Skip to content

We only see what you choose to share, and we guard it.

RelayLine doesn’t connect to your inbox, your calendar, or your calls. It reads what your team sends to a capture address, keeps each firm’s data apart and encrypted, and gives you the controls to decide who sees what and for how long.

RelayLine never

  • Joins your callsIt reads transcripts and recaps you choose to forward.
  • Reads your inbox or calendarOnly mail and invites sent to its address, from senders it can verify.
  • Mixes your data with another firm’sEvery firm has its own separate, encrypted database.
  • Contacts your clients on its ownSurveys go out only when you send them.
  • Trains AI models on your dataAnd our AI provider’s terms prohibit it.

You control

  • Exactly what it seesNothing is captured unless your team shares it.
  • Who can see each clientRoles, two-factor, and restricted clients only named people can open.
  • How long text is keptSet a retention period; old email and transcript text is removed.
  • Exporting or erasing dataA whole client, or everything about one person when they ask.
  • The recordEvery sign-in, export, and change is logged, and you can download it.

What it reads

  • Email your team CCs or forwards to a client’s capture address. Calendar invites that include it, with meeting links and dial-in passcodes removed before storage. Transcripts and AI recaps your team forwards.
  • Only real senders get in. Each capture address is unguessable, and RelayLine checks every message’s email authentication itself (DKIM signatures and SPF). Mail claiming to be from your firm that fails is refused. Mail from a client counts only once your team has written to that person or an admin trusts them; anything else is held for your admin and never used unless accepted.
  • No replays. A real email someone received from you can’t be re-sent into RelayLine: it has to name the capture address and be recent.

Separation and encryption

  • A separate database for every firm. Your firm’s data lives in its own database. Sign-ins, links, and incoming mail are tied to one firm, so one firm’s account can’t reach another’s.
  • Encrypted in transit. Every connection to RelayLine uses HTTPS.
  • Encrypted at rest. The text of captured email and call transcripts is stored encrypted, with a key per firm held outside the database. Saved secrets, like your HubSpot token and two-factor keys, are encrypted too.
  • Encrypted backups. Nightly backups are encrypted before they leave the server, so the storage provider never sees readable data.

Who can see it

  • Individual accounts. Everyone signs in with their own email and password. There’s no shared login.
  • Roles. Admins invite people, change roles and settings, and export or delete data. Members work their clients.
  • Restricted clients. Admins can limit a sensitive client to named people. Everyone else can’t see it anywhere: not in lists, totals, briefs, alerts, exports, or the weekly digest.
  • Two-factor sign-in. Codes from an authenticator app, with one-time recovery codes. Admins can require it for everyone.
  • Protected sign-in. Passwords are stored as salted scrypt hashes. Repeated wrong passwords or codes lock the login for 15 minutes, and the person is emailed when their password or two-factor settings change.
  • Sessions that end. Signing out ends the session for good, idle sessions expire after a day, and you can see and sign out every device you’re signed in on.
  • Activity log. Sign-ins, invites, role and setting changes, exports, and deletions are recorded with who did them, and admins can download the log.
  • RelayLine’s own view. The tools we use to run the service show each firm’s status and usage, not its client data.

AI

  • Calls and emails are analyzed with Anthropic’s Claude through its commercial API. Anthropic’s commercial terms say it may not train models on customer content, and RelayLine doesn’t train models on your data either.
  • Quotes are verified. Every quote is checked word for word against the original transcript. If it isn’t there, it isn’t shown.
  • Instructions in your data are ignored. Text inside an email or transcript can’t change how RelayLine scores an account.
  • Usage limits. Each firm can cap its monthly AI usage; past the cap, simpler keyword analysis takes over and nothing stops working.
  • How we measure accuracy

Retention and deletion

  • Retention you set. Choose how long transcript and email text is kept. After that, the text is deleted; scores and signals stay.
  • Delete a client. Admins can delete everything captured for a client in one step, after exporting it if they want.
  • Erase a person. If someone asks, an admin can find everything RelayLine holds about their email address, export it, or erase it.
  • When you leave. You have 30 days after your subscription ends to export. Then your firm’s database is deleted, and encrypted backups expire on their own.

Privacy and compliance

  • Your firm stays in charge. For client information, your firm is the controller and RelayLine is its processor. Our Data Processing Addendum sets out what we do with it and what we don’t.
  • Data subject requests. Access, export, and erasure requests (GDPR, UK GDPR, CCPA/CPRA) can be answered from the dashboard, and we’ll help with any we can’t.
  • Breach notice. If a security incident affects your data, we’ll tell your admins without undue delay, and within 72 hours of confirming it.
  • Policies. Privacy Policy, Terms of Service, and the subprocessors below.

Backups and monitoring

  • Nightly backups of every firm, kept on the server and, encrypted, in separate storage.
  • Mail isn’t dropped. Incoming email is queued and retried if anything fails, and repeat deliveries are ignored.
  • Monitored. Health checks and alerts cover crashes, failed backups, and mail that gets stuck.
  • Hardened app. Strict content security policy (no scripts we didn’t write), protection against cross-site requests and forged sign-in links, and spreadsheet exports that can’t carry formulas.

Service providers

  • Railway hosts the application and its databases.
  • Cloudflare protects and delivers the website.
  • Postmark receives captured email and sends ours.
  • Anthropic provides the AI analysis of calls and email.
  • Stripe handles payments. We never see or store card numbers.
  • Encrypted backup storage (S3-compatible). It only ever receives encrypted files.
  • HubSpot and Slack receive data only if your firm connects them.

Security reviews

Every release goes through automated tests that try the attacks above: cross-firm access, forged mail, replays, session tampering, and more. RelayLine doesn’t hold a SOC 2 report or a third-party penetration test yet. If your firm has a security questionnaire, we’ll fill it out and answer it straight.