Privacy Policy
How ZEBRABYTE LIMITED processes personal data when you use Captain Relay.
1. Scope and controller
This Privacy Policy applies to Captain Relay websites, applications, APIs, the Captain Relay Agent, the remote MCP service, support interactions and related service operations. ZEBRABYTE LIMITED is the controller for account administration, authentication, service security, billing, support, abuse prevention and our own business operations. Where a business customer instructs Captain Relay to process content from customer-controlled systems solely on that customer's behalf, ZEBRABYTE LIMITED may act as processor under the applicable Data Processing Agreement.
2. Data we process
- Account and identity data: name, email address, account identifiers, organisation membership, authentication/session metadata and security settings.
- Device data: device name, hostname, operating-system/platform details, architecture, agent version, enrolment/revocation state, connectivity and last-seen timestamps.
- Remote execution data: requested capability/tool, policy decision, approval lifecycle, job identifiers, inputs, outputs, errors, timestamps and audit metadata needed to perform or evidence the requested action.
- Computer-use content: screen captures, window metadata and input events only where those capabilities are explicitly invoked.
- Usage and security telemetry: request identifiers, IP/security events, product usage quantities, error information and abuse indicators needed to operate and secure the service.
- Billing data: billing contact information, customer/subscription/invoice identifiers and payment status. Raw card credentials are handled by our payment processor rather than intentionally stored by Captain Relay application servers.
- Support data: communications and information you provide when requesting help or reporting a security/privacy issue.
- Managed app connection data: connected service/toolkit, account alias or identifier, OAuth authorisation state, connection status and the minimum metadata needed to manage the connection.
- Connected-app action and event data: data sent to or returned from an app when Captain executes an action you request, plus authorised event/webhook metadata used to trigger Automations.
3. How we use personal data
We process personal data to provide Captain Relay; authenticate users; verify ownership and authorisation; enrol and manage devices; evaluate policies; request human approvals; execute and audit requested remote actions; provide AI and automation features; prevent fraud and abuse; investigate incidents; provide support; administer billing; meet legal obligations; and maintain reliability and security. If you enable Managed Apps, we also process connection/authentication state and route the data necessary to discover or execute the app actions and events you authorise.
4. Legal bases
Depending on the activity and jurisdiction, we rely on performance of a contract, legitimate interests in operating and securing Captain Relay, compliance with legal obligations, and consent where the law requires it. Customer-controlled content processed solely on behalf of a business customer is handled under that customer's documented instructions and the applicable DPA.
5. AI clients and recipients chosen by you
Captain Relay is designed to return requested results to the AI client or application that you choose to connect. That external client may process the information under its own terms and privacy policy. You should connect only clients you trust and request only the minimum information necessary for your task. Captain Relay does not treat a user-selected external AI client as part of ZEBRABYTE LIMITED merely because you connect it to Captain Relay.
6. Service providers and subprocessors
We use selected providers for infrastructure, identity, payment processing, managed app connectivity, communications, monitoring and other service functions. Where they process personal data on our behalf, we put appropriate contractual and security measures in place. The current public list is maintained at Subprocessors. When you connect a destination service such as Google, Microsoft, Slack, GitHub or Notion, data exchanged with that service is also governed by your relationship with that service and its own terms and privacy practices. We do not sell personal data.
7. International transfers
Where personal data is transferred from the United Kingdom or another protected jurisdiction to a country that does not benefit from an applicable adequacy decision, we use an appropriate transfer mechanism and assess supplementary safeguards where required.
8. Retention
We retain data only for as long as reasonably necessary for the relevant purpose, contractual obligations, security and audit needs, legal requirements and dispute handling. Sensitive remote-content categories are intended to have shorter retention than core account/security records. Disconnecting a Managed App stops Captain Relay from using that connected account and initiates removal of the managed connection. Tool-call and event metadata may remain for the applicable security, audit or service-provider retention period. Exact production retention periods may vary by category, plan and customer agreement, subject to legal requirements.
9. Security
Captain Relay uses authenticated access, account and device scoping, revocation, server-enforced execution policies, human approval paths for sensitive actions, audit records and security monitoring. We also apply data minimisation and access controls appropriate to the service. No internet-connected service can guarantee absolute security.
10. Your choices and rights
Subject to applicable law, you may have rights to access, correct, delete, restrict or port personal data, object to certain processing and withdraw consent where processing is based on consent. Business-customer end users may need to exercise certain rights through the organisation that controls their account or content. We may need to verify identity before fulfilling a request.
11. Cookies and browser storage
Captain Relay uses storage necessary for authentication, security and product operation. Non-essential analytics or marketing technologies, if enabled, are subject to the requirements described in our Cookie Policy.
12. Children
Captain Relay is not intended for children and should not be used by anyone who lacks legal capacity to enter into the relevant agreement or whose use is prohibited by applicable law.
13. Complaints
You may contact us first so we can address your concern. You also have the right to complain to the UK Information Commissioner's Office where UK data-protection law applies.
14. Changes
We may update this Policy to reflect product, legal or operational changes. The current version and its revision date will be published on this page.
15. Contact
Privacy and legal enquiries: legal@zebrabyte.co.uk.