Relate Privacy Policy

Pixelic, Inc. ("Company", "we", or "Owner") operates Relate, Spread, and Spread AI (collectively, the "Service") and is committed to protecting users' personal data. This Privacy Policy applies to non-Korean users; Korean users are covered by a separate Korean-language Privacy Policy issued by Pixelic Korea, Inc.

This Policy explains what personal data we process, the legal bases for processing, the parties with whom we share data, international transfers, retention, and the rights available to data subjects — including users in the European Economic Area and the United Kingdom (under the GDPR/UK GDPR) and residents of California (under the CCPA/CPRA).


1. Owner and Data Controller

2. Types of Personal Data Collected

We collect the following categories of personal data, by ourselves or through third parties:

Unless stated otherwise, the data we request is necessary to provide the Service, and failing to provide it may make it impossible for us to provide the Service. Personal data may be freely provided by the User or, in the case of Usage Data, collected automatically when using the Service.

For third-party personal data (contacts/leads) a Member uploads to the Service, the Member is responsible for securing a lawful basis to collect and use it; in such cases we process the data as a processor acting on the Member's instructions. The Service is intended for business users and is not directed to children; we do not knowingly collect personal data from children under the applicable minimum age.

3. Mode and Place of Processing

We take appropriate technical and organizational security measures to prevent unauthorized access, disclosure, modification, or destruction of data. Processing is carried out using computers and IT-enabled tools, following procedures strictly related to the purposes indicated. Data may be accessible to persons involved in operating the Service (administration, sales, marketing, legal, system administration) or to external parties appointed as data processors (see Sections 6 and 7).

Depending on the User's location, data transfers may involve transferring data to a country other than the User's own. See Section 7 for international transfer details and safeguards.

4. Purposes of Processing

We process personal data to provide the Service, comply with legal obligations, respond to enforcement requests, protect our rights and interests (and those of our Users or third parties), detect malicious or fraudulent activity, and for the following purposes:

  1. Membership registration and management: identification, authentication, fraud prevention, notices.
  2. Service provision: CRM/contact management, email sending and workflow automation, AI-powered content generation/summarization/analysis, engagement (open/click) tracking.
  3. Paid Services and settlement: payments, billing, withdrawal/refund handling.
  4. Customer support: handling inquiries and complaints and notifying outcomes.
  5. Service improvement and product development (including aggregated/de-identified analysis).
  6. Marketing and event information (where consent is obtained).

5. Legal Basis for Processing (GDPR)

For users in the EEA and UK, we process personal data on one or more of the following legal bases under Article 6 GDPR:

We will gladly clarify the specific legal basis that applies, including whether the provision of personal data is a statutory or contractual requirement.

6. Processors and Sub-processors

We delegate processing to the following parties to provide the Service. These services are engaged under data processing agreements that restrict use to our instructions:

When entering into processing agreements, we specify, as required by applicable law, restrictions on processing beyond purpose, security measures, limits on re-delegation, supervision of the processor, and liability. Changes to processors are disclosed through this Policy.

7. International Transfers of Personal Data

We transfer personal data to the recipients below. Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) (and the UK Addendum) or an applicable adequacy decision.

Data subjects may object to or refuse cross-border transfer; refusal may restrict all or part of the Service relying on that processing. To do so, contact us at the address in Section 11.

8. Retention

Unless stated otherwise, personal data is processed and stored for as long as necessary for the purpose for which it was collected, and may be retained longer where required by a legal obligation or based on the User's consent. In particular:

Once the retention period expires, personal data is deleted; the rights of access, erasure, rectification, and portability cannot be enforced after expiry.

9. AI Features and MCP Integration

(1) We provide AI-powered features that generate, summarize, or analyze content at the Member's request, processed via the AI processors in Sections 6–7. AI features operate solely as user-facing tools; the Member is responsible for verifying AI-generated output.

(2) When a Member activates MCP (Model Context Protocol) or external integrations, the Member's data may be transmitted to the external tools, data sources, or AI model providers the Member selects. Such integration occurs only upon explicit activation, and processing by the external service is governed by that provider's privacy policy.

(3) We may use aggregated and de-identified information to improve our systems. We do not use Google user data obtained through Google APIs to develop, improve, or train generalized AI or machine-learning models (see Section 10).

10. Google API Services User Data Policy — Limited Use

Where a Member enables Google integration (e.g., Gmail sync/send), we may access, through authorized Google APIs: Gmail message metadata (sender, recipient, subject, timestamps) and Gmail message content within the scope the Member authorizes for sending/synchronization. We process Google user data only to: send Member-authorized email, synchronize communication threads, render per-recipient email, provide engagement (open/click) tracking, and display communication history within the Service.

Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  1. Google user data is used only to provide user-facing functionality.
  2. Google user data is not used to develop, improve, or train generalized AI or machine-learning models.
  3. Google user data is not used for advertising and is not sold.
  4. Google user data is not transferred to third parties except as necessary to provide the Service.
  5. We do not permanently store Gmail message bodies; we process them transiently only as necessary to provide the Service and do not transfer Gmail message content to third-party email-delivery providers.
  6. Members may disconnect their Google account at any time. Upon account deletion or revocation, we cease accessing new Google user data and delete associated stored data within a reasonable period, except where retention is required by law.
  7. The https://mail.google.com/ scope is used only to (i) authenticate SMTP sending via OAuth 2.0 (XOAUTH2) to deliver individualized, per-recipient messages with Member-configured tracking links and accurate delivery/engagement tracking, and (ii) permanently delete email threads that the Member explicitly selects (via the Gmail API threads.delete method, bypassing Trash, with explicit confirmation and available only to the mailbox owner). Access is limited to functionality the Member explicitly enables.

We apply technical and organizational safeguards to Google user data, including encryption in transit and at rest, role-based access controls, and access logging.

11. Rights of Data Subjects (GDPR)

To the extent permitted by law, Users may exercise the following rights regarding their personal data:

How to exercise: Requests may be directed to us via the contacts in Section 1. Requests are free of charge and answered as early as possible and always within one month, as required by law. An agent acting on a data subject's behalf must provide appropriate authorization.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) provides the following rights:

How to exercise: Submit a request to privacy@relate.so. We will verify your request and respond within the timeframes required by the CCPA. You may use an authorized agent, subject to verification. We do not knowingly sell or share the personal information of consumers under 16 years of age.

13. Service Linkage (Relate · Disquiet)

(1) Separately from Relate, Disquiet — an IT/maker community service — is operated by Pixelic Korea, Inc. Relate and Disquiet are independent services.

(2) Creating a Relate account alone does not create a Disquiet account. Where a user separately registers for Disquiet, account linkage and the processing of personal data in that service are governed by that service's (Korean-language) privacy policy.

14. Cookies and Tracking

(1) We use cookies and other trackers for login persistence, security, and usage analytics. A cookie is a small text file stored on the User's device (browser) when visiting the Service.

(2) Categories of cookies used:

Specific cookies and durations:

(Fathom Analytics is cookieless, and Google OAuth/Fonts cookies are set on Google's own domains. Other third-party providers may set additional cookies under names and retention periods they determine; refer to each provider's privacy/cookie policy.)

(3) Data subjects may refuse or delete cookies through browser settings (Chrome, Safari, Edge, etc.) or, for advertising/analytics trackers, the controls described in Section 12. Refusing strictly necessary cookies may prevent normal use of the Service, including login.

15. Security Measures

We implement administrative measures (internal management plan, regular training), technical measures (access control, encryption, access logging, security software), and physical measures to ensure the security of personal data. No method of transmission or storage is 100% secure, but we take commercially reasonable steps to protect user data.

16. Destruction of Personal Data

We destroy personal data without delay when it is no longer necessary, such as upon expiry of the retention period or achievement of the purpose. Electronic files are securely deleted so they cannot be recovered; printed materials are shredded or incinerated.

17. Legal Action and Disclosure

Personal data may be used for legal purposes in court or in the stages leading to possible legal action arising from improper use of the Service. The User acknowledges that we may be required to disclose personal data upon the request of public authorities.

18. Changes to this Policy

We may amend this Privacy Policy at any time by notifying Users on this page and, where feasible, within the Service or by other available contact means. Where changes affect processing based on consent, we will obtain new consent where required. Users are encouraged to review this page periodically, referring to the effective date below.


This Privacy Policy is effective from July 1, 2026.