← Home

Privacy policy

What we collect, why, where it lives, and what you can demand of us. Written plainly - the legal points are all here, but you should not need a lawyer to read it.

Last updated: 25 July 2026

Two kinds of data

Your account data - the email address and password you sign up with, your workspace name, your API keys, and your billing record.

Your CRM content - the contacts, companies, deals, activities, pipelines, automations and notes you or your AI agent write into Relm. This is yours. We process it only to run the service for you.

What we collect and why

DataWhyHow long
Email and passwordSign-in and account recoveryUntil you delete the account
API keysAuthenticating your agent's requestsUntil revoked - stored only as a SHA-256 hash, never in plain text
CRM records you createThe product itselfUntil you delete them; test-mode records auto-delete after 7 days
Request countsQuota and billingRolling billing periods
Payment detailsBillingHeld by Stripe, never by us - we do not see your card
Site and product analyticsKnowing what to improveSee Analytics
Third-party keys you connect (e.g. a Resend key)Sending email you asked us to sendUntil you delete the connection - encrypted at rest with AES-256-GCM

What we do not do

Where your data lives

Your CRM database runs on our own servers in Helsinki, Finland (EU), hosted by Hetzner. Nightly backups are encrypted with GPG AES-256 before they leave the machine, and are stored in Cloudflare R2. Backups are kept 14 days locally and 30 days offsite.

Who else touches it

These are our subprocessors - the only third parties that can hold or process your data:

ProviderRoleWhere
HetznerServer hosting, primary databaseFinland (EU)
CloudflareDNS, CDN, encrypted backup storage, email routingGlobal
StripeSubscription billing and paymentsGlobal
PostHogProduct analyticsUnited States
Google AnalyticsMarketing-site analytics onlyUnited States

If you connect your own provider - for example a Resend key so automations can send email - that provider also receives whatever you send through it. That connection is yours: delete it and we stop.

Analytics

We use PostHog on the marketing site and in the dashboard, and Google Analytics on the marketing site only, to see which pages and features people actually use. That covers page views, clicks, and product events such as signing up or minting an API key. It does not include your CRM records. Block both with any standard content blocker if you prefer - the product works exactly the same.

Security

More detail on the engineering: relmcrm.com/security.

Deleting your data

Records you delete are soft-deleted first, so you can restore them, then removed. Test-mode data is deleted automatically after 7 days. To erase your entire account and everything in it, email [email protected] and we will delete it - including from backups, as those roll off on the schedule above. We will not pretend deletion is instant everywhere: an encrypted backup can hold a copy for up to 30 days before it expires.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict how we process it, and to complain to your data protection authority. Email [email protected] and we will respond within 30 days. We will never charge you for a reasonable request.

Your CRM content is exportable at any time through the same API you put it in with. There is no lock-in and no export fee.

Children

Relm is a business tool and is not directed at anyone under 16.

Changes

If we change this policy materially we will note it in the changelog and update the date at the top. Continuing to use Relm after a change means you accept it.

Who we are

Relm is operated by:

ASP FZE LLC
Sharjah Publishing City Free Zone
Sharjah, United Arab Emirates
[email protected]

Something here unclear?

Email [email protected] - a human answers.

Start free →