Privacy policy
What we collect, why, where it lives, and what you can demand of us. Written plainly - the legal points are all here, but you should not need a lawyer to read it.
Last updated: 25 July 2026
Two kinds of data
Your account data - the email address and password you sign up with, your workspace name, your API keys, and your billing record.
Your CRM content - the contacts, companies, deals, activities, pipelines, automations and notes you or your AI agent write into Relm. This is yours. We process it only to run the service for you.
What we collect and why
| Data | Why | How long |
|---|---|---|
| Email and password | Sign-in and account recovery | Until you delete the account |
| API keys | Authenticating your agent's requests | Until revoked - stored only as a SHA-256 hash, never in plain text |
| CRM records you create | The product itself | Until you delete them; test-mode records auto-delete after 7 days |
| Request counts | Quota and billing | Rolling billing periods |
| Payment details | Billing | Held by Stripe, never by us - we do not see your card |
| Site and product analytics | Knowing what to improve | See Analytics |
| Third-party keys you connect (e.g. a Resend key) | Sending email you asked us to send | Until you delete the connection - encrypted at rest with AES-256-GCM |
What we do not do
- We do not train AI models on your data. Not ours, not anyone else's.
- We do not sell your data, and we do not share it for advertising.
- We do not read your CRM content, except when you ask us to for support or where we are legally compelled.
Where your data lives
Your CRM database runs on our own servers in Helsinki, Finland (EU), hosted by Hetzner. Nightly backups are encrypted with GPG AES-256 before they leave the machine, and are stored in Cloudflare R2. Backups are kept 14 days locally and 30 days offsite.
Who else touches it
These are our subprocessors - the only third parties that can hold or process your data:
| Provider | Role | Where |
|---|---|---|
| Hetzner | Server hosting, primary database | Finland (EU) |
| Cloudflare | DNS, CDN, encrypted backup storage, email routing | Global |
| Stripe | Subscription billing and payments | Global |
| PostHog | Product analytics | United States |
| Google Analytics | Marketing-site analytics only | United States |
If you connect your own provider - for example a Resend key so automations can send email - that provider also receives whatever you send through it. That connection is yours: delete it and we stop.
Analytics
We use PostHog on the marketing site and in the dashboard, and Google Analytics on the marketing site only, to see which pages and features people actually use. That covers page views, clicks, and product events such as signing up or minting an API key. It does not include your CRM records. Block both with any standard content blocker if you prefer - the product works exactly the same.
Security
- Passwords are hashed. API keys are stored only as SHA-256 hashes and shown to you once.
- Credentials you connect are encrypted at rest with AES-256-GCM, per workspace.
- All traffic is over HTTPS.
- Webhooks are signed with HMAC-SHA256 so your endpoint can verify a delivery really came from us.
- Webhook targets are restricted to public HTTPS addresses and re-checked at delivery, so they cannot be pointed at internal systems.
- Backups are encrypted before they leave the server.
More detail on the engineering: relmcrm.com/security.
Deleting your data
Records you delete are soft-deleted first, so you can restore them, then removed. Test-mode data is deleted automatically after 7 days. To erase your entire account and everything in it, email [email protected] and we will delete it - including from backups, as those roll off on the schedule above. We will not pretend deletion is instant everywhere: an encrypted backup can hold a copy for up to 30 days before it expires.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict how we process it, and to complain to your data protection authority. Email [email protected] and we will respond within 30 days. We will never charge you for a reasonable request.
Your CRM content is exportable at any time through the same API you put it in with. There is no lock-in and no export fee.
Children
Relm is a business tool and is not directed at anyone under 16.
Changes
If we change this policy materially we will note it in the changelog and update the date at the top. Continuing to use Relm after a change means you accept it.
Who we are
Relm is operated by:
ASP FZE LLC
Sharjah Publishing City Free Zone
Sharjah, United Arab Emirates
[email protected]