Privacy Policy
Effective July 18, 2026
Relym is an AI-native IT service management platform used by organizations to run their internal support desks. This policy describes what we collect when an organization ("customer") uses Relym, how we use it, and the choices available. We act primarily as a processor of data our customers put into the service; the customer controls that data.
What we collect
Account data. Name, work email address, and role, provided when a workspace admin invites you or when your organization's identity provider signs you in.
Service content. Tickets, messages, knowledge documents, workflow definitions, asset records, and approvals your organization creates in Relym — including content that arrives through connected channels such as Slack, Microsoft Teams, or email intake.
Connected applications. When an admin connects a third-party application (for example Slack, Google Workspace, Okta, Microsoft Intune, Jira, Zendesk, or Notion), we store the credentials or tokens needed to operate that connection, encrypted with AES-256-GCM, and we access that application only to provide the features the admin configured — for example syncing devices, provisioning access, or mirroring tickets.
Usage and logs. Standard operational logs (timestamps, request metadata) and an audit trail of actions taken in the workspace, kept so admins can see who did what.
How we use it
To provide the service: routing and resolving tickets, running workflows and approvals your admins configure, syncing connected systems, and keeping the audit trail. We also use aggregate, de-identified operational metrics to keep Relym reliable. We do not sell personal information, and we do not use customer content for advertising.
AI processing
Relym's assistant features send relevant service content (such as a ticket and matching knowledge articles) to our AI model providers — currently Anthropic (language models) and Voyage AI (embeddings) — to generate replies, suggestions, and search results. These providers process the content to return a result and are contractually restricted from using it to train their models. Consequential actions the assistant proposes (like granting access) follow the approval rules your admins configure.
Subprocessors
We host on Vercel, store data in Neon (Postgres), process background jobs with Inngest, and use WorkOS for authentication. Together with the AI providers above, these are our subprocessors; each processes data only as needed to run Relym.
Retention and deletion
Customer content is retained for the life of the customer's workspace. When a workspace is deleted, or on a verified request from a workspace admin, we delete the associated content within 30 days, excluding backups that expire on their own schedule. Individuals can ask their workspace admin to correct or remove their data, or contact us directly.
Security
All traffic is encrypted in transit (TLS). Third-party credentials are sealed with AES-256-GCM before they touch the database, and every database query runs behind row-level security that isolates each organization's data. Access to production systems is limited to the small team that operates Relym.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Because your organization controls its workspace, the fastest path is usually your workspace admin; you can also email us and we will help, honoring applicable law.
Changes and contact
If this policy changes materially we will note the new effective date here and notify workspace admins. Questions or requests: gage@415inc.com.