Relate Privacy Policy
Pixelic, Inc. ("Company", "we", or "Owner") operates Relate, Spread, and Spread AI (collectively, the "Service") and is committed to protecting users' personal data. This Privacy Policy applies to non-Korean users; Korean users are covered by a separate Korean-language Privacy Policy issued by Pixelic Korea, Inc.
This Policy explains what personal data we process, the legal bases for processing, the parties with whom we share data, international transfers, retention, and the rights available to data subjects — including users in the European Economic Area and the United Kingdom (under the GDPR/UK GDPR) and residents of California (under the CCPA/CPRA).
1. Owner and Data Controller
- Owner / Data Controller: Pixelic, Inc.
- Address: 548 Market St. #42341, San Francisco, CA 94104-5401, USA
- Owner contact email: admin@relate.so
- Data Protection Officer: Sangyong Jung — sj@relate.so
- Data protection team: privacy@relate.so
2. Types of Personal Data Collected
We collect the following categories of personal data, by ourselves or through third parties:
| Category | Items |
|---|---|
| Registration / account | Email, first/last name, password, username, profile picture, company name, country, time zone, profession |
| Service usage data | Contact information, email/message content and metadata (sender, recipient, send time, message intent/relevance/importance, etc.) that the Member inputs, connects, or generates |
| Paid Services | Payment information, billing address, purchase history (payment details handled by the payment processor) |
| Automatically collected (Usage Data / Trackers) | IP address, cookies/trackers, usage records, page views, browsing history, device/browser/OS information, universally unique identifier (UUID) |
Unless stated otherwise, the data we request is necessary to provide the Service, and failing to provide it may make it impossible for us to provide the Service. Personal data may be freely provided by the User or, in the case of Usage Data, collected automatically when using the Service.
For third-party personal data (contacts/leads) a Member uploads to the Service, the Member is responsible for securing a lawful basis to collect and use it; in such cases we process the data as a processor acting on the Member's instructions. The Service is intended for business users and is not directed to children; we do not knowingly collect personal data from children under the applicable minimum age.
3. Mode and Place of Processing
We take appropriate technical and organizational security measures to prevent unauthorized access, disclosure, modification, or destruction of data. Processing is carried out using computers and IT-enabled tools, following procedures strictly related to the purposes indicated. Data may be accessible to persons involved in operating the Service (administration, sales, marketing, legal, system administration) or to external parties appointed as data processors (see Sections 6 and 7).
Depending on the User's location, data transfers may involve transferring data to a country other than the User's own. See Section 7 for international transfer details and safeguards.
4. Purposes of Processing
We process personal data to provide the Service, comply with legal obligations, respond to enforcement requests, protect our rights and interests (and those of our Users or third parties), detect malicious or fraudulent activity, and for the following purposes:
- Membership registration and management: identification, authentication, fraud prevention, notices.
- Service provision: CRM/contact management, email sending and workflow automation, AI-powered content generation/summarization/analysis, engagement (open/click) tracking.
- Paid Services and settlement: payments, billing, withdrawal/refund handling.
- Customer support: handling inquiries and complaints and notifying outcomes.
- Service improvement and product development (including aggregated/de-identified analysis).
- Marketing and event information (where consent is obtained).
5. Legal Basis for Processing (GDPR)
For users in the EEA and UK, we process personal data on one or more of the following legal bases under Article 6 GDPR:
- Consent — where the User has given consent for one or more specific purposes (e.g., marketing). Consent may be withdrawn at any time.
- Performance of a contract — where processing is necessary to provide the Service the User has requested or to take pre-contractual steps.
- Legal obligation — where processing is necessary to comply with a legal obligation to which we are subject.
- Legitimate interests — where processing is necessary for our legitimate interests (e.g., securing the Service, preventing fraud, improving features), provided these are not overridden by the User's rights.
We will gladly clarify the specific legal basis that applies, including whether the provision of personal data is a statutory or contractual requirement.
6. Processors and Sub-processors
We delegate processing to the following parties to provide the Service. These services are engaged under data processing agreements that restrict use to our instructions:
| Processor | Delegated work | Place of processing |
|---|---|---|
| Stripe, Inc. | Payment processing and settlement | USA |
| Nylas, Inc. | Email/calendar integration and backend infrastructure | USA |
| Twilio Inc. (SendGrid) | Email sending | USA |
| Mailgun Technologies, Inc. | Email sending | USA |
| Google LLC | Google OAuth authentication, Gmail API integration, Google Fonts | USA |
| OpenAI, L.L.C. | AI-based content generation/summarization | USA |
| Anthropic, PBC | AI model (Claude) processing and MCP integration | USA |
| Conva Ventures Inc. (Fathom Analytics) | Anonymized usage analytics | Canada |
| Twilio, Inc. (Segment) | Tag/event management | USA |
| Cloudflare, Inc. | Traffic optimization and content delivery (CDN) | USA |
| Meta Platforms, Inc. | Advertising and conversion measurement (Meta Pixel / Conversions API) | USA |
When entering into processing agreements, we specify, as required by applicable law, restrictions on processing beyond purpose, security measures, limits on re-delegation, supervision of the processor, and liability. Changes to processors are disclosed through this Policy.
7. International Transfers of Personal Data
We transfer personal data to the recipients below. Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) (and the UK Addendum) or an applicable adequacy decision.
| Recipient | Country | Items transferred | Purpose | Retention | Contact |
|---|---|---|---|---|---|
| Stripe, Inc. | USA | Name, email, billing address, payment/purchase info, trackers, usage data | Payment/settlement | Until end of agreement | privacy@stripe.com |
| Nylas, Inc. | USA | Name, email, contact info, email/message content & metadata, phone, picture | Email/calendar integration | Until end of agreement | privacy@nylas.com |
| Twilio Inc. (SendGrid) | USA | Name, email, company, country, phone, username, usage data | Email sending | Until end of agreement | privacy@twilio.com |
| Mailgun Technologies, Inc. | USA | Name, email, country, phone, profession, usage data | Email sending | Until end of agreement | dpo@sinch.com |
| Google LLC | USA | Auth info, Gmail metadata/content (Member-authorized scope), trackers, usage data | Auth / Gmail integration / fonts | Until end of agreement | googlekrsupport@google.com |
| OpenAI, L.L.C. | USA | Data entered during use, trackers, usage data | AI processing | Until end of agreement | privacy@openai.com |
| Anthropic, PBC | USA | Data entered during use; data the Member sends via MCP integration | AI (Claude) processing / MCP | Until end of agreement | privacy@anthropic.com |
| Conva Ventures Inc. (Fathom) | Canada | Trackers, usage data (anonymized) | Usage analytics | Until end of agreement | support@usefathom.com |
| Twilio, Inc. (Segment) | USA | Trackers, usage data | Tag/event management | Until end of agreement | privacy@twilio.com |
| Cloudflare, Inc. | USA | Trackers, communication data | Traffic optimization / CDN | Until end of agreement | dpo@cloudflare.com |
| Meta Platforms, Inc. | USA | Hashed email, IP address, user agent, Meta cookies (_fbp/_fbc), event data (page view, sign-up, subscription value) |
Advertising / conversion measurement | Until end of agreement | privacy@meta.com |
Data subjects may object to or refuse cross-border transfer; refusal may restrict all or part of the Service relying on that processing. To do so, contact us at the address in Section 11.
8. Retention
Unless stated otherwise, personal data is processed and stored for as long as necessary for the purpose for which it was collected, and may be retained longer where required by a legal obligation or based on the User's consent. In particular:
- Account information is retained until membership withdrawal, except where an investigation of a legal violation is ongoing, in which case until its conclusion.
- Data processed to perform a contract is retained until the contract has been fully performed.
- Where applicable law requires longer retention — for example, records relating to contracts, withdrawal of subscription, payments and supply of goods, consumer complaints or disputes, and access logs — we retain the relevant records for the period required by such law.
Once the retention period expires, personal data is deleted; the rights of access, erasure, rectification, and portability cannot be enforced after expiry.
9. AI Features and MCP Integration
(1) We provide AI-powered features that generate, summarize, or analyze content at the Member's request, processed via the AI processors in Sections 6–7. AI features operate solely as user-facing tools; the Member is responsible for verifying AI-generated output.
(2) When a Member activates MCP (Model Context Protocol) or external integrations, the Member's data may be transmitted to the external tools, data sources, or AI model providers the Member selects. Such integration occurs only upon explicit activation, and processing by the external service is governed by that provider's privacy policy.
(3) We may use aggregated and de-identified information to improve our systems. We do not use Google user data obtained through Google APIs to develop, improve, or train generalized AI or machine-learning models (see Section 10).
10. Google API Services User Data Policy — Limited Use
Where a Member enables Google integration (e.g., Gmail sync/send), we may access, through authorized Google APIs: Gmail message metadata (sender, recipient, subject, timestamps) and Gmail message content within the scope the Member authorizes for sending/synchronization. We process Google user data only to: send Member-authorized email, synchronize communication threads, render per-recipient email, provide engagement (open/click) tracking, and display communication history within the Service.
Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide user-facing functionality.
- Google user data is not used to develop, improve, or train generalized AI or machine-learning models.
- Google user data is not used for advertising and is not sold.
- Google user data is not transferred to third parties except as necessary to provide the Service.
- We do not permanently store Gmail message bodies; we process them transiently only as necessary to provide the Service and do not transfer Gmail message content to third-party email-delivery providers.
- Members may disconnect their Google account at any time. Upon account deletion or revocation, we cease accessing new Google user data and delete associated stored data within a reasonable period, except where retention is required by law.
- The
https://mail.google.com/scope is used only to (i) authenticate SMTP sending via OAuth 2.0 (XOAUTH2) to deliver individualized, per-recipient messages with Member-configured tracking links and accurate delivery/engagement tracking, and (ii) permanently delete email threads that the Member explicitly selects (via the Gmail APIthreads.deletemethod, bypassing Trash, with explicit confirmation and available only to the mailbox owner). Access is limited to functionality the Member explicitly enables.
We apply technical and organizational safeguards to Google user data, including encryption in transit and at rest, role-based access controls, and access logging.
11. Rights of Data Subjects (GDPR)
To the extent permitted by law, Users may exercise the following rights regarding their personal data:
- Withdraw consent at any time, where processing is based on consent.
- Object to processing carried out on a legal basis other than consent, including processing for direct marketing, which Users may object to at any time, free of charge.
- Access their data and obtain a copy of the data undergoing processing.
- Rectify inaccurate or incomplete data.
- Restrict processing of their data.
- Erase their data ("right to be forgotten").
- Data portability — receive their data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
- Lodge a complaint with their competent supervisory/data-protection authority.
How to exercise: Requests may be directed to us via the contacts in Section 1. Requests are free of charge and answered as early as possible and always within one month, as required by law. An agent acting on a data subject's behalf must provide appropriate authorization.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) provides the following rights:
- Right to know / access — request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to delete — request deletion of personal information we collected, subject to legal exceptions.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell personal information for money. However, our use of advertising/analytics trackers (e.g., Meta Pixel) may constitute "sharing" for cross-context behavioral advertising under the CPRA. You may opt out via the cookie/tracker controls in Section 14 or your browser's Global Privacy Control (GPC) signal, which we honor.
- Right to limit use of sensitive personal information — to the extent we process any sensitive personal information, you may request that we limit its use to permitted purposes.
- Right to non-discrimination — we will not discriminate against you for exercising any of these rights.
How to exercise: Submit a request to privacy@relate.so. We will verify your request and respond within the timeframes required by the CCPA. You may use an authorized agent, subject to verification. We do not knowingly sell or share the personal information of consumers under 16 years of age.
13. Service Linkage (Relate · Disquiet)
(1) Separately from Relate, Disquiet — an IT/maker community service — is operated by Pixelic Korea, Inc. Relate and Disquiet are independent services.
(2) Creating a Relate account alone does not create a Disquiet account. Where a user separately registers for Disquiet, account linkage and the processing of personal data in that service are governed by that service's (Korean-language) privacy policy.
14. Cookies and Tracking
(1) We use cookies and other trackers for login persistence, security, and usage analytics. A cookie is a small text file stored on the User's device (browser) when visiting the Service.
(2) Categories of cookies used:
| Type | Purpose | Example providers |
|---|---|---|
| Strictly necessary | Login/session persistence, security, core functionality (the Service cannot function if refused) | Company's own; Cloudflare (security/CDN); Google OAuth (authentication) |
| Analytics | Usage statistics to improve the Service | Fathom Analytics; Segment |
| Functional | Content display and convenience (e.g., fonts) | Google Fonts |
| Advertising | Conversion and ad measurement | Meta (Facebook Pixel) |
Specific cookies and durations:
| Cookie | Provider | Purpose | Retention |
|---|---|---|---|
_session_id |
First-party | Login/session persistence | 1 month |
actors |
First-party | Engagement (open/click) attribution | 2 years |
theme-preference |
First-party | UI theme preference | 1 year |
__cf_bm |
Cloudflare | Bot mitigation / security | 30 minutes |
ajs_anonymous_id, ajs_user_id |
Segment | Analytics (event/identity) | 1 year |
_fbp, _fbc |
Meta | Advertising / conversion measurement | 3 months |
(Fathom Analytics is cookieless, and Google OAuth/Fonts cookies are set on Google's own domains. Other third-party providers may set additional cookies under names and retention periods they determine; refer to each provider's privacy/cookie policy.)
(3) Data subjects may refuse or delete cookies through browser settings (Chrome, Safari, Edge, etc.) or, for advertising/analytics trackers, the controls described in Section 12. Refusing strictly necessary cookies may prevent normal use of the Service, including login.
15. Security Measures
We implement administrative measures (internal management plan, regular training), technical measures (access control, encryption, access logging, security software), and physical measures to ensure the security of personal data. No method of transmission or storage is 100% secure, but we take commercially reasonable steps to protect user data.
16. Destruction of Personal Data
We destroy personal data without delay when it is no longer necessary, such as upon expiry of the retention period or achievement of the purpose. Electronic files are securely deleted so they cannot be recovered; printed materials are shredded or incinerated.
17. Legal Action and Disclosure
Personal data may be used for legal purposes in court or in the stages leading to possible legal action arising from improper use of the Service. The User acknowledges that we may be required to disclose personal data upon the request of public authorities.
18. Changes to this Policy
We may amend this Privacy Policy at any time by notifying Users on this page and, where feasible, within the Service or by other available contact means. Where changes affect processing based on consent, we will obtain new consent where required. Users are encouraged to review this page periodically, referring to the effective date below.
This Privacy Policy is effective from July 1, 2026.