PRIVATE PREVIEW · VERSION 2026-10-11
Privacy notice
Know where the context goes.
Effective and last updated: 11 October 2026
Execution can happen on a laptop while selected task data is stored in Figureit’s cloud and sent to AI providers. “Local” does not mean “offline” or “never leaves the device.”
This Relay-specific notice describes the current preview and supplements the Figureit Privacy Policy. Figureit Ltd. is the operator. Contact admin@figureit.ai about access, correction, deletion or other applicable privacy rights.
What Relay handles
- Account data: email, identity and authentication information needed for sign-in and room membership.
- Shared work: conversation messages, plans, acceptance criteria, participant feedback, progress summaries, execution-host information and activity records.
- Local work: selected checkouts, task context, CLI sessions and logs, diffs, test output, screenshots and reports saved on the execution laptop. Some of that content can appear in shared summaries or provider prompts.
- GitHub delivery: when PR delivery is approved, task branches and a PR description containing the review summary, checks, caveats and security notes are sent to the selected GitHub repositories. Screenshots and raw logs remain local unless separately uploaded. A public repository makes published code and PR descriptions public.
- Transfers: selected workspace content and task context uploaded as a private checkpoint when execution moves between participants.
- Access requests: name, email, optional company and note, contact permission and request status. A temporary hashed IP-based counter helps limit form abuse.
Why and with whom
Relay uses this information to authenticate participants, coordinate requested work, preserve context, present results, transfer execution, operate the service and handle access requests or security issues. Room members can read the shared room data allowed by their roles. Execution hosts can access the workspace they receive. Authorized Figureit administrators and infrastructure providers may need operational access; room membership is not a promise of end-to-end encryption.
Shared service data is hosted in Figureit’s AWS account in the US East (Northern Virginia) region. Authentication uses Amazon Cognito. Coding tools send selected prompts, code and tool results to their configured AI services. Managed execution sends repository content to the managed provider. Provider processing may take place in other locations under the relevant account agreement.
Provider retention and model-training settings depend on the account and service used. Relay does not turn off those settings for you or offer a blanket no-training or zero-retention guarantee. Review the OpenAI policies and Anthropic commercial terms, or the consumer terms applicable to your account.
Retention and deletion
- Shared room records currently have no automatic expiry. Ask Figureit to arrange deletion; backups may persist under the cloud backup configuration.
- Transfer checkpoints are configured to expire after 30 days, with noncurrent versions expiring after 7 days. Storage cleanup is asynchronous, so these are lifecycle settings rather than guaranteed deletion deadlines.
- Access requests are scheduled for expiry after 90 days. Anti-abuse counters expire after roughly 2 hours; cleanup can take longer.
- Service function logs are configured for 14-day retention.
- Local files remain until removed from the laptop. Signing out, closing Relay or removing room membership does not erase them or copies previously downloaded. Provider-held records follow the provider’s policy.
Browser storage and account safety
The shared browser app uses session storage for sign-in tokens and local storage for unfinished conversation and review drafts. Signing out clears the app’s session token but does not currently erase saved drafts. Use a trusted device; clear browser site data if you need to remove those drafts. Authentication services may also use their own sign-in cookies.
Do not paste passwords, API keys, production secrets or unnecessary sensitive personal data into conversations or access requests. Redaction and checkpoint exclusions can reduce accidental exposure but are not exhaustive. Report a suspected leak promptly so the relevant credentials can be revoked or rotated.
Your requests
For privacy requests or questions, contact admin@figureit.ai. We may need to verify your identity and coordinate with your workspace administrator. The Figureit Privacy Policy describes applicable rights and the broader legal basis for processing. Removing data from Relay does not automatically remove it from a participant’s laptop, GitHub or an AI provider.