NewLaunching String Web Access APIRead the manifesto →

Privacy policy

Last updated: Jul 20, 2026

Relativity Labs Inc. d/b/a String (“String,” “we,” “us,” or “our”) provides infrastructure for accessing and working with publicly available web data, including the String Web Access API, the String customer portal, the String MCP server, our managed data services, our websites at usestring.ai and portal.usestring.ai, and any related services we may offer (collectively, the “Services”).

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. It covers customers and visitors who use our Services (“you”), individuals whose personal information may appear in publicly available web pages processed through our Services, and visitors to our websites.

If you do not agree with this policy, please do not use the Services.

1. Information We Collect

Account information. When you create an account we collect account information, which may include your name, email address, company name, and, if you sign in through a supported identity provider (such as Google or Microsoft), the basic profile information that provider shares (name, email, profile picture). We may also collect information you provide during onboarding, such as your intended use case.

Billing information. Payments are processed by Stripe, Inc. Your card number is sent directly to Stripe and stored by Stripe, not by us; we retain your billing contact, transaction history, and the last four digits and brand of your card, which we use for invoicing, tax and accounting compliance, fraud prevention, and resolving billing disputes. Stripe's privacy policy: https://stripe.com/privacy.

Service usage data. We collect API request metadata (endpoints called, target domains, timestamps, response status, credits consumed), authentication logs, and support communications, to operate and secure the service, bill accurately (including not billing blocked requests), enforce our acceptable use policy, and debug problems.

Request content. The Web Access API returns the content of web pages you direct it to fetch. We retain request URLs and returned content only for as long as needed for debugging, abuse prevention, and any features you invoke. We do not sell your request data, we do not share it with other customers, we do not use it for advertising, and we do not use your request URLs or returned content to train machine-learning models.

Website and technical data. Like most websites we collect IP addresses, browser and device type, pages visited, referrers, and timestamps, using cookies and similar technologies. We use PostHog for product analytics. We use Cloudflare Turnstile to protect our websites from bots and abuse; Turnstile evaluates limited browser and device signals to distinguish human visitors from automated traffic, and its use is subject to Cloudflare's Turnstile Privacy Addendum.

Publicly available web data. Our Services access publicly available web pages, which may incidentally contain personal information their publishers have made public. For managed data services, our Web Data Collection Policy (Part I, Section 3) governs what we collect. For the Web Access API, customers direct the requests and are responsible for their own lawful use of the results under our Terms of Service and acceptable use policy; String acts as a service provider processing those requests on the customer's behalf. Section 8 covers the rights of individuals whose information appears in public pages.

2. How We Use Information

To provide, operate, and secure the Services; authenticate you; process payments and prevent fraud; respond to support requests; notify you about service issues, changes, and (unless you opt out) product updates; enforce our Terms and acceptable use policy; comply with law; and understand aggregate usage to improve the product.

We do not sell personal information. We do not use your information for third-party behavioral advertising. We do not train models on customer request content.

3. Legal Bases (GDPR)

Where the EU or UK GDPR applies, we process personal information on these bases: performance of a contract (account, billing, usage data); legitimate interests (security, abuse prevention, product improvement, and processing of publicly available web data, balanced against data-subject rights); legal obligation (tax, accounting, lawful requests); and consent where specifically requested (such as marketing email, withdrawable anytime).

4. Who We Share Information With

Service providers (sub-processors) under confidentiality obligations: the current list is published in our security documentation (Part I, Section 7) and maintained as it changes.

Legal and safety: when required by law, subpoena, or court order, or to detect or prevent fraud, security incidents, or policy violations, or to protect the rights, property, or safety of String, our customers, or the public.

Business transfers: in a merger, acquisition, or sale of assets, personal information may transfer to the successor, which must honor this policy.

With your consent or at your direction.

We do not rent or sell personal information, and we do not share your request data with other customers.

5. Data Retention

We retain account and billing information for as long as you maintain an account, plus periods required for legal, tax, and accounting purposes. Request content is retained only for as long as needed for the purposes described above, then deleted. We do not currently operate a response cache; if caching features are introduced, cached copies will expire automatically at the end of their cache period and will be covered by the same protections as request content. Usage logs are retained as long as needed for security and billing-dispute purposes. On account closure, we delete or de-identify your personal information within a commercially reasonable period, except where law requires longer retention.

6. Security

Data is encrypted in transit with TLS (our API and public web endpoints enforce TLS 1.2 or higher) and at rest using provider-managed encryption (AES-256). We do not store customer passwords or credentials; authentication is delegated to Clerk, our identity provider. Access follows least-privilege principles, automated secret scanning runs in continuous integration on our primary engineering repositories, and infrastructure runs on major cloud providers. SOC 2 Type I and II is underway. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you and the relevant authorities as required by law. Report vulnerabilities to support@usestring.ai with “SECURITY” in the subject line.

7. International Transfers

We are based in the United States and our servers and service providers are primarily located there. If you use the Services from outside the US, your information is transferred to and processed in the US. Where GDPR applies to a transfer, we rely on Standard Contractual Clauses or an adequacy decision.

8. Individuals in Publicly Available Web Data

If you believe personal information about you appearing in publicly available web pages has been processed through our Services and you wish to object, request deletion from our systems, or exercise other rights, contact support@usestring.ai with “PRIVACY” in the subject line and enough detail for us to locate it. Where we hold such information, we will handle your request under applicable law. We cannot remove information from the public websites that publish it; requests about source content should go to the publisher.

9. Your Rights and Choices

Depending on where you live, you may have the right to access, receive a portable copy of, correct, delete, restrict, or object to processing of your personal information (including direct marketing, which we honor for everyone), and to withdraw consent. EU/UK residents may lodge a complaint with their supervisory authority. To exercise any right, email support@usestring.ai with “PRIVACY” in the subject line. We verify identity before acting and respond within legally required timelines. We honor these rights for all users regardless of location. Opt out of marketing email via the unsubscribe link in any message; service and billing notices continue while your account is open.

10. California Residents (CCPA/CPRA Notice)

In the preceding 12 months we have collected: identifiers (name, email, IP address); customer records (billing contact, transaction history); commercial information (products purchased, usage); internet activity; professional information (company, role); and geolocation inferred from IP. Sources: you, your devices, and our service providers. Purposes: as in Section 2. Disclosed for business purposes to the service-provider categories in Section 4.

We do not sell or share personal information as defined by the CCPA/CPRA, and have not in the preceding 12 months. We do not use or disclose sensitive personal information for purposes requiring a right to limit.

California residents may request access (twice per 12 months), deletion, and correction, and may designate an authorized agent, by emailing support@usestring.ai. We verify identity, respond within 45 days (with a permitted extension), and will not discriminate against you for exercising your rights.

11. Cookies and Do Not Track

We use essential cookies for authentication and session management, and analytics cookies to understand product usage. You can refuse cookies in your browser; refusing essential cookies will break sign-in.

12. Children

The Services are not directed at children under 16 and we do not knowingly collect their personal information. If you believe a child provided us personal information, contact support@usestring.ai and we will delete it.

13. Changes to This Policy

We may update this policy as the Services evolve. We will update the “Last Updated” date and, for material changes, give notice on the site or by email before they take effect. We will not reduce your rights without your consent.

14. Contact

Relativity Labs Inc. d/b/a String

Attn: Privacy Officer

651 North Broad Street, Suite 201, Middletown, DE 19709

support@usestring.ai

© 2026 StringBuilt in New York City 🗽 🍎