MCP and privacy
What a connected
app can actually see.
When you connect an outside AI application to Kelven, it doesn't get your memory. It gets to ask narrow questions, and receives the minimum answer that makes the task work — usually with names and amounts replaced by typed placeholders.
Six stages, every request
Minimisation happens before anything leaves.
Stage 1
Authorization
The request must carry a valid token with the scope for the capability it's calling. No token, no answer.
Stage 2
Relevance retrieval
Only records related to the stated task are considered — never your whole profile.
Stage 3
Sensitivity filter
Local-only records are removed absolutely. Records above your maximum sharing level, or switched off for connected apps, are removed too.
Stage 4
Context minimisation
What survives is trimmed to the few facts the task actually needs.
Stage 5
Tokenisation
Identifiers become typed placeholders — CLIENT_1, PROPERTY_1, AMOUNT_1 — with relationships preserved. Secrets are removed rather than replaced.
Stage 6
Result and receipt
The client gets the minimised answer. You get a log entry showing what was returned and what was withheld.
How far a record may travel
You set the ceiling, per record.
- PublicSafe to share anywhere.
- NormalShareable with connected apps when relevant.
- PrivateShared only when the task needs it, and tokenised.
- ConfidentialNot shared with connected apps unless you turn it on per record.
- Local onlyNever leaves the device. Never returned through the Gateway. No exceptions.
What we won’t claim
Kelven controls what Kelven shares.
If you type a client's real name straight into another AI application, that application already has it. No gateway can reach back and conceal it. What Kelvencontrols is its own half of the exchange: the context it returns, how much of it, and in what form.
We also don't claim providers see nothing. They see a minimised, tokenised version of what the task requires — which is a real and measurable reduction, not invisibility.
Every request appears in Connected Apps with what was returned and what was withheld, and disconnecting blocks the next request immediately.
The future isn’t another AI model. It’s an intelligence layer that’s yours.
Kelven is the user-controlled intelligence layer between you and AI — with one memory that’s always yours.
No spam. Just one note when early access opens.