The same plain-language rule that governs our employees governs this document. No dark patterns, no data hostage-taking, no fine print that says the opposite of the headline. Here's exactly what we collect, why, and how to make it disappear.
Three buckets, nothing hidden:
Account data — your name, email and workspace settings, so we can log you in and send reports. Connected-service data — when you link Google Ads, Search Console, or any tool via Equipment, your employees read the data they need to work (campaigns, search terms, rankings, tickets). Product usage — the actions your birds take, the reports they generate, and the ledger of what happened, so the office actually functions and you have a record.
We hold the keys to your connected accounts and a memory of the work — because that's the job. We don't scrape your inbox "just in case", and nothing you didn't connect is ours to see.
To run your employees, deliver your morning reports, keep the cause-and-effect ledger, and improve the product. That's the whole list. We do not sell your data, rent it to advertisers, or use your private business information to train models that other companies' birds can see. Aggregate, de-identified signals (e.g. "reports load slowly on large accounts") may guide engineering — never anything that identifies you or your customers.
The golden rule is enforced in code: an employee can only ever access what your own Google (or other) login can access. Where a service offers OAuth, you authenticate on their page — we receive a revocable token, never your password. API keys and tokens are encrypted at rest (AES-256-GCM) and transmitted only to the service they belong to. Revoke access from your settings or the provider's, and the connection goes dark immediately.
Only the infrastructure that makes the product run: our cloud hosting, the AI model providers that power the employees, and the services you explicitly connect. Each is bound to process data on our instructions and protect it. We disclose data to authorities only when legally compelled — and, where the law allows, we'll tell you first. We never share your data for anyone else's marketing.
While your account is open, so your employees keep their memory and the ledger stays intact. Delete your workspace and we remove your personal data and connection tokens within 30 days, except the minimum we're legally required to retain (e.g. billing records). Cached data from disconnected services is purged promptly.
You can access, correct, export or delete your data, and object to or restrict certain processing — rights granted under GDPR, CCPA and similar laws, extended to everyone regardless of where you live. Your memory and ledger are yours to export in a portable format. We will never hold your data hostage as a way to keep you subscribed. To exercise any right, email support@kelvyr.com.
Encryption in transit and at rest, least-privilege access for our team, and the same adversarial testing we apply to employee behavior applied to our data handling. No system is perfectly secure, but we treat a data incident the way we treat a broken rule in the constitution — as a defect to fix at the root, and to tell you about honestly and promptly.
We use essential cookies to keep you signed in and a minimal set of privacy-respecting analytics to understand product usage — no third-party ad trackers. Kelvyr is for businesses and isn't directed at children under 16. If we materially change this policy, we'll notify you in the product before it takes effect; the "last updated" date above always reflects the current version.
A real person answers. Write to support@kelvyr.com and we'll get back to you. See also our Terms of Service.