ohttp.io
Legal

Privacy policy.

The full legal text is being finalized. The short version below is complete and accurate, and it's short because of how the relay works: most of what privacy law regulates never touches us.


In transit

What the relay sees.

When a request passes through the relay we see your IP address for the duration of the connection, the hostname of the gateway we forward to, and ciphertext. Request and response bodies are end-to-end encrypted to the gateway with HPKE, so their contents are never visible to us.

When the request completes, all of it is discarded: no client IP addresses, no connection metadata, no timing records, no logs. There is nothing retained to subpoena, breach, or mine.


At rest

What we store.

The only personal data we retain is your account and billing record: the details you give us at signup and the invoices we issue. For customers, we process that limited metadata as a data processor acting on your instructions.

Aggregate usage counters (requests and bytes per account, for enforcing plan limits) are kept, but they are counts, not content, and are never linked back to the clients behind your gateway.


By design

What we never have.

We never see plaintext request or response payloads. We never operate both ends of a customer's flow, so we can never hold both "who is asking" and "what is being asked" for the same traffic.

Questions, access or deletion requests: [email protected].