Privacy policy
Relativity Labs Inc. d/b/a String (“String,” “we,” “us,” or “our”) provides infrastructure for accessing and working with publicly available web data, including the String Web Access API, the String customer portal, the String MCP server, our managed data services, our websites at usestring.ai and portal.usestring.ai, and any related services we may offer (collectively, the “Services”).
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. It covers customers and visitors who use our Services (“you”), individuals whose personal information may appear in publicly available web pages processed through our Services, and visitors to our websites.
If you do not agree with this policy, please do not use the Services.
1. Information We Collect
Account information. When you create an account we collect account information, which may include your name, email address, company name, and, if you sign in through a supported identity provider (such as Google or Microsoft), the basic profile information that provider shares (name, email, profile picture). We may also collect information you provide during onboarding, such as your intended use case.
Billing information.Payments are processed by Stripe, Inc. Your card number is sent directly to Stripe and stored by Stripe, not by us; we retain your billing contact, transaction history, and the last four digits and brand of your card, which we use for invoicing, tax and accounting compliance, fraud prevention, and resolving billing disputes. Stripe's privacy policy: https://stripe.com/privacy.
Service usage data. We collect API request metadata (endpoints called, target domains, timestamps, response status, credits consumed), authentication logs, and support communications, to operate and secure the service, bill accurately (including not billing blocked requests), enforce our acceptable use policy, and debug problems.
Request content. The Web Access API returns the content of web pages you direct it to fetch. We retain request URLs and returned content only for as long as needed for debugging, abuse prevention, and any features you invoke. We do not sell your request data, we do not share it with other customers, we do not use it for advertising, and we do not use your request URLs or returned content to train machine-learning models.
Website and technical data.Like most websites we collect IP addresses, browser and device type, pages visited, referrers, and timestamps, using cookies and similar technologies. We use PostHog for product analytics, which also records session replays and heatmaps of your interactions with our websites and the customer portal, so we can diagnose problems and understand how features are used. We use Sentry for application error monitoring; when the portal hits an error, Sentry receives that error's technical context, which may include your account identifier and details of the request that failed. We use Cloudflare Turnstile to protect our websites from bots and abuse; Turnstile evaluates limited browser and device signals to distinguish human visitors from automated traffic, and its use is subject to Cloudflare's Turnstile Privacy Addendum.
Browser environment measurement. Our products have to tell real browsers from automated ones, and to do that well we need to know what real browsers actually look like. On our own websites we therefore record a description of the browser and device you are using: your user agent and the matching browser and operating system version, screen size and colour depth, window size and device pixel ratio, reported device memory and CPU core count, touch point count, language settings and time zone. We also record whether a handful of your browser's own built-in functions are still the ones it shipped with, which tells us an extension or a tool has not rewritten them.
This measurement does not read your browsing history, your bookmarks, your location, anything belonging to any other site, or anything stored in your browser by us or by anyone else. It sets no cookie and no identifier of its own, so one measurement cannot be linked to another or back to you. It describes a class of machine, not a person, and many people share an identical description. We keep it to build the browser profiles our products use, we do not sell it, we do not use it for advertising, and we do not combine it with your account. It runs after the page has loaded and does not affect what you see.
Website visitor identification. On usestring.ai, an identity provider may use online identifiers and activity on our site, including pages viewed, referrer, and timestamps, to try to match a visit with business contact information such as a name, employer, job title, work email address, and LinkedIn profile. A match can be wrong. We use these results to evaluate provider accuracy, understand business interest, and support human-reviewed sales follow-up. This feature is limited to eligible United States traffic. It runs by default on those visits and stops as soon as you reject it through Your privacy choices, or if your browser sends Global Privacy Control.
Publicly available web data.Our Services access publicly available web pages, which may incidentally contain personal information their publishers have made public. For managed data services, our Web Data Collection Policy (Part I, Section 3) governs what we collect. For the Web Access API, customers direct the requests and are responsible for their own lawful use of the results under our Terms of Service and acceptable use policy; String acts as a service provider processing those requests on the customer's behalf. Section 8 covers the rights of individuals whose information appears in public pages.
2. How We Use Information
To provide, operate, and secure the Services; authenticate you; process payments and prevent fraud; respond to support requests; notify you about service issues, changes, and (unless you opt out) product updates; enforce our Terms and acceptable use policy; comply with law; understand aggregate usage to improve the product; and, where visitor identification is active, evaluate business interest and conduct human-reviewed sales follow-up.
We do not sell personal information for money or use your information ourselves for third-party behavioral advertising. Section 10 explains why a visitor-identification disclosure may nevertheless count as a sale or sharing under California law. We do not train models on customer request content.
3. Legal Bases (GDPR)
Where the EU or UK GDPR applies, we rely on the legal bases set out below. Each basis is stated against the purpose it covers, using the purposes described in Sections 1 and 2. This section is a notice about how we process personal information. It is not a request for consent to everything described here. Where consent is the basis, we ask for it separately, and you may withdraw it at any time without affecting the lawfulness of processing carried out before you withdrew it.
Performance of a contract. We rely on this basis to create and administer your account, authenticate you to the customer portal, issue and scope API credentials to your organization, provide the Services you request, measure billable usage, process your payments, resolve billing disputes, send you service and billing notices while your account is open, and answer support requests about the Services. Account fields marked required are needed to create or administer an account. If you do not provide them, we cannot provide the related account or Service. Other fields are optional.
Legal obligation. We rely on this basis to keep tax, accounting, and invoicing records for the periods the law requires, to respond to a lawful request from a court or public authority, and to receive, verify, and answer requests to exercise the rights described in Section 9.
Legitimate interests: keeping the Services secure and free from abuse. Our interest is protecting the Services, our websites, our customers’ accounts, and the people who use them against fraud, abuse, and security incidents. On this basis we keep authentication and security logs, detect and investigate security incidents, screen billing activity for fraud, enforce our Terms and acceptable use policy, and run Cloudflare Turnstile bot protection on our websites. We have documented that this processing is necessary for that interest, and we balance it against your rights.
Legitimate interests: diagnosing faults and improving the product. Our interest is understanding how the Services are actually used, so that we can fix faults and improve them. On this basis we run aggregate product analytics, session replay and heatmaps of our websites and the customer portal, and application error monitoring, and we retain request URLs and returned content for the limited debugging periods described in Section 5. We balance this processing against your rights, and you may object to it under Section 9.
Legitimate interests: measuring the browser environment. Our interest is building the browser profiles our anti-bot products depend on. Section 1 describes exactly what this measurement records, what it does not read, and the fact that it sets no identifier and is not combined with your account.
Consent. We rely on consent for marketing email and for product-update email. You may withdraw that consent at any time through the unsubscribe link in any message, or by contacting us under Section 9, and we honor the withdrawal for everyone regardless of location. Service and billing notices are not sent on this basis and continue while your account is open.
Publicly available web data. Our Services access publicly available web pages, which may incidentally contain personal information their publishers have made public. Where the EU or UK GDPR applies to that processing and String is the controller of it, the basis we rely on is our legitimate interest in operating a web-data service and in producing the datasets our customers commission, balanced against the rights of the people concerned. Section 8 explains how a person can object to that processing or ask us to delete information about them from our systems.
Where String acts for a customer. For Web Access API requests that a customer directs, that customer decides the purpose of the processing and the legal basis for it, and String processes the request on the customer’s behalf. Requests about that processing should go to the customer concerned.
Our Article 27 representatives for the EU and the UK are named in Section 14.
4. Who We Share Information With
Service providers (sub-processors) under confidentiality obligations: we maintain a current list of these sub-processors and update it as they change. The current list is available to customers on request via our sub-processors page.
Legal and safety: when required by law, subpoena, or court order, or to detect or prevent fraud, security incidents, or policy violations, or to protect the rights, property, or safety of String, our customers, or the public.
Business transfers: in a merger, acquisition, or sale of assets, personal information may transfer to the successor, which must honor this policy.
With your consent or at your direction.
Visitor-identification providers. Where visitor identification is active, we disclose the online identifiers and usestring.ai activity described in Section 1 to RB2B so it can attempt a business-contact match. We do not use that permission to load a resolver on the customer portal or authenticated product pages.
We do not rent or sell personal information for money, and we do not share your request data with other customers.
5. Data Retention
We retain account and billing information for as long as you maintain an account, plus periods required for legal, tax, and accounting purposes. Request content is retained only for as long as needed for the purposes described above, then deleted. Diagnostic artifacts generated while operating the Services are deleted automatically on fixed schedules: request captures kept for debugging are deleted after 30 days, code-generation logs and extraction-run artifacts after 30 days, and monitoring artifacts after 90 days. We do not currently operate a response cache; if caching features are introduced, cached copies will expire automatically at the end of their cache period and will be covered by the same protections as request content. Usage logs are retained as long as needed for security and billing-dispute purposes. On account closure, we delete or de-identify your personal information within a commercially reasonable period, except where law requires longer retention.
Analytics data has its own fixed windows. Session replays are deleted 30 days after capture. Product analytics events, including the interaction data behind heatmaps, are kept for no more than 12 months. The analytics profile that PostHog holds for a signed-in portal user is deleted, together with that user’s events and recordings, when the account is closed or when we act on an erasure request under Section 9.
Raw visitor-identification exports are deleted within 30 days after a pilot window is scored. We retain the minimum record needed to measure accuracy, suppression, and outcomes for no more than 180 days, unless the person responds, becomes a customer, asks us to retain it, or law requires longer retention. Provider retention may differ under its published terms.
6. Security
Data is encrypted in transit with TLS (our API and public web endpoints enforce TLS 1.2 or higher) and at rest using provider-managed encryption (AES-256). We do not store customer passwords or credentials; authentication is delegated to Clerk, our identity provider. Access follows least-privilege principles, automated secret scanning runs in continuous integration on our primary engineering repositories, and infrastructure runs on major cloud providers. SOC 2 Type I and II is underway. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you and the relevant authorities as required by law. Report vulnerabilities to support@usestring.aiwith “SECURITY” in the subject line.
7. International Transfers
We are based in the United States and our servers and service providers are primarily located there. If you use the Services from outside the US, your information is transferred to and processed in the US. Where GDPR applies to a transfer, we rely on Standard Contractual Clauses or an adequacy decision.
PostHog, which provides the product analytics described in Sections 1 and 11, processes that data in the United States. PostHog is certified under the EU-U.S. Data Privacy Framework, the UK Extension to it, and the Swiss-U.S. Data Privacy Framework. Independently of that certification, our data processing agreement with PostHog incorporates the EU Standard Contractual Clauses (controller-to-processor module) and, for transfers from the United Kingdom, the UK International Data Transfer Addendum to those clauses.
8. Individuals in Publicly Available Web Data
If you believe personal information about you appearing in publicly available web pages has been processed through our Services and you wish to object, request deletion from our systems, or exercise other rights, contact support@usestring.aiwith “PRIVACY” in the subject line and enough detail for us to locate it. Where we hold such information, we will handle your request under applicable law. We cannot remove information from the public websites that publish it; requests about source content should go to the publisher.
9. Your Rights and Choices
Depending on where you live, you may have the right to access, receive a portable copy of, correct, delete, restrict, or object to processing of your personal information (including direct marketing, which we honor for everyone), and to withdraw consent. EU/UK residents may lodge a complaint with their supervisory authority, and may contact our Article 27 representatives, named in Section 14. To exercise any right, email support@usestring.aiwith “PRIVACY” in the subject line. We verify identity before acting and respond within legally required timelines. We honor these rights for all users regardless of location. Opt out of marketing email via the unsubscribe link in any message; service and billing notices continue while your account is open.
10. California Residents (CCPA/CPRA Notice)
In the preceding 12 months we have collected: identifiers (name, email, IP address); customer records (billing contact, transaction history); commercial information (products purchased, usage); internet activity; professional information (company, role); and geolocation inferred from IP. Sources: you, your devices, and our service providers. Purposes: as in Section 2. Disclosed for business purposes to the service-provider categories in Section 4.
We do not receive money for visitor-identification data. California law may nevertheless treat disclosing online identifiers and internet activity to an identity provider as a sale or sharing. California residents can opt out through Your privacy choices or Global Privacy Control. We do not use or disclose sensitive personal information for purposes requiring a right to limit.
California residents may request access (twice per 12 months), deletion, and correction, and may designate an authorized agent, by emailing support@usestring.ai. We verify identity, respond within 45 days (with a permitted extension), and will not discriminate against you for exercising your rights.
11. Cookies, Analytics, and Do Not Track
The portal and our websites work differently. The customer portal at portal.usestring.ai uses essential cookies for authentication and session management; refusing those will break sign-in. The rest of this section describes usestring.ai, which has no sign-in.
Analytics. We use PostHog for product analytics. It records page views and interactions, and it may also record session replays and heatmaps, as described in Section 1.
If you are in the EEA, the United Kingdom, the Crown Dependencies, or Gibraltar, PostHog does not run until you accept it. Nothing analytics-related loads, and no analytics cookie is set, before you choose. Declining takes one click and is as easy as accepting.
If you are elsewhere, analytics runs by default and you can turn it off at any time.
Changing your mind. Use the “Your privacy choices” link in the footer of any page. Analytics and visitor identification have separate controls. We keep those choices in your browser’s local storage under string:analytics-consent and string:visitor-identification-consent. These records are not cookies and are not sent to us.
Visitor identification. This feature is limited to eligible United States traffic and has its own control, separate from analytics. It is on by default on those visits; outside the United States, and where the region cannot be established, it never runs. Global Privacy Control blocks it automatically. A saved rejection stops future provider requests. The provider script cannot read your browser history, bookmarks, or the contents of other sites.
What runs whatever you choose. Cloudflare Turnstile loads only when you interact with a demo or a lead form, to protect that form from automated abuse. The browser-environment measurement runs on our websites; Section 1 describes what it records and why.
Do Not Track. Browsers send Do Not Track signals in different ways and no common standard defines what a site must do with them, so we do not rely on them. The controls above are the ones we honor.
12. Children
The Services are not directed at children under 16 and we do not knowingly collect their personal information. If you believe a child provided us personal information, contact support@usestring.ai and we will delete it.
13. Changes to This Policy
We may update this policy as the Services evolve. We will update the “Last Updated” date and, for material changes, give notice on the site or by email before they take effect. We will not reduce your rights without your consent.
14. EU/EEA & UK GDPR Representatives (Article 27)
If you are located in the EU or UK and have questions or concerns regarding your personal data, you may contact our appointed GDPR representative:
EU Representative. Euverify Ltd (Ireland), Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland. gdpr@euverify.com
UK Representative. Euverify Ltd (UK), 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom. gdpr@euverify.com
To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related inquiry, please use our secure portal at https://gdpr.euverify.com/verify/955f1f5d-be3e-447c-88b5-69fcaa015b98.
This link allows you to verify our appointed representative and submit GDPR requests directly. Requests submitted through this portal are logged and tracked to ensure timely response and compliance.
15. Contact
Relativity Labs Inc. d/b/a String
Attn: Privacy Officer
651 North Broad Street, Suite 201, Middletown, DE 19709
UK representative.Euverify Ltd (UK) is our representative in the United Kingdom under Article 27 of the UK GDPR, for UK data subjects and supervisory authorities. 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom. gdpr@euverify.com
