RELIQ
Privacy Policy
Effective date: 30 June 2026 (early draft)
1. Who we are
Reliq (“Reliq”, “we”, “us”) is a private, developer-oriented “second brain”: a personal memory substrate exposed over the Model Context Protocol (MCP) that AI coding tools (such as Claude Code, Codex, and Cursor) read from and write to on your behalf. Reliq stores, organizes, and retrieves context about you and your work; it is not itself an AI model and does not reason as one. The AI tool you connect supplies the intelligence; Reliq supplies the memory.
The data controller for the personal data described here is Reliq (operated by Wisp), an individual sole operator based in Sweden. The point of contact is email: for privacy questions or to exercise your rights, contact webbywisp@gmail.com.
Reliq is in early development with no public users; contact and operator details may be expanded before any public launch or first paying customer.
2. Data we collect and how
Reliq is built around low-effort, mostly passive capture. The data we hold comes from these sources:
2.1 Coding-session signals (the primary source)
When you install the Reliq plugin and enable its session hooks, the plugin captures a deterministic, minimal session record computed locally from git and the harness. It includes only:
- the repository display name and path, and the current git branch;
- a diff stat (
git diff --stat) and the names of changed files (not their contents); - recent commit subject lines;
- the task / prompt text you yourself wrote to the agent, when the harness makes it available (never the agent’s responses);
- session metadata such as timing, a session identifier, and the harness event that triggered capture.
We do not capture raw file contents, full source code, or full agent transcripts through this path. Token-shaped secret strings (e.g. keys matching sk-…, gh[pousr]_…, AWS AKIA…, and Reliq tokens) are redacted before the record leaves your device. You control which repositories are eligible via a repository allowlist.
2.2 Notes and memories you create
Text you (or an AI agent acting for you) deliberately save — notes, durable decisions, conventions, facts, and pinned memories — written through Reliq’s add_note, remember, and document-ingestion tools.
2.3 Connected sources (only if you connect them)
If you choose to connect them, Reliq also ingests:
- Calendar events — titles, times, locations, organizers, and attendee names/emails — to build episodes and a people graph;
- Contacts — to resolve and enrich the people in your memory;
- GitHub activity — commit and pull-request metadata from repositories you authorize.
These are opt-in per source. We do not connect them unless you do.
2.4 Account and technical data
Account identifiers and authentication data (via OAuth 2.1 and/or Personal Access Tokens), plus operational logs needed to run, secure, and debug the service.
2.5 What we do not collect
Reliq does not ingest health data — health ingestion is out of scope. Reliq does not sell your data and does not use it to train any model of our own (we do not operate one).
3. Why we use your data, and our legal bases
| Purpose | Legal basis (GDPR, where applicable) |
|---|---|
| Provide the core memory service: store, index, and retrieve your context for the AI tools you connect | Performance of a contract (Art. 6(1)(b)) |
| Operate connected sources (calendar, contacts, GitHub) you opt into | Consent (Art. 6(1)(a)) |
| Secure the service, prevent abuse, debug, and maintain reliability | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
You can withdraw consent for any opt-in source at any time (see §8); doing so does not affect processing already carried out.
4. How AI tools connect — and the training nuance
Reliq is accessed through an AI tool that you choose and connect (for example Claude Code, Cursor, or another MCP client). That tool is a third-party you connect — it is your tool, not a sub-processor acting on Reliq’s behalf. When the tool reads from Reliq, the memory we surface flows into that tool’s conversation.
This has a direct consequence for model training that you should weigh:
- When you connect Reliq through a consumer AI surface (e.g. a consumer Claude.ai / Claude Code plan, or a consumer ChatGPT plan), the AI provider may use your conversations — including the memory Reliq surfaces — to train its models, unless you opt out in that provider’s settings.
- When you connect through a commercial, API, or Enterprise surface, that training default generally does not apply under those providers’ terms.
Reliq does not control and is not responsible for how your connected AI tool uses the data once it leaves Reliq. Review the privacy policy of whichever AI tool you connect, and choose your surface (and opt-out settings) accordingly.
5. Sub-processors
| Sub-processor | Purpose |
|---|---|
| Supabase | Database and authentication hosting (Postgres with row-level security) |
| Fly.io | Application/server hosting for the MCP server |
Reliq does not use a third-party embedding or model host; vector embeddings for search are generated without sending your data to an external model provider.
The AI tool you connect (e.g. Anthropic/Claude, OpenAI, Cursor) is not a Reliq sub-processor: it is a third-party you choose and connect. See §4.
6. Retention
- Coding-session records, notes, memories, and connected-source data are retained while your account is active — that persistence is the point of the product.
- You can delete any individual item, or your entire account, at any time (see §8). Deletion cascades across the stored node, its edges, summaries, and embeddings.
- After account deletion (or a deletion request) we remove your data within 30 days, except where we must retain limited records to meet a legal obligation.
- Operational logs are kept briefly for security and debugging, then rotated.
7. Security
- Tenant isolation via Postgres row-level security: every row is keyed to your account and enforced at the database, so application bugs cannot leak data across users.
- Encryption in transit (TLS) and at rest for the database and stored blobs.
- Authentication via OAuth 2.1 (PKCE, audience-bound tokens) and/or Personal Access Tokens; least-privilege scopes gate read vs. write.
- Secret redaction runs on the capture path before data is stored.
- End-to-end encryption and a fully local-only mode are on our roadmap; they are not the current default, and we describe the present state honestly rather than overclaiming.
8. Your rights and how to exercise them
Under the EU General Data Protection Regulation (GDPR), as implemented in Sweden by the Swedish Data Protection Act (dataskyddslagen), you have rights to:
- Access the personal data we hold about you;
- Rectification — correct inaccurate or incomplete data;
- Erasure — delete individual items or your whole account (“right to be forgotten”);
- Data portability — export your data in a structured, machine-readable format (Reliq supports JSON/data export);
- Object to certain processing;
- Restrict certain processing;
- Withdraw consent for any opt-in connected source at any time, without affecting processing carried out before withdrawal;
- Lodge a complaint with a supervisory authority — the competent authority is the Swedish Authority for Privacy Protection (IMY — Integritetsskyddsmyndigheten). (If Reliq serves UK users, the UK GDPR may also apply and you may instead complain to the UK Information Commissioner’s Office.)
To exercise any of these, contact webbywisp@gmail.com. Many actions (delete, export, disconnect a source) are also available directly in the Reliq web dashboard.
9. International transfers
The operator is based in Sweden (EEA), but our sub-processors (Supabase, Fly.io) may host or process data in the United States or other countries outside the EEA. Such transfers require an appropriate safeguard under the GDPR (for example, the EU Standard Contractual Clauses; if we serve UK users, the UK International Data Transfer Addendum may also apply). In practice, your data may be processed on infrastructure (Supabase, Fly.io) that can be located outside Sweden and the EU/EEA.
10. Children
Reliq is not directed at people under 18 and is intended for adults (18+). We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as Reliq evolves. We will post the updated version with a new effective date and, for material changes, take reasonable steps to notify you.
12. Contact
Reliq (operated by Wisp) (individual sole operator, based in Sweden)
webbywisp@gmail.com (email contact)
Data-protection framework for this policy: the EU General Data Protection Regulation (GDPR), as implemented in Sweden by the Swedish Data Protection Act (dataskyddslagen); the supervisory authority is the Swedish Authority for Privacy Protection (IMY). UK GDPR may also apply where Reliq serves UK users.