Privacy Policy
Last updated ยท 17 September 2026
In one sentence: Relay reads incoming text messages on your phone and forwards them only to destinations you set up yourself. We run no server that receives your messages, we show no ads, and we use no tracking or analytics. The only third parties in the app are Google Play billing (through RevenueCat) for the optional Pro purchase, and Firebase Crashlytics, which receives a technical report if the app crashes and never any message content.
01 Who we are
Relay ("the App") is developed and operated by Livotov Labs Ltd. ("we", "us", "our"), P.O. Box 99, Varna 9002, Bulgaria, Company ID 202346120. For any privacy question, contact labs@livotov.eu. This Policy explains how the App and this website handle information.
02 Our core principle: on-device processing
Relay is designed so your message content never leaves your device except to the destinations you explicitly set up: another phone number, your own Telegram bot and chat, your own email account or Postmark server, a web address you control, or an automation app on the same phone. There is no Relay cloud, no Relay account, and no intermediary server that receives, stores or reads your messages. This is true for every destination kind, email included.
03 Information the App accesses on your device
To perform its single function, forwarding text messages, the App accesses the following locally, on your device:
- Incoming SMS (sender and text): read when a message arrives, evaluated against your rules, and forwarded if a rule matches. Requires RECEIVE_SMS and READ_SMS. If you prefer not to grant SMS access, Relay can instead read the text from your messaging app's notification, which requires notification access and no SMS permission.
- Sending SMS: if you configure an "Another phone" destination, the App sends the forward through your device with SEND_SMS. Carrier charges may apply.
- Notifications: to tell you when a delivery has failed (POST_NOTIFICATIONS).
- Network access: to deliver to Telegram, email and webhook destinations you configure (INTERNET).
- Background work: to finish a delivery after a message arrives and to retry a failed one, the App schedules short background jobs and may ask you to exempt it from battery optimisation (REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, RECEIVE_BOOT_COMPLETED).
We request only the permissions the feature you use needs, and the App works, with the feature disabled, if you decline.
04 Information stored on your device
Stored locally only:
- Your rules, destinations and app settings.
- A capped activity log of forwarded, skipped and failed messages (sender and a short preview), so you can see what happened and retry failures. For a failed delivery the full text is kept for up to seven days so it can be resent, then deleted.
- Secrets, meaning a Telegram bot token, a webhook header value, a mail password or a Postmark server token, are held in your device's hardware-backed encrypted storage and are never written to logs or exports.
Clear the log at any time (Activity โ Clear, or Settings โ Your data). Uninstalling removes all locally stored data.
05 Information sent to third parties: only the destinations you choose
When a message matches a rule, its content is transmitted from your phone directly to the destination(s) you configured. Those services have their own terms and privacy policies:
- Another phone: delivered as an SMS through your mobile carrier.
- Telegram: delivered through the Telegram Bot API to the chat or channel you specify, using your own bot.
- Email: delivered either through the mail server and account you provide (SMTP) or through your own Postmark account using your server token. Either way the connection is made from your phone.
- Webhook: posted as JSON to the web address you provide.
- Automation app: handed to an app on the same phone (such as Tasker) by an Android broadcast. If you do not name a target app, any app on the phone that listens for that broadcast can receive it; the App warns you about this.
We neither control nor take responsibility for how those services process messages you route to them, and we never add ourselves as a recipient or intermediary.
06 Purchases and crash reports: the two SDKs we use
Relay offers an optional "Pro" upgrade, as a one-time purchase or an annual subscription with a free trial. Payments are processed by Google Play; we never see or store your card details. To recognise your purchase across reinstalls and devices, the App uses the RevenueCat SDK, which receives from Google Play your purchase and subscription status together with a random app-instance identifier. That identifier is not linked to your name, phone number or messages, and RevenueCat processes it only to provide the entitlement service (see RevenueCat's privacy policy). Manage or cancel subscriptions in Google Play; refunds follow Google Play policies.
If the App crashes, Firebase Crashlytics (Google) sends us a technical report so we can fix the fault: the stack trace, the app version, the Android version, the device model, free memory and storage, and a random installation identifier that Crashlytics generates. A report never contains a message, a phone number, a rule or a destination, because the App does not hand any of those to Crashlytics. Reports are kept by Crashlytics for 90 days. Crash reporting is switched off in development builds and there is no analytics or usage tracking (see Firebase's privacy documentation).
07 What we do not do
- We do not operate a server that receives your messages.
- We do not sell, rent or share your data with anyone.
- We do not use advertising, ad networks or advertising identifiers.
- We do not embed analytics or tracking SDKs. The only SDKs that talk to a network on our behalf are the purchase SDK and the crash reporter described above, and neither ever receives a message.
- We do not require an account, an email address or a sign-up.
08 This website
This website uses no cookies, no trackers, no analytics and no third-party scripts. Nothing about your visit is collected or stored by us, so there is no cookie banner: there is nothing to consent to. Fonts are loaded from Google Fonts solely to render the page, which means your browser requests them from Google's servers under Google's privacy policy. If the site is served through a hosting provider, that provider may keep ordinary server logs (such as IP addresses) for security and operation.
09 Children
Relay is intended for adults and is not directed to children under 18. We do not knowingly collect information from children.
10 Your rights
Because your data lives on your own device, you control it: view, edit or export the activity log, or delete everything by clearing it in the App or uninstalling. Data-protection rights under the GDPR and equivalent laws apply; since we hold no personal data on servers of our own, most requests are satisfied directly on your device. You may still contact labs@livotov.eu, and you have the right to lodge a complaint with your supervisory authority.
11 Security
We minimise risk by keeping data on your device, encrypting secrets in the Android Keystore and using encrypted connections (HTTPS, or TLS for mail) to every destination that supports them. No method is perfectly secure, but by design there is no central store of your messages to breach.
12 Changes
We may update this Policy for new features or legal requirements. Material changes update the "Last updated" date above and, where appropriate, are noted in the App.
13 Contact
Livotov Labs Ltd.
P.O. Box 99, Varna 9002, Bulgaria
Company ID 202346120
Email labs@livotov.eu