Trust & Privacy
This page is maintained by Sprint With RELAY LLC to answer common security and privacy questions about the platform. It describes practices and controls in use today and is not an independent audit, certification, or legal commitment.
Account & authentication
Sign-in is handled through Lovable Cloud's managed authentication. Passwords are hashed and never stored in plaintext. Sessions are bound to your browser and revoked on sign-out. Optional Google sign-in is available where configured.
Hosting & platform
The application runs on Lovable's hosting (Cloudflare edge for the web app and Supabase-managed Postgres for application data). Data in transit uses HTTPS/TLS; data at rest is encrypted by the underlying managed providers. Sprint With RELAY does not operate its own servers.
Mention of platform capabilities does not constitute a certification by those providers or by Lovable.
Data we collect
We store the information you submit to use the product: profile details, resume content, career-path selections, sprint progress, quiz attempts, messages, portfolio links, and store/points activity. We collect basic operational logs for reliability and abuse prevention.
How we use it
Your data is used to deliver features (career paths, modules, the Career Passport, messaging, RELAY Runners), surface relevant suggestions, and operate the service. We do not sell personal data.
Row-level security
Application tables use row-level security policies so that, in general, you can only read and modify your own rows. Admin operations are scoped to verified RELAY admin roles in the database.
Subprocessors & integrations
Lovable (hosting & build), Supabase (database, auth, storage), and Cloudflare (edge network). AI features route through Lovable's AI gateway. If you connect optional third-party services, those providers receive only the data needed for the feature.
Retention & deletion
You can request account deletion from Profile Settings. Deletion requests are reviewed by a Founder or Co-Founder before execution. Backups managed by our hosting providers roll off on their standard schedule.
Privacy requests & security contact
For privacy requests (access, export, deletion) or to report a security issue, email security@sprintwithrelay.com. Please do not include passwords or other secrets in your message.
Changes to this page
We update this page as the product evolves. For specific contractual terms (DPA, custom SLAs, compliance attestations), contact us directly — those are handled outside of this public page.

