Relaxin Jailbreak

Last updated 28 July 2026

Privacy policy

Short version: we run a documentation site. We do not want your personal data, we collect as little of it as a web server can function on, and we do not sell or share any of it.

1. Who we are

This site ("we", "us") publishes install documentation and download mirrors for the Relaxin jailbreak at relaxin-jailbreak.com. We are an independent community project, not the Relaxin development team, and not affiliated with Apple Inc. For anything in this policy, contact privacy@relaxin-jailbreak.com.

2. What we collect

Server logs

Like any web server, ours records requests: the page or file requested, timestamp, HTTP status, referring page, browser user-agent, and a truncated IP address (the final octet is discarded before the entry is written). These logs exist for security and for counting downloads. They are kept for 30 days and then deleted.

Messages you send us

If you use the contact form or email us, we receive your name, email address, chosen topic and whatever you write. We use it to answer you and nothing else. Threads are deleted after 12 months, or immediately if you ask.

Blog comments

Our blog runs on WordPress. If commenting is enabled and you leave one, WordPress stores the name, email and comment text you submit, plus your IP address and user-agent for spam filtering. Comments and their metadata are retained indefinitely so conversations stay readable — ask us and we will remove yours.

3. What we do not collect

  • No advertising pixels, no ad networks, no data brokers. We do not run ads and we do not sell data.
  • No account system — there is nothing to register for and no password to lose.
  • No serial numbers or IMEIs, and the browser signer and the rest of the site never ask for a UDID. (The optional Pro signing service does need your device UDID — see section 8 — but nothing on the site collects one unless you order Pro.)
  • No Apple ID credentials, ever. Neither the free signer nor Pro signing ever asks for your Apple ID password.
  • No session recorders or heat maps — nothing replays what you did on the page.

4. Cookies

This site uses Google Analytics, and Google Analytics sets cookies. On your first visit it writes _ga and _ga_<id> to your browser — first-party cookies holding a random identifier so that two page views can be recognised as one visit. _ga lasts two years by default; the per-property one lasts two years as well.

The WordPress blog at /blog/ may additionally set functional cookies if you leave a comment (to remember your name and email for the next one) or log in as an author. Those are first-party and strictly functional.

Blocking all of these in your browser, or using an extension that blocks Google Analytics, breaks nothing on this site. Every page works identically without them.

5. Analytics

We use Google Analytics 4 (measurement ID G-3H24QJMNCY) to see which guides people actually read and where the install steps lose them. It tells us page views, rough location at city level, device and browser type, and which site sent you here.

Analytics is off until you agree. On your first visit a banner asks, and Google Consent Mode holds analytics cookies back until you tap Accept — tap Decline and none are ever set. You can change your mind any time by clearing this site's storage in your browser.

Google processes this data as our processor, and it involves transferring data to Google servers, including outside your country. Google may retain it under its own retention rules. We have not linked this property to Google Ads and we do not use it for advertising or remarketing. We cannot identify you personally from it, and we do not try to.

If you would rather not be counted, install Google's official opt-out browser add-on, switch on your browser's tracking protection, or block cookies for this site. Any of those is enough, and none of them costs you functionality here.

6. Downloads and third-party tools

Files are served directly from our own infrastructure or a named mirror. We record that a download happened, not who downloaded it.

The install guides point to independent tools — Lightning Sign, ZeeSigner and Sideloadly. Those are operated by other people under their own privacy policies, which we do not control. When you sign an IPA, your Apple ID or certificate is handled by that tool, not by us. Read their policies before you hand over anything sensitive.

7. The online signer

The signer page runs the signing engine as WebAssembly inside your browser. Your .p12 certificate, its password and the private key it contains are read into that tab's memory, used there, and discarded when you close it. They are never transmitted to us, and we could not read them if we wanted to.

One button is the exception, and it says so on the page. “Install on this iPhone” uploads the finished, signed IPA to our server, because iOS will only install an app from an HTTPS link and cannot install one out of browser memory. That file contains the certificate you signed with. It is written to a randomly named folder that is not listed or linked anywhere, and a sweep deletes it 30 minutes after upload. We do not log who uploaded it, and nothing about it is stored in a database.

If you would rather nothing of yours reached our server at all, use “Download signed IPA” instead. That path is entirely local — the file is assembled in your browser and saved straight to your device — and you can then install it with any sideloader you like.

8. Pro signing service

If you buy Relaxin Pro, we collect the one thing signing requires: your device's UDID, plus an email address to send your install link and receipt. A UDID is a device identifier — it lets us register your device on our developer certificate. It cannot be used to log into your Apple account or any other account, and we never ask for your Apple ID password.

We keep your UDID and email for as long as your signature is active (the year you paid for) plus a short period for support and renewals, then delete them. Payment is handled by our payment provider — we receive confirmation that you paid, not your card number. We do not sell or share any of this, and you can ask us to delete it once your signature lapses.

Where the UK GDPR or EU GDPR applies, we rely on legitimate interests for server logs (keeping the site up and secure) and on your consent, given by choosing to write to us, for contact messages.

Analytics consent

Under the EU ePrivacy rules and GDPR, analytics cookies need opt-in consent before they are set. This site uses a consent banner backed by Google Consent Mode v2: analytics stays denied until a visitor taps Accept, so nothing is set for anyone who declines or ignores it.

You can ask us to:

  • tell you what we hold about you,
  • correct it,
  • delete it,
  • send you a copy in a portable format,
  • or stop processing it.

Email privacy@relaxin-jailbreak.com and we will respond within 30 days. Because we hold so little, most requests are settled the same week. If you are in the EEA or UK you may also complain to your national data protection authority. California residents have equivalent rights under the CCPA/CPRA; we do not sell or share personal information as those laws define it.

10. Children

This site is not directed at children under 13 (or 16 where local law sets that bar), and we do not knowingly collect their data. If a child has sent us something, tell us and we will delete it.

11. Security

The site is served over HTTPS. Contact submissions are transmitted encrypted and stored on access-controlled systems. No system is perfect; if a breach ever affected personal data, we would post a notice here and email anyone directly affected.

12. Changes to this policy

When this policy changes we update the date at the top of the page. Material changes get a note on the blog as well, so there is a dated record rather than a silent edit.

Not legal advice

This policy describes how this site actually behaves. If you are reusing it for a site of your own, have a lawyer check it against your jurisdiction and your real data flows first.