RelayDesk Privacy Policy
Last updated: September 25, 2026
RelayDesk is operated by Mave Studios LLP, a limited liability partnership incorporated in India ("Mave Studios", "RelayDesk", "we", "us").
RelayDesk lets an authenticated user connect devices they own or are authorized to control and use supported device actions from compatible AI apps.
Information we process may include account identifiers; paired-device identifiers, names, platform, agent version, hostname and presence timestamps; MCP tool schemas; command arguments and results; usage counters; billing/subscription status; transaction identifiers; diagnostic and security events; and information you voluntarily submit through support or feedback.
RelayDesk's public AI integration is not designed to process access credentials or authentication secrets such as passwords, API keys, MFA/OTP codes, tokens, passphrases or private keys, and it is not intended for payment-card data, protected health information or government identifiers. The native agent blocks recognized credential stores, secret-bearing files, environment-secret extraction patterns and authentication-secret prompts. Complete authentication locally on the device and keep restricted data outside RelayDesk workflows.
RelayDesk does not independently scan the public internet for machines and does not control a device until that device is deliberately paired to the authenticated RelayDesk account.
Payment processing. Paid RelayDesk plans may be processed by Razorpay. RelayDesk does not store full card numbers, CVV, UPI credentials or other payment-instrument credentials. Razorpay and relevant banks/payment networks process payment-instrument data under their own privacy notices and legal obligations. RelayDesk may retain payment provider customer, subscription, invoice/payment identifiers, currency, amount, payment status, billing period, and related records needed for billing, support, fraud prevention, accounting and legal compliance.
We use information to authenticate users/devices, route commands, return results, display device presence, meter plan usage, provide paid entitlements, process billing events, prevent cross-account access, investigate abuse/security incidents, maintain reliability and provide requested functionality.
Service providers may process information as necessary to operate RelayDesk, including Supabase for authentication/database/device transport, Vercel for the public web/OAuth/MCP facade, Razorpay for payments, and an AI platform selected by the user when that platform connects to RelayDesk.
Device metadata is retained until the device or associated RelayDesk data is deleted. Command/audit rows are retained for approximately 24 hours for reliability diagnostics, then deleted automatically. Billing, tax, fraud-prevention and accounting records may be retained longer where required by applicable law.
Users can stop the local agent, revoke a device credential or replace it by re-pairing, rename/delete paired devices, revoke AI-client OAuth access, and request deletion of RelayDesk-specific data. The underlying Supabase Auth identity may be shared with another Mave Studios service and is not automatically deleted when only RelayDesk data is removed.
Security measures include HTTPS/TLS, Row Level Security, owner-scoped routing, hashed device credentials, stale-device rejection, bounded command execution, command lease expiry, rate/usage limits and server-side payment verification.
RelayDesk does not sell personal data.
For privacy, billing or legal requests: relaydeskmcp@gmail.com
Security reports can be sent to relaydeskmcp@gmail.com. Do not include passwords, device tokens, payment credentials or private file contents.