Privacy Policy
What we store, and what we can never see.
Last updated & effective: 18 July 2026
The Last Relay is an encrypted dead-man’s switch operated by Unthinking AI, LLC (“we”, “us”). This policy explains, in plain language, exactly what we hold about you, what we have deliberately built ourselves out of being able to read, and who else touches your data.
The one thing to know
Your capsule’s contents — your message and your files — are encrypted on your device before they ever reach us. We store only ciphertext. We never receive your encryption keys or your recipients’ unlock phrases, so we cannot read your capsule — and a breach of our servers, or a demand that we hand data over, can yield only that ciphertext and the metadata described below.
On this page
01 What we store
- Account & identity. Your email address(es) and their verification status, and your passkey credentials (WebAuthn public keys and credential identifiers). We never store passwords — sign-in is passkey-only. We also keep a small record of your acceptance of the Terms of Use: the email you signed up with, the version you accepted, and when.
- Capsule ciphertext. The sealed capsule — your message and files — as an opaque encrypted container. It is encrypted with XChaCha20-Poly1305, and the key that unlocks it is itself wrapped with a key derived (via Argon2id) from a phrase we never receive.
- Routing & delivery data. The email addresses of the recipients and the trusted contact(s) you designate, a per-recipient identifier, and any optional display name or note you choose to include in an invitation. We need these to deliver invitations, reachability checks, and the capsule itself. When a contact or recipient accepts their role, opts into escalation calls, or opens a released capsule, we also keep a small acceptance record — their email, the role, the document or disclosure version shown, and the date — which is retained like the owner’s Terms-acceptance record (see Section 6).
- Trusted-contact phone number (optional). If a trusted contact chooses to add their phone number for escalation calls, we store the number they provide and, when they answer, the answer they gave — a keypad digit or a recognized yes/no — in the capsule’s activity log, exactly as if it had been given by email. We do not record call audio, and we do not keep our own per-call attempt or outcome records — an unanswered call is simply retried at the next reminder. Our telephony provider generates call-detail records (numbers, timestamps, durations) as part of placing the calls; see Section 4.
- Capsule configuration & state. Your check-in schedule, countdown and threshold settings, your release policy, and the current lifecycle state (draft, armed, overdue, in verification, released, deleted, and so on).
- Incapacity answer (only if you enable it). If you turn on the optional incapacity feature, and your trusted contact answers that you are “alive but unable to respond,” we store that answer. Because it relates to your physical condition we treat it as consumer health data and cover it in a separate Consumer Health Data Privacy Notice, with its own opt-in consent and withdrawal rights. It is off unless you enable it.
- Activity log. An append-only, timestamped record of the events that drive your switch — check-ins, arming, contact responses, releases, deletions. This is how the switch works, and it doubles as your audit trail.
- Technical logs. Ordinary server and security logs (such as IP address, timestamp, and user agent), kept transiently for security, abuse prevention, and debugging.
02 What we deliberately can’t see
By design, our servers never receive — and the data we store cannot yield — any of the following:
- The plaintext of your message or files. They are encrypted on your device before upload.
- Your encryption keys, in any usable or unwrapped form.
- Your recipients’ unlock phrases. Each recipient’s six-word phrase is generated and stored on your device so you can hand it over — on a card, or in person. It is never sent to or stored by our servers.
The practical consequence: nothing we store can be used — by us, or by anyone who obtains what we store — to read, recover, or reconstruct the readable contents of any capsule. We cannot decrypt a capsule for you, for a recipient who lost their phrase, or for anyone who compels us to produce what we hold.
03 How we use what we store
- To operate the switch: track your check-ins, run countdowns, ask your trusted contact whether they can reach you, and deliver the capsule to your recipients under the conditions you set.
- To communicate: send verification, check-in, invitation, reachability, security-notice, and release emails.
- To keep it safe: detect abuse, prevent fraud, and diagnose problems.
We do not sell your data, share it for advertising, or build behavioural profiles. There is no ad tech here.
Do Not Track & Global Privacy Control. We do not track you across third-party websites or services and we host no advertising or cross-site trackers, so there is no cross-site tracking to turn off. Because of that, our sites do not respond differently to browser “Do Not Track” (DNT) or Global Privacy Control (GPC) signals — there is nothing for them to disable. We disclose this in line with California Business & Professions Code § 22575.
04 Who else touches the data
We rely on a small set of infrastructure providers. Vercel, Neon, Resend, and Twilio act as our service providers, handling data to provide the specific functions below:
- Vercel — hosting, serverless functions, encrypted blob storage, and scheduled jobs.
- Neon — the PostgreSQL database that holds account, routing, configuration, state, and log data.
- Resend — delivery of our transactional email. Resend processes each message in full: the recipient address, the subject, and the complete message body — which can include a display name or personal note you chose to put in an invitation, and the signed action links our emails carry.
- Twilio — escalation calls to trusted contacts who opted in: placing the automated call, recognizing the spoken or keypad answer, and the call-detail records telephony requires. Twilio processes the contact’s number and spoken response only to place and complete these calls.
Apple supports passkey (WebAuthn) and associated-domain verification, and — if we offer paid subscriptions through the App Store — handles billing. Apple acts under its own privacy policy for those functions, not solely on our instructions.
Ciphertext stored with these providers stays ciphertext. None of them can read your capsule either.
05 Email
Every message we send is transactional — there is no marketing list to join or leave. Security-sensitive actions, such as a check-in or a sign-in, trigger a notice to all of your verified addresses, so you always know when your switch has been touched. The only phone calls we ever place are the automated escalation calls a trusted contact opted into — never marketing.
06 Retention & deletion
- Draft content — your plaintext message, files, and generated phrases — stays on your device until you arm your capsule; only then is ciphertext uploaded. The app stores the draft with iOS file protection, keeps the draft file out of iCloud and device backups, and deletes it after you arm (or when you reset the draft). Backups your device made before this exclusion existed are not retroactively changed.
- You can delete your capsule at any time. Deletion is subject to a safety cooldown and a fresh passkey confirmation — so that no one can silently destroy your switch. After the cooldown, the ciphertext and its wrapped keys are erased. If a final countdown completes before the cooldown ends, the release proceeds and the pending deletion is canceled — cancel the countdown by checking in if you want the deletion to complete instead.
- You can delete your entire account from within the app. If nothing is armed, your account, passkey, email addresses, and any capsule are erased immediately. If a capsule is armed, deletion enters the same cancelable 7-day security window — which exists so that no one can force you to destroy your switch under duress — after which the capsule is destroyed, never released, and your account and all its data are erased — with one disclosed exception: we retain acceptance records — your Terms acceptance (the signup email, the version, and the date), and the equivalent records of contacts and recipients who accepted a role, opted into calls, or opened a released capsule — for as long as necessary to establish or defend legal claims. Nothing in those records can decrypt anything.
- After a capsule is released and every recipient confirms they have downloaded it, the ciphertext is erased from our servers shortly afterward. If a recipient never confirms, the ciphertext is still erased on a schedule: 60 days after release, extended by recipient activity, and never later than 180 days after release. One earlier ending is possible and deliberate: the owner can delete their account after a release, which immediately and permanently erases any capsule file not yet downloaded — it is the only way a living owner can contain a release that should not have happened.
- If your subscription lapses while a capsule is armed, the capsule is destroyed — never released — after the 180-day grace period and 30-day final warning described in our Terms of Use.
- Once a recipient downloads and decrypts a capsule onto their own device, those files are theirs. We cannot retrieve, revoke, or delete copies that have left our system.
- Routing data and logs are kept only as long as needed to operate your switch and to meet security and legal obligations, then deleted.
07 Your choices & rights
- View and adjust your account, capsule configuration, recipients, and contacts in the app.
- Delete your account from within the app at any time (Settings → Delete account) — immediately when nothing is armed, or after the cancelable 7-day security window when a capsule is armed.
- Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, port, or erase the personal data we hold about you. Contact us to exercise them. Where a capsule is armed, we complete an erasure request through the same 7-day security window — a short, disclosed delay that protects you from a coerced deletion — and confirm when it is done. Erasure does not extend to the Terms-acceptance record described in Sections 1 and 6, which we retain to establish or defend legal claims. Note that we cannot produce the readable contents of a capsule, because we do not have them.
- If someone else named you. Recipients and trusted contacts never create accounts, but you have choices too: a recipient may ask us to remove their address from a capsule’s routing, and a trusted contact may step down from the role, or remove their phone number, at any time — email info@ai-created.com from the address the invitation was sent to. We honor these requests and notify the owner so they can designate someone else. Revoking consent to phone calls takes effect immediately and is independent of stepping down from the role. Removal does not erase the acceptance record described in Sections 1 and 6, which we retain to establish or defend legal claims.
08 Security
End-to-end encryption, passkey-only authentication, private storage reached through short-lived signed links, and security notices on sensitive actions. No system is perfectly secure, but the architecture is built so that a breach of our servers exposes ciphertext and routing metadata — never the contents of a capsule.
09 Legal requests
Because capsule contents are end-to-end encrypted and we hold neither your keys nor your recipients’ phrases, the most we can ever produce in response to a lawful request is ciphertext and metadata — account and routing information, timestamps, and logs. We cannot decrypt a capsule for anyone. How we handle legal process is described in our Terms of Use.
10 Children
The Last Relay is not intended for anyone under 18, and we do not knowingly collect data from children.
11 International processing
Your data may be processed in the United States and in other countries where our providers operate. Wherever it is processed, the encryption model is the same.
12 Changes to this policy
We may update this policy from time to time. We will revise the date at the top, and for material changes we will make a reasonable effort to notify you.
13 Contact
Questions about privacy? Email info@ai-created.com.