagnostic information needed to operate, secure, and bill for the Service.

3. How We Use Information

We use the information described above to operate and provide the Service (executing the specific tool called and returning a result); authenticate requests and enforce prepaid balances and rate limits; process payments and maintain an accurate transaction ledger; deliver messages and documents to the humans or agents you direct us to reach; complete identity verification and sanctions/PEP screening where you request those tools; secure the Service against fraud, abuse, and unauthorized access; and comply with legal obligations, including recordkeeping obligations tied to KYC/AML-adjacent tools.

We do not use the content of your Batons, documents, or messages to train AI models, and we do not sell personal information.

4. When We Share Information

We share information with:

We do not share Baton content, document content, or message content with other customers or with unrelated third parties.

5. x402 and Wallet-Based Usage

When you pay per call via x402 with no account, we treat the paying wallet address as your identity for that transaction and any linked ledger history. We do not require or collect a name, email, or other personal identifier for this path unless the specific tool you call (e.g., idverify, screen_name, esigndoc) inherently requires it.

6. Data Retention

Retention depends on the product:

7. Sensitive Data (Identity Verification and Screening)

Government-ID images, biometric liveness/face-match data, and screening results are processed only to perform the specific verification or screening you requested, are encrypted in transit and at rest, and are subject to stricter access controls than general Baton content. We do not use this data for advertising, profiling unrelated to the requested check, or any secondary purpose.

8. International Data Transfer

The Service may process and store data in jurisdictions other than your own, including the United States. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers of personal data.

9. Security

We use encryption in transit and at rest, access controls scoped to the minimum necessary, and hash-chained/witnessed integrity checks for Ledger-type Batons. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your Rights and Choices

Depending on your jurisdiction, you may have the right to access, correct, delete, or export personal information we hold about you, and to object to or restrict certain processing. You can exercise most of these rights directly for account data via the dashboard at app.relaystation.ai, or by contacting us at the address below. For data submitted through Courier, e-signature, or verification tools on behalf of a third party, the developer or agent that submitted the data is responsible for ensuring they had a lawful basis and, where required, the individual's consent.

11. Children's Privacy

The Service is intended for use by developers, businesses, and their AI agents, not by children. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this policy from time to time. We will post the updated version at this URL and update the "Last updated" date above. Material changes will be communicated through the dashboard or by email where we have your contact information.

13. Contact Us

Questions about this policy or requests regarding your data can be sent to hi@relaystation.ai.