FetchRelay
Privacy policy
Last updated: September 5, 2026
This notice explains how FetchRelay handles information when you use fetchrelay.com and the FetchRelay API. FetchRelay is a tool for extracting public web content, running crawls, and monitoring changes. For questions or privacy requests, contact support@jaipilot.com.
Account information and Google sign-in
When you continue with Google, we request only your basic identity, email address, and profile information (openid, email, and profile). Google provides an account identifier, email, and basic profile details such as your name and profile picture. Supabase, our authentication provider, processes this information and authentication tokens to create and manage your FetchRelay account and session.
We use this information to identify you, secure sign-in, associate your API keys, usage, jobs, and monitors with your account, and respond to account support requests. We do not receive your Google password or request access to Gmail, Google Drive, contacts, or calendars. We do not sell Google user data, use it for advertising, or use it to train models. Google account information is not included in scraping requests or customer webhook payloads.
If you choose another available sign-in provider, we process its account identifier, email, and basic profile information for the same purposes. Email and password sign-in, where available, is handled by Supabase.
Information processed by the tool
- Submitted URLs, request options and headers, extracted content, screenshots, job status, errors, and results needed to run your requests.
- Monitor settings, schedules, webhook destinations, latest results, and change history needed to run monitoring and deliver notifications.
- API key names, prefixes, hashed keys, timestamps, and usage counts needed to authenticate requests and enforce limits. Newly generated API keys are shown once.
- Technical information used for operation and abuse prevention, including request timing, errors, and network metadata. Our rate limiter uses a hashed IP identifier; hosting providers may also process IP addresses and request logs.
- Information you choose to include when contacting support.
Do not submit passwords, private access tokens, or unnecessary personal information in URLs, headers, or content. Extracted pages may contain personal information. You are responsible for having the necessary permission to collect and use it; optional redaction does not guarantee that all personal information is removed.
Storage, sharing, and international processing
We use Supabase for authentication and database storage, and Vercel for hosting, request processing, and storage infrastructure. These providers process information to operate FetchRelay. Processing includes the United States and may occur in other countries where our providers operate. Account and job data are not restricted to storage in India.
A target website receives requests needed to fetch its content, including headers you supply. Browser rendering may also contact services embedded in that page. If you configure a webhook, we send the relevant job or monitor notification to the destination you specify. Exported results are delivered to you or the client you authorize.
We may access or disclose relevant information to investigate abuse, resolve support requests, protect the service, or meet a legal obligation. We do not sell account information or scraped results. Third-party sites and services have their own privacy practices.
Cookies and security
FetchRelay uses cookies for authentication, secure sign-in redirects, and account recovery. Production session cookies are Secure and HTTP-only. Blocking these cookies can prevent sign-in. We do not currently use advertising cookies or third-party marketing analytics in the app. We use HTTPS, server-side account checks, and hashed API keys; no system can guarantee absolute security.
Retention
Account details, usage records, and monitor configuration are retained while needed to provide and secure your account. Automated cleanup is configured to remove jobs that are no longer queued or running after 30 days from creation, associated job history, delivered webhook records after seven days, and minute-level rate-limit records after one day. Active jobs, undelivered notifications, and the latest monitor state may remain longer. Optional in-memory result caching has a maximum freshness window of 24 hours.
Backup copies and provider logs may persist beyond deletion from the active database under provider retention processes. Information needed for security or legal obligations may be retained longer. Export results you need to keep; FetchRelay is not a permanent archive.
Your choices and requests
You can export available results, revoke API keys, and remove monitors using the app. To request access, correction, an account export, or deletion of your account and related data, email support@jaipilot.com. We may need to verify account ownership before acting on your request. Privacy rights and applicable exceptions depend on your location.
You can revoke Google access in your Google Account connections. Revoking access prevents future use of that authorization but does not itself delete your FetchRelay account or data already stored. Contact us to request deletion as well.
Changes to this notice
We will update this page when our data practices change. If we request additional Google data or use it for a new purpose, we will explain the change and obtain any required consent before doing so.