Privacy Center
Your intelligence shouldn’t
require giving up your privacy.
This is the plain-language version, written to be accurate rather than reassuring. Every capability below carries one status — Available, Beta, Planned or By arrangement — and nothing is described as available unless it works in the product today.
Where things stand today
Kelven is live: you can create an account, choose a privacy mode, see which model answered and what was shared with it, keep memory on your device or in your account, and export or delete everything. The formal privacy policy is published, and this page is the plain-language companion to it.
Stored
What Kelven keeps.
Your account
The email address you sign up with, and the record that you have an account.
Your memory, if you choose cloud memory
Preferences, projects and context you've asked it to remember — encrypted at rest, exportable and deletable by you.
Waitlist signups, today
Right now the only thing Kelven actually stores is the email address (and optional note) you send through this site.
Not stored
What it won’t do.
Conversation data as a business model
Kelven is intended to be paid for by the people who use it. Selling private conversations or behavioural profiles is not part of the plan.
A profile attached to every request
The design goal is the opposite: retrieve what's relevant to this request, send that, and nothing more.
Memory you can't see
Anything remembered should be viewable, editable and removable by you.
Memory
Where your memory lives.
Three options, each with an honest description of what it does and does not protect.
Memory is stored by Kelven. Relevant context still travels to the AI provider handling a request.
All three are available in Kelven today, chosen from the app and applied to every conversation until you change it.
Tokenization
The model answers
without knowing who.
Most reasoning doesn’t need real identities. Before a request leaves your device, Kelven finds the sensitive values in it and decides which ones the task actually needs. The rest become typed stand-ins — a person, a client, a company, a property — so the structure of your situation survives and the identities don’t.
The answer comes back about the stand-ins. Kelven puts the real details back locally, and the mapping is destroyed.
Credentials are a harder rule: passwords, API keys, recovery phrases, card and government numbers are removed outright and never sent anywhere.
This is minimisation, not invisibility. A provider still processes the abstracted request — and Kelven shows you exactly what that request contained.
- You
- Your device
- Privacy gateway
- Approved model
What you write
Jordan Lee runs Northstar Labs and needs to reply to client Casey Morgan about Project Aurora at a project site in Austin, Texas, where a delivery arrived damaged.
What the model receives
PERSON_1 runs COMPANY_1 and needs to reply to client CLIENT_1 about Project PROJECT_1 at a project PROJECT_2 in Austin, Texas, where a delivery arrived damaged.
5 values were replaced before the request left the device. The model reasons on the abstracted version; the real names are put back locally when the answer comes home.
Context
What travels with a request.
The design principle is context minimisation: retrieve what the request needs, send that, and leave the rest where it is.
Nine of these memories stay where they are. Three are relevant to the request.
Your memory
Everything you've told it, at rest.
Local retrieval
Only the request decides what's relevant.
3 relevant memories
Not a profile. Three items.
Kelven
Assembles the minimum context needed.
The model that answers
Receives the request and that context.
Precision
Four things people get told, that aren’t quite true.
What Kelven stores vs. what a provider processes
These are separate questions with separate answers. Kelven may keep no memory at all while a request is still processed by an AI provider in order to be answered.
Local memory is not local inference
Keeping memory on your device means Kelven doesn't need a copy in its cloud. It does not mean the answer is produced on your device — the relevant context still travels to whichever model answers.
End-to-end encryption has limits here
A cloud model needs readable text to answer a question. So we won't describe a cloud-answered request as end-to-end encrypted. Storage encryption and transport encryption are real; inference-time secrecy is not.
Retention is per route, not one number
Different providers retain differently, and their policies change. Route-level retention will be stated where we can verify it, with the date we last checked.
Status
Every privacy capability, with its real status.
One status vocabulary, used the same way across this whole site: Available — working in the product today. Beta — working, still being hardened — expect rough edges. Planned — designed and on the roadmap, not built yet. By arrangement — delivered as part of a contract, not self-serve.
- Available
Privacy modes
Standard, Private, Confidential and Local Only as one control in the composer, not a settings page.
- Available
Provider transparency
Every answer shows which route handled it, why it was chosen, what context was shared and what was replaced before sending.
- Available
Bring your own AI
Connect your own OpenAI or Google credentials for a direct relationship and your own billing, with routing and minimisation unchanged.
- Available
Portable export
One structured export of memory, preferences, projects and instructions that you keep.
- Beta
Local processing
Retrieval, classification and sensitive-data detection run on your device; on-device answering works on supported hardware.
- By arrangement
Kelven Private
Organisation-controlled credentials, private memory infrastructure, retention rules, routing policies, allowlists and audit logs.
- Planned
Connected applications acting for you
Approved external actions carried out on your behalf, inside the ceilings you set.
Your data is not our business model.
If improving Kelven ever involves your content, that will be an explicit choice you make — not a line in a policy document. Questions we haven’t answered here are worth asking directly.
The formal privacy policy governs; this page is the plain-language description of what Kelven does with data.