Privacy Policy
This is a working draft, audited against the current codebase on 2026-08-01. Bracketed items in orange are placeholders that need a real value before this page is published or submitted for Google OAuth verification. This draft should also get a legal review pass; it is written to describe only what the product verifiably does today, not to be a substitute for counsel.
Two things this audit surfaced that are worth reading before you approve this draft — both are accurate-but-imperfect realities of the current implementation, not oversights I'm hiding:
- Deleting a chat session/history in the portal today is a soft delete — it disappears from your view but the underlying record isn't immediately purged from our database (Section 6).
- Full account/organization deletion is real and comprehensive, but it's currently performed by our team on request rather than as a one-click self-service action, and we don't yet commit to a fixed turnaround time (Section 6).
Neither of these blocks Google OAuth verification — Google cares about the Gmail-specific disclosures in Section 2, not your internal deletion UX — but you should decide, with legal input, whether to state them this plainly or invest in closing the gap first.
This Privacy Policy explains how [Relativity Systems, Inc. — confirm legal entity name] ("Relativity," "we," "us," or "our") collects, uses, shares, and protects information when you use the Relativity platform — our client portal, our Slack integration, our optional Gmail and Google Drive connectors — and when you interact with our public website, including our contact/inquiry form (collectively, the "Service").
Relativity is a business-to-business knowledge platform. Our direct customers are organizations ("Clients"), and the individuals who use the Service on a Client's behalf are that Client's team members. If you are a team member using Relativity through your employer or organization, your use of the Service is also subject to your organization's own policies.
1. Information We Collect
1.1 Account and profile information
When you or your organization creates an account, we collect information such as your name, work email address, and password. Authentication is handled by our identity provider, Supabase Auth — we do not store your password in plain text ourselves.
1.2 Content you upload or connect
The core of the Service is making your organization's own knowledge searchable. Depending on which sources your organization connects, this may include:
- Uploaded documents — files your organization's members upload directly to the portal.
- Slack messages — questions and threads where your organization's Relativity Slack app is mentioned or used, and any content your organization chooses to make searchable via Slack.
- Gmail content — for organizations that connect Gmail, and only for the individual members who personally authorize that connection: message content and metadata (subject, sender, date) that is either (a) explicitly labeled by that member for ingestion, or (b) matched by an organization-configured policy your admin sets up, depending on the mode your organization uses. We request read-only access — our Gmail integration cannot send, modify, compose, or delete mail on your behalf — plus the narrow ability to create and read a single managed label ("Relativity/Knowledge") used to mark what you've chosen to make searchable.
- Google Drive files — files a member explicitly selects and imports via Google's file picker, one file at a time. We do not maintain a persistent connection to your Google Drive and do not access files beyond what you've specifically chosen to import.
- Chat and query content — questions you ask the Relativity assistant and the answers it generates, including citations back to source content.
1.3 Usage and log data
We keep operational records needed to run and troubleshoot the Service — for example, per-connector sync activity (when a sync ran, how many items were imported, skipped, or failed) and, for Gmail specifically, a short structured reason for why an individual message was or wasn't imported (never the message's own subject or body). These are operational logs, not a comprehensive security audit trail — we do not currently operate a dedicated monitoring/alerting system across the platform. We do not use third-party advertising trackers, and we do not sell any data collected through the Service.
1.4 Website inquiries
If you submit our public website's contact form, we collect what you provide (name, email, phone, company, and your message) to respond to your inquiry. This information is stored in our systems and may be handled using internal tools our team uses to manage and follow up on inbound inquiries. It is not connected to, or mixed with, any Client's ingested knowledge content.
2. Google API Services — Limited Use Disclosure
Relativity's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, for the Gmail scopes we request (gmail.readonly and gmail.labels):
- Why we ask for it: to let an individual member make their own email a searchable part of their organization's Relativity knowledge base — either message-by-message (they label it) or by matching an organization-wide policy their admin configures.
- What we access: message content and metadata for mail that qualifies under one of those two mechanisms, plus the ability to create/read the single managed "Relativity/Knowledge" label. We never request send, compose, modify, or delete access to Gmail.
- How it's used: qualifying message content is processed into the same search/AI pipeline described in Section 3, so it can be retrieved and cited in answers — nothing more.
- We do not use Gmail data for advertising of any kind, and we do not sell or transfer Gmail data to third parties, data brokers, or ad networks.
- We do not allow our team to read Gmail content except: (a) with your affirmative consent for a specific, named purpose (for example, help debugging a support request), (b) as necessary for security purposes (such as investigating suspected abuse), (c) to comply with applicable law, or (d) as part of a merger, acquisition, or asset sale, with notice to you.
- A member can disconnect their Gmail account at any time from the portal. Disconnecting revokes the access token with Google and deactivates the connection immediately, preventing any further access. A member can additionally request deletion of previously-ingested content at the same time — see Section 6 for exactly what that does and doesn't guarantee.
3. How AI Is Used
Relativity uses AI to power search and question-answering over the content described in Section 1. Concretely:
- Uploaded documents and connected-source content (Slack, Gmail, Google Drive, when enabled) are converted into search embeddings and indexed so they can be retrieved when a member asks a question.
- When a member asks a question, relevant content is retrieved and sent to our AI provider to generate an answer with citations back to the source material.
- This processing happens only to answer requests made by an authorized member of your organization — content isn't processed speculatively or for purposes unrelated to search, retrieval, summarization, and question-answering.
- Our AI provider is OpenAI, accessed through their standard API. [Confirm current terms before publishing, but as of this writing, OpenAI's API platform terms state that data submitted through the API is not used to train their models unless a customer explicitly opts in — this is a statement about OpenAI's API product specifically, distinct from their consumer-facing products, and should be reconfirmed against OpenAI's current terms at publication time.] Relativity does not separately train any public or third-party AI model on your content.
4. How We Share Information
We do not sell personal information. We share information only with service providers who process it on our behalf, under their own terms, to operate the Service:
| Provider | Purpose | What it processes |
|---|---|---|
| OpenAI | Generates search embeddings and produces AI chat answers | Document/message content sent as part of ingestion and query processing |
| Supabase | Database, authentication, and file storage | Account data, uploaded documents, ingested content, chat history |
| Vercel | Application hosting | All application traffic (infrastructure-level only) |
| Inngest | Background job processing for ingestion and Slack question-answering | Ingestion job data (file references and metadata) and, for Slack-originated questions, the question text itself, in transit to trigger asynchronous processing |
| Resend | Transactional email (invites, password resets, contact-form notifications) | Name, email address, and the content of the transactional email itself |
| Slack | Optional integration your organization enables | Messages and workspace data your organization authorizes |
| Google (Gmail, Drive) | Optional integrations individual members enable | Mail/file content as described in Sections 1.2 and 2 |
We may also disclose information if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Relativity, our Clients, or others.
5. Your Content, Your Ownership
- Your organization retains ownership of the content it uploads or connects to Relativity — documents, messages, and any other material described in Section 1.
- We process that content only to provide the Service to your organization (search, retrieval, AI-generated answers, and the other functionality described in this policy) — not for our own independent purposes.
- We do not sell your content or use it to benefit any party other than your organization.
6. Data Retention and Deletion
Retention works differently depending on what you're deleting. We describe each mechanism as it actually works today, rather than promising a uniform timeline that doesn't yet exist in the product:
- Disconnecting Gmail or Slack stops future syncing immediately. For Gmail specifically, we also revoke the access token with Google at the moment of disconnection.
- Requesting content cleanup at disconnect (Gmail): if you ask us to remove previously-ingested content tied to that connection, we attempt to delete every item attributed to it. This is a best-effort operation across potentially many individual items — an individual item failing to delete doesn't block the rest, and isn't separately reported to you today.
- Deleting an individual document removes its content from search immediately (the underlying searchable text/embeddings are deleted); the document's record is marked deleted rather than being immediately purged from our database.
- Deleting a chat session or your chat history in the portal removes it from your view immediately. As implemented today, this is a soft delete: the underlying records are marked deleted rather than immediately and permanently erased from our database.
- Policy or label changes (Gmail, organization policy mode): if your admin narrows an organization-wide policy, or you remove the label from a previously-ingested message, that content is removed from search on the next sync.
- Member offboarding: an offboarded member's connections stop syncing immediately; whether their previously-ingested content is also removed is a separate choice your organization's admin makes.
- Full account or organization deletion is available and is comprehensive when performed — it removes ingested content and its searchable index, chat records, stored files, connection records, and login accounts. Today, this is carried out by our team upon request rather than as an automated, one-click self-service action within the portal, and we do not currently commit to a fixed turnaround time. Contact us at [privacy contact email] to request it.
- We do not currently have a fixed automatic expiration schedule for operational logs (for example, sync-run and ingestion-event records) — removal of that data today happens through the mechanisms above, not on an automatic timer.
7. How We Protect Information
We apply a mix of technical controls appropriate to a business knowledge platform, including:
- Encryption of OAuth credentials (Slack and Gmail) at rest, using AES-256-GCM.
- Traffic to and from the Service is encrypted in transit (HTTPS/TLS).
- Access to your organization's data is scoped to your organization's members and enforced in our application layer on every request.
- Cryptographically signed, time-limited requests between our own internal services, to reduce the risk of request forgery or replay.
- Role-based access within your organization — for example, only owners/admins can configure organization-wide connector policy.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your information, we will notify you consistent with applicable law.
8. Your Choices and Rights
- Access and correction — you can review and update your account information from the portal at any time.
- Disconnecting sources — you control which sources (Gmail, Slack, Google Drive) are connected and can disconnect at any time.
- Deletion — see Section 6 for exactly what each deletion mechanism does today.
- Depending on your location, you may have additional rights under applicable law — see Sections 9 and 10 below.
9. GDPR / European Privacy Rights
If the EU or UK GDPR applies to you — for example, because you are located in the European Economic Area, the UK, or Switzerland — you may have rights under that law, including the right to access, correct, delete, or restrict our processing of your personal information, the right to data portability, the right to object to certain processing, and the right to lodge a complaint with your local data protection authority.
This section describes rights that may be available to you under applicable law. It is not a statement that Relativity has completed a GDPR compliance program, certification, or formal assessment. To exercise any of these rights, contact us at [privacy contact email]. [Confirm whether Relativity currently serves clients/users in the EEA/UK, and if so, whether an EU representative or additional GDPR documentation (e.g., a records-of-processing register, Standard Contractual Clauses for transfers per Section 11) needs to be put in place before this section is relied upon.]
10. California Privacy Rights
If the California Consumer Privacy Act (CCPA), as amended by the CPRA, applies to you, you may have rights under that law, including the right to know what personal information we have collected about you, the right to request deletion or correction of that information, and the right to opt out of the sale or sharing of personal information. As described in Section 4, we do not sell your personal information, and we do not share it for cross-context behavioral advertising.
This section describes rights that may be available to you under applicable law. It is not a statement of CCPA/CPRA certification. We will not discriminate against you for exercising any of these rights. To exercise any of these rights, contact us at [privacy contact email].
11. Children's Privacy
The Service is intended for business use by adults acting on behalf of their organization. We do not knowingly collect personal information from children, and the Service is not directed to children.
12. International Data Transfers
[Confirm hosting/processing regions for Supabase, OpenAI, and Inngest, and add appropriate transfer-mechanism language (e.g., Standard Contractual Clauses) if your organization serves clients or users outside the United States.]
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, by posting an updated effective date at the top of this page, or by direct notice to Client administrators).
14. Contact Us
If you have questions about this Privacy Policy or want to exercise any of the rights described above, contact us at:
[Relativity Systems, Inc.]
[Registered address]
Email: [privacy contact email]