FARAH RELAY

Privacy Policy

Effective and last updated: 18 September 2026

This policy describes data handled when you connect ChatGPT to a paired device through Farah Relay.

Data we handle

Network addresses

Request IP addresses are used transiently in memory as rate-limit keys. Raw IP addresses are not written into Farah Relay security audit events by the current implementation.

Authentication

GitHub is used for identity. A GitHub access token obtained during sign-in is used to retrieve identity and is not persisted by Farah Relay after that lookup. ChatGPT/OpenAI separately processes data under OpenAI's own terms and privacy policies.

Current lifetimes and cleanup

RecordProtocol lifetime
OAuth access token15 minutes
OAuth refresh familyUp to 30 days
OAuth authorization code5 minutes
OAuth transaction10 minutes
Device pairing session5 minutes
Relay call envelope4 minutes

Expiration stops validity or dispatch; it is not a promise of immediate physical deletion. Expired and terminal records are eligible for bounded cleanup and may remain until maintenance cleanup runs. Account/device metadata can persist while the account/device exists or until deletion is requested.

Use and sharing

Data is used to authenticate, pair and route devices, execute requested workflows, recover durable results, prevent abuse, troubleshoot, and secure the service. Farah Relay does not sell personal data or use relay content for advertising. Service infrastructure providers may process data as necessary to operate the service.

Your controls

Security

The service uses HTTPS, hashed server-side credentials/tokens, scoped OAuth, tenant ownership checks, bounded request sizes, rate limits, and device-side policy enforcement. Do not submit secrets in support requests.

Contact

For privacy questions or deletion requests, use the Farah Relay support process.