Privacy and security
This page is an inventory rather than a policy. It says what is actually reachable — by this site, and by the engine when you embed it — and what could be done with it. Where the honest answer is "nothing, because it was never built", that is what it says.
What this site collects
Nothing, in the sense people usually mean. There is no analytics service, no tag manager, no pixel, no consent banner, and nothing that sets a cookie. There is no account to create and no form to submit.
What does exist is the ordinary record any web server keeps. The site is served as static files from a content delivery network, and its access log holds, per request, an IP address, a timestamp, the path asked for, and the User-Agent and Referer the browser sent. That log exists to answer whether the site is up and what is breaking. It is kept for 90 days and then deleted. It is not joined to anything, because there is nothing to join it to.
Two details are worth stating outright, because they are what make the log of limited use rather than merely unused:
- The site issues no identifier. No cookie, no fingerprinting script, no
localStoragevalue that travels anywhere. Two visits from the same reader are two IP addresses in a log, and a great many readers share one — a company network, a mobile carrier, a VPN. There is no key that turns those rows into a person. - Search happens in your browser. The search box does not query a server. The whole index is a file this site serves, fetched the first time you type into the box and searched locally. The term you typed goes into the URL after a
#, which is the part of an address a browser keeps to itself and never sends — so a search is still a link you can share, and it still does not appear in the log. It used to be written as?q=, which a browser does send; a link in that older form still works and is rewritten to the private one as soon as you type.
The site stores two values in your browser's localStorage, and they never leave it: relix-spelling, remembering whether you prefer operators written as symbols or as keywords, and relix-build-tool, remembering which build tool's instructions the install page should show you. Clearing site data removes both and costs you nothing but those two preferences.
What this site loads from elsewhere
Nothing. Every font, stylesheet, script and image a page loads comes from this site's own address.
That is a deliberate change rather than an accident of simplicity. Earlier versions loaded the two typefaces from Google Fonts and the diagram renderer from a public CDN, which meant reading a page here announced your IP address, your browser and the page you were reading to a third party. A documentation site has no reason to arrange that. The fonts are licensed under the SIL Open Font License and the diagram renderer under the MIT licence, so serving our own copies is exactly what those licences are for, and the licence text ships beside each one.
The consequence is that this page's claim has no exceptions to keep track of: if you watch the network while you read the site, every request goes to one host.
What the engine can see
This is the question that matters more, because Relix reads databases.
Relix is a library, not a service. It runs inside your process, on your machine or your server. It opens the connections your script declares, executes the query, and returns rows to the code that asked for them. There is no account, no licence check, no usage ping and no crash reporter. This is not a promise about what we choose to send — it is a property of the build: no module of the engine declares a dependency on any networking API, and a test reads the compiled module descriptors on every build and fails if one does. Code that cannot open a socket cannot report anything.
Your data does not reach us because there is no mechanism by which it could, and no part of the engine that would know where to send it.
Asking questions in English stays on your machine. The REPL's :ask command runs a language model in-process against a model file on your own disk. The prompt — which includes your schema — is not transmitted anywhere. When :ask produces something the engine cannot answer, it appends a line to a local ask-log.jsonl file in the directory you ran it from, as a debugging aid for you. That file is never uploaded, and RELIX_ASK_LOG=off or the :log off command stops it being written at all.
Two things do cross the network, and both are things you asked for. Relix can fetch a JDBC driver, and it can fetch the catalogue of available connector plugins. Both download from public repositories — Maven Central and this project's GitHub releases — which see an IP address at the moment of the download, the same way any software download does. Neither happens on its own: a Relix session built in Java downloads nothing unless the program supplies a provisioner, and the command-line tool requires --download-drivers before it will fetch anything. A missing driver is reported as a missing driver rather than quietly resolved over the network.
Security
Relix executes the queries your program gives it, against the sources your program names, with the credentials your program supplies. It has no privileges of its own and grants none: if the database account you connect with can only read one schema, that is the whole of what a query can reach. Credentials come from your environment — the ${VAR} form in a source declaration reads an environment variable — so they are not written into a script and not carried in anything the engine serialises.
A script only reads. There is no statement in the language that writes to a source, creates a table or deletes a row, so a Relix query cannot modify the system it is reading, whatever the query says and whatever the connection would permit.
To report a security problem, please use GitHub's private vulnerability reporting rather than a public issue, so a fix can be prepared before the problem is described in the open.
Changes and questions
The site is generated from its own repository, so what this page said on any past date is recoverable from its history rather than a matter of trust. Questions about anything here belong on the issue tracker, and are as welcome as questions about the engine.