MediaRelay Logo
MediaRelay
Legal Compliance & Privacy

Privacy Policy

Last Updated & Effective Date: September 5, 2026 • Application Package: media.relay.app

Our Absolute Privacy Commitment (Zero Relay Server Principle)

MediaRelay operates zero intermediary media storage or relay servers. When you back up photos or videos, your files stream directly from your Android handset to Google Photos REST API servers over encrypted TLS connections. We do not store, view, copy, parse, or sell your photos, videos, or messages.

1. Introduction

MediaRelay ("we", "us", or "our") develops and distributes the MediaRelay Android application (package name media.relay.app) and related website located at https://mediarelayapp.web.app. This Privacy Policy outlines what information the application accesses, how that data is processed, and our strict safeguards.

By installing, accessing, or using MediaRelay, you acknowledge the practices described in this Privacy Policy.

2. Google API Services User Data Policy & Limited Use Disclosure

MediaRelay's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • MediaRelay requests access to Google Photos solely through user-consented OAuth 2.0 authorization.
  • We only request the minimal permissions required to function: https://www.googleapis.com/auth/photoslibrary.appendonly and https://www.googleapis.com/auth/photoslibrary.sharing.
  • MediaRelay never transfers or sells Google user data to third parties, data brokers, advertising networks, or data aggregators.
  • MediaRelay never uses Google user data for serving advertisements, retraining machine learning models, facial recognition, or commercial profiling.
  • Human personnel never read or inspect your Google Photos or uploaded media.

3. Permissions & Data Accessed on Your Device

To route media from folders such as WhatsApp to your designated Google Photos destination, MediaRelay requests the following permissions on your Android device:

READ_MEDIA_IMAGES & READ_MEDIA_VIDEO (Android 13+) / READ_EXTERNAL_STORAGE

Used strictly to query local media files in user-designated folders (e.g. /Android/media/com.whatsapp/WhatsApp/Media/) via Android's MediaStore API. MediaRelay reads file bytes solely to compute SHA-256 integrity hashes and stream the file directly to Google Photos API.

Storage Access Framework (SAF / DocumentTree)

If granted by the user for custom folders, this allows MediaRelay to access files outside standard media collections.

MANAGE_MEDIA / Delete Intent Requests

Used only when the user explicitly triggers the "Reclaim Storage" cleanup tool in the app. MediaRelay never deletes any file automatically; each deletion requires system confirmation by the user.

FOREGROUND_SERVICE & RECEIVE_BOOT_COMPLETED

Used by Android WorkManager to reliably perform media upload background operations according to user constraints (e.g., Wi-Fi only, device charging) and display notification progress.

4. Information We Do NOT Collect

  • No Chat Messages or Text: MediaRelay does not have access to, read, or decrypt WhatsApp databases, contacts, or chat transcripts.
  • No Media Files on Remote Servers: We do not operate a media relay proxy. Your photo and video bytes never touch any server operated by MediaRelay.
  • No Personal Identifiable Information for Sale: We never sell, rent, monetize, or trade any personal data.

5. Local Storage & MediaMemory™ Cloud Ledger

To deliver verified backups and cross-device duplicate protection, MediaRelay manages metadata in two locations:

  • Local Room Database: Stored strictly in sandbox storage on your device. Contains local file URIs, file names, file sizes, SHA-256 cryptographic fingerprints, Google Media Item IDs, and upload timestamps.
  • MediaMemory™ Cloud Ledger (Google Firestore): For users who sign into their MediaRelay account across multiple devices, we record non-reversible cryptographic SHA-256 hashes and upload verification timestamps. This enables your new device to recognize already-backed-up media without re-uploading duplicate files. Raw photo bytes are never stored in the ledger.
  • Token Security: Google OAuth refresh and access tokens are secured in private application storage using Android's encrypted storage facilities.

6. Data Retention, Revocation & Account Deletion

You maintain complete control over your data at all times. For comprehensive, step-by-step account and data deletion procedures (including self-service email generation and Google OAuth permission revocation), please visit our dedicated Delete Account Instructions Page.

  • Disconnecting Google Account: You can disconnect any linked Google Account directly in the MediaRelay Settings tab at any moment. This immediately deletes stored OAuth tokens on your device.
  • Google Account Security Permissions: You can revoke MediaRelay's access to your Google Account at any time by visiting Google Account Third-Party Access.
  • Clearing Local Data: Uninstalling the application or clearing App Data via Android Settings permanently deletes all local Room database entries, cached hashes, and settings.
  • Cloud Ledger Deletion: You can request immediate deletion of your MediaMemory Cloud Ledger records by using our Account Deletion Tool or contacting us directly at privacy@mediarelay.app.

7. Children's Privacy

MediaRelay is not directed to children under the age of 13 (or under the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children.

8. Contact Us

If you have questions, feedback, or data privacy requests regarding this policy, please reach out to:

MediaRelay Privacy & Security Team
Email: privacy@mediarelay.app
Website: https://mediarelayapp.web.app