Your inbox stays yours.

Relay retrieves an email code only when you ask. This page explains the information involved in that lookup.

What a lookup reads

Relay’s service uses your connected accounts’ Google access tokens to verify that you authorized Relay and read the latest three messages in each connected Gmail inbox. It reads text, sender, recipient, subject and receipt time. Attachments are ignored. Email is never sent, deleted, or marked as read.

The extension also reads the current website’s hostname, page title, and text near the code field. It does not send your browsing history, cookies, passwords, or other tabs.

How Jev finds a code

The combined three-message snapshots from all connected Gmail accounts and page context are sent to TypeSafe AI’s Jev service. Jev chooses a matching email and scores possible codes. Relay checks the result, its age, and the field before filling. An uncertain result leaves the field unchanged. Relay does not click Submit, though a website may continue automatically when its code is entered.

Google Messages and SMS

SMS is an optional, unofficial connection using a desktop helper. Google Messages session cookies and pairing keys stay in the helper’s local configuration directory; they are never sent to Relay’s hosted service or TypeSafe. Unlike Gmail OAuth, these are sensitive browser session credentials, not a narrowly scoped read-only permission. You explicitly import a local session file and confirm pairing on your phone. The extension does not request browser cookie access.

When you choose SMS and click Find & fill, the helper inspects recent inbox conversations locally and returns up to five incoming text messages from the last ten minutes. Their text, sender and receipt time, together with page context, are sent to Relay’s service and TypeSafe for selection. Attachments, outgoing messages and group chats are excluded. No SMS content is saved or logged by Relay. Pairing credentials persist locally with restricted file permissions; this is not a promise of encrypted storage at rest.

Turn off SMS processing in Settings to stop SMS lookups. Disconnect Messages attempts to remove the phone pairing and deletes local credentials. If remote removal fails, also remove Relay under Device pairing in Google Messages. Gmail disconnection does not delete the helper’s pairing credentials. Delete any session export file yourself after pairing.

What is saved

Relay saves your connected email addresses, processing permission, and any sender rules in this browser. Temporary lookup status and additional accounts’ access tokens stay in the browser session. Additional accounts renew silently using your Google session; if access expires, reconnect the affected account in Settings. Relay’s service does not store email content, codes, Google tokens, or page text, and the application does not log them.

Netlify hosts Relay’s service and may retain infrastructure request metadata, such as IP addresses and request times. TypeSafe processes the evidence sent for selection under its own terms and privacy practices. This page does not promise a retention period for those providers.

Your controls

Uncheck processing permission in Settings to pause lookups. Use the Disconnect control beside an account to revoke its Google access and remove that connection. You can also remove Relay’s access from your Google account at any time.

Relay does not sell email data or use it for advertising. Its email access is used to provide the code-filling feature you requested.

Provider information

Last updated October 4, 2026.