Press S to start or stop slow automatic scrolling. Press Escape to stop.
← Relentless

Privacy, from the start.

Understand what happens when you visit this website, contact us or connect a website to Relentless.

Draft for review · 16 September 2026. The website behaviour below describes the current homepage implementation. The product process describes requirements for service activation, not a claim that customer capture is already operating.

Who operates Relentless

Relentless is operated by SENTRY AI LLC, a Florida limited liability company in the United States. Its registered company and approved public business and postal address is 7901 4th St N # 22469, St. Petersburg, FL 33702.

When you visit this website

The homepage does not include advertising trackers, analytics collection or session replay in the current implementation. We plan limited, optional public-page analytics after a separate notice and consent setup. The initial scope excludes form entries, tax or other protected information and all session replay. Account sign-in is a separate, optional setup flow. Copying the installation instruction writes that text to your clipboard; it does not connect your agent, install software or submit website data to Relentless. Copy feedback stays in the page and resets when you reload.

The site is hosted on Render. Hosting infrastructure may process technical request information, such as IP address, requested URL, browser information and timestamps, to serve and secure the site. Hosting log fields and retention must be confirmed before this notice is final. Do not put secrets or personal information in page URLs.

When you sign in or add a website

Where account setup is enabled, you can use a configured sign-in provider or enter an email address to request a sign-in link. Supabase handles authentication; configured email delivery uses Resend. These services receive the information needed for that request. The setup screen does not receive provider access tokens or read the secure sign-in cookies.

The account service stores account identifiers, sign-in and revocation records, workspace membership and website addresses you register. Necessary secure cookies bind a sign-in attempt to this browser and keep you signed in. Adding a website does not install tracking code, verify consent or authorise visitor collection. The separate walkthrough uses example websites whose changes reset on reload.

This describes the account implementation prepared for review. Hosted account availability, final processing terms, retention and deletion arrangements must be confirmed before service activation.

When you contact us

The Contact link opens your email application. If you send a message, your email provider and the receiving email service handle your address, message and any attachments. We use correspondence to respond to your enquiry. Please do not email credentials, payment details or raw visitor data. Sending an enquiry is not permission to add you to marketing email.

Who controls visitor privacy choices

The website owner is responsible for its visitor-facing privacy and consent content and determining applicable regimes, including UK and EEA requirements. Relentless connects to the client-approved consent signal rather than adding its own legal copy or a second banner. Relentless remains responsible for its agreed processor duties, security and handling of data on client instructions.

How website capture is intended to work

  1. Agree the scope. Identify the website, authorised users, collection purpose and permitted data before enabling capture. Running our installation prompt in an agent authorised to access your codebase authorises preparation of the requested integration and pull request. It does not establish visitor consent or authorise activation.
  2. Check consent and exclusions. Honour supported consent signals and exclude sensitive routes. Hold nonessential capture when the permitted collection state is unknown.
  3. Exclude before collection. Initial analytics uses only approved non-form events on reviewed public pages. It must not collect form contents or form-interaction data, tax or other protected information, page text, DOM snapshots or session replay. Masking is an extra safeguard, not a substitute for exclusion. Validate incoming events again before storing them.
  4. Restrict access. Keep evidence scoped to the correct site and workspace. Grant agents and optional integrations only the permissions needed for the authorised task. Do not create a cross-site identity graph.
  5. Limit retention and honour withdrawal. Define retention separately for events, reports, account records, logs and backups. Stop future capture after consent withdrawal and apply the agreed deletion process to controlled copies and derived evidence.

The initial proposal includes named public-page and non-form interaction events, opaque approved page identifiers, coarse technical context and approved experiment identifiers. It excludes replay, page structure and text, form contents and interactions, raw URLs and referrers, query strings and fragments, request and response bodies, console messages and stack traces, cookies, storage contents and headers. If the issued integration cannot enforce these exclusions, capture must remain disabled. Replay-capable code may be included, but disabled replay must not capture, store or send replay payloads. Collection requires account-owner enablement, current signed per-site configuration and the client-approved visitor-consent signal. These are activation requirements, not a claim that an existing installation has been verified. Account sign-in information and hosting logs are separate processing, described above; this is not a claim that the service stores no personal data.

Your analytics choice

Optional analytics must wait for your opt-in. Declining it must not prevent use of the website. When enabled, accessible settings must let you withdraw as easily as you agreed, stop future capture and clear controlled analytics storage and queues. The initial policy also treats supported global opt-out signals as analytics opt-out. These controls require verification before activation; this draft does not claim they are already available.

Your agent and other providers

Pasting an instruction into your coding agent shares it with that agent’s provider under its own terms. When service connections become available, the setup must explain which providers receive data, for what purpose and with which permissions. Repository connections are optional and are separate from account sign-in. This draft does not approve any additional provider, data transfer or marketing integration.

Retention and deletion

No final customer retention schedule is established in this draft. The engineering proposal for short-lived test evidence is not a promise about customer data or backups. Before service activation, the notice and agreement must state retention periods or clear criteria, deletion and export arrangements, and how restored backups are reconciled with deletion requests.

Questions and privacy requests

Contact hello@relentlessengine.com to ask about data handling or request access, correction or deletion. Depending on applicable law, you may also have rights to restriction, portability, objection and withdrawal of consent, and to complain to your data protection authority. We may need proportionate information to verify a request; do not send identity documents unless specifically requested through an agreed secure process.

Before this notice becomes final

Applicable legal bases, hosting and email processing details, provider locations and transfer safeguards, retention schedule, controller and processor responsibilities, request handling and effective date still require confirmation. Any customer-data processing agreement and visitor-facing notice must reflect the actual released service. Material changes to this notice should be dated and communicated as required.

Contact · Terms & conditions