Privacy Policy
CaptureRelay is an image-delivery tool for people authorized by participating WordPress website administrators. It sends images and related information only where you direct it — to the WordPress websites you choose. This policy explains what the app processes, where that information goes, what CaptureRelay deliberately does not collect, and the choices available to you. The CaptureRelay app and WordPress plugin are developed and published by Skyrocket Radio (the “Publisher,” “we,” or “us”), the developer identified on our App Store Connect and Google Play accounts. Privacy questions and requests may be sent through our contact form.
What the app processes
To request approval, secure the connection, and deliver images, CaptureRelay processes: website connection details, a user-provided device name, a generated per-website device identifier, device platform/model/OS/app version, the network address used to request a connection, images taken in the app or specifically selected from the device, optional image titles and Photo Credit, capture or selection time, and operational upload records. This information is used only to request administrator approval, secure the connection, process and deliver images, prevent abuse and duplicates, and diagnose failures.
Where your information goes — and who receives it
CaptureRelay performs a user-directed transfer. When you send an image, the app transmits it — together with the generated per-website device identifier, your device name and platform/model/OS/app version, any optional image title and Photo Credit, the capture or selection time, and operational upload records — directly to the WordPress website or websites you select.
CaptureRelay's publisher does not operate a central relay, cloud, or account service, and does not receive, store, or process your images, identifiers, or upload metadata. Each destination WordPress website is operated independently by its own administrator, who determines the purposes, access rules, storage, use, and retention of the information it receives under that website's own privacy policy. CaptureRelay provides the software that carries out the transfer you request and normally cannot access or delete information held by a destination website. The exceptions are information processed by this public website, including the analytics and contact form described below.
How credentials and images are stored
Permanent website credentials are unique per phone and website and are stored in the iOS Keychain or Android Keystore-backed storage. The destination plugin stores its corresponding credential in encrypted form. Queued photos are stored in the app's private storage until uploaded or deleted. WordPress stores the final image and protected operational metadata.
Production transfers require HTTPS. Approved-device requests are signed, time-limited, replay-protected, and rate-limited; administrator approval is required before an upload credential is issued. Credentials, authorization headers, and signing secrets are excluded or redacted from operational logs. The destination plugin validates and rewrites accepted JPEG files before adding them to the Media Library. No security measure can eliminate every risk, but CaptureRelay is designed to minimize access and retain only the information needed to operate and protect the transfer.
What CaptureRelay does not do
- It does not scan or upload your photo library — it receives only the photo or photos you select through the iOS or Android system picker.
- It does not request device location access or collect location data.
- It does not use advertising identifiers, track you across apps or websites, sell personal information, display advertising, or include third-party behavioral analytics.
- Every delivered image has its EXIF, GPS, XMP, IPTC, and other embedded metadata removed on the server before it reaches the Media Library.
Retention, deletion, and your choices
By default, an unapproved connection request expires after 24 hours. Its raw network address is cleared when the request is approved, rejected, cancelled, or expires. Closed connection-request records are retained for 30 days, while delivery and activity records are retained for 90 days. One-time nonce and rate-limit records expire automatically. A destination administrator may select different retention periods in the plugin settings.
Approved or revoked device records remain until the destination administrator removes the plugin data. A permanent device block, which contains a one-way device identity hash and limited administrative details, remains until that administrator removes the block. Media Library images remain until the destination administrator deletes them. By default, uninstalling the plugin preserves its operational and security tables; the administrator can expressly choose to erase them during uninstall.
Website administrators can reject, block, unblock, or revoke a device at any time. App users can disconnect websites and delete queued images. For an image, device record, block, or delivery record stored on a destination website, contact that website's administrator; CaptureRelay's publisher normally has no access to that independently stored information. Requests concerning this public website's contact or analytics data may be sent through our contact form.
Administrator notification emails
A destination website may optionally email its administrators when a device requests approval or when an upload succeeds. If that option is enabled, those emails are generated and delivered through the destination WordPress website's own hosting or email provider, under that website's and that provider's policies — not by the Publisher.
This website: analytics
We measure traffic to capturerelay.app with our own first-party, privacy-respecting analytics — not Google Analytics or any third-party behavioral tracker. It uses no cookies and no cross-site identifiers, and it honors your browser's Do-Not-Track setting.
For each visit we record the page viewed, the referring website (if any), key actions (such as App Store, Google Play, and plugin-download clicks), a coarse browser/OS label, and your country. Our analytics database does not store your raw IP address. To count unique visitors within a single day, it computes a pseudonymous one-way token from the IP address using a salt that rotates every 24 hours; the token cannot be used by the analytics system to recover the IP or link visits across days, and it is omitted entirely when Do-Not-Track is on. Our hosting and content-delivery infrastructure necessarily processes network addresses to deliver and protect the website and to derive the country code, but the analytics data retains no location more precise than country. This first-party data is never sold or used for advertising and is used only to understand site usage.
The contact form on this website
When you use our contact form, we process your name, email address, chosen topic, and message to respond to your enquiry. Your message is emailed through our configured email provider and stored on our server so we can track and follow up on it; we record your country and the time of submission with it, and retain it only as long as needed to handle your enquiry or meet applicable recordkeeping obligations. Submissions are protected by reasonable technical measures, including a short-lived signed token, timing checks, and rate limiting. We do not use this information for marketing, and we do not operate a newsletter.
Future app-verification technologies
CaptureRelay includes a fail-closed integration boundary for Apple App Attest and Google Play Integrity, but device attestation is not currently enforced. If we enable it in the future, a verification service may process integrity tokens and related network information to confirm that requests come from a genuine, unmodified app. We will update this policy to describe that processing before enabling enforcement.
Contact & requests
Questions or requests concerning information controlled by CaptureRelay may be sent through our contact form. Requests concerning information held by an independently operated destination website must be sent to that website's administrator.