Privacy notice
How Relium collects, uses and stores personal data, and what you can ask us to do with it.
Last updated: September 2026
This notice describes personal data. For the technical detail of what Relium reads from your repository and warehouse, see Security and data handling.
Who we are
Relium provides a pre-deployment verification service for data changes at relium.dev and app.relium.dev. This notice covers all three of those hosts and applies to everyone who uses them.
What we collect
Account data
Your name, email address and organisation membership, provided when you sign in. Authentication is handled by Clerk; if you sign in with GitHub or Google, we receive the profile information those providers release for sign-in.
Workspace and configuration data
The organisation name you enter during setup, the repositories you connect, your dbt project configuration, and — if you provide them — the optional role and team size fields. Both optional fields can be left blank and nothing depends on them.
Service data
The compiled dbt manifests your CI submits, the reviews Relium produces from them, and aggregate warehouse metadata where a collector is connected. This is described in full on the security page. It can contain personal data only incidentally — for example, if a column name or a model name in your project happens to identify a person.
Billing data
If you subscribe to a paid plan, Polar acts as merchant of record and collects your billing details directly. Relium receives the subscription status and plan, not your payment method or card number.
Operational logs
Standard server logs for the API and application, kept to operate and secure the service.
What relium.dev itself collects
This marketing website loads no analytics, no advertising pixels and no third-party scripts. It sets no cookies. Your theme preference is stored in your own browser's local storage and never leaves it. That is why there is no cookie banner on this site — there is nothing to consent to.
The application at app.relium.dev does set cookies, because it has to: the session cookie that keeps you signed in, and a CSRF token that protects state-changing requests. Neither is used for tracking or advertising.
Why we use it
- To provide the service — reviewing your changes, publishing decisions, and keeping the review record you can audit later.
- To authenticate you and to check, with GitHub, that you are permitted to perform a governance action.
- To bill you, if you are on a paid plan.
- To operate and secure the service — diagnosing failures, preventing abuse.
- To contact you about the service itself: setup problems, incidents, changes that affect you.
We do not sell personal data, and we do not use your data to train models for anyone else.
Who we share it with
Only the subprocessors listed on the security page — GitHub, Clerk and Polar — each for the purpose stated there, plus our hosting and infrastructure providers. We will disclose data if we are legally required to, and we will tell you unless we are prohibited from doing so.
How long we keep it
- Review records are retained according to your plan: 7 days on Free, 90 days on Starter, and retained on Pro.
- Account and workspace data is kept while your account is open.
- Billing records are kept as long as we are required to keep them for tax and accounting purposes.
Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. We answer requests of that kind within 30 days of receiving them. Relium does not yet publish a contact address for making one.
You can also cut off Relium's access to your code yourself, at any time, without asking us: uninstall the Relium GitHub App from your GitHub organisation. That revokes repository access immediately.
Security
Traffic to relium.dev, app.relium.dev and api.relium.dev is encrypted in transit. Warehouse credentials never reach Relium. The CI token we issue is stored only as a hash. More detail, including the subprocessors that receive data, is on the security page.
Changes to this notice
If we change this notice in a way that materially affects you, we will tell you before it takes effect. The date at the top of this page always reflects the current version.
This notice covers relium.dev, app.relium.dev and api.relium.dev.