Skip to content

Privacy Center

Your intelligence shouldn’t
require giving up your privacy.

This is the plain-language version, written to be accurate rather than reassuring. Every capability below carries one status — Available, Beta, Planned or By arrangement — and nothing is described as available unless it works in the product today.

Where things stand today

Kelven is live: you can create an account, choose a privacy mode, see which model answered and what was shared with it, keep memory on your device or in your account, and export or delete everything. The formal privacy policy is published, and this page is the plain-language companion to it.

Stored

What Kelven keeps.

  • Your account

    The email address you sign up with, and the record that you have an account.

  • Your memory, if you choose cloud memory

    Preferences, projects and context you've asked it to remember — encrypted at rest, exportable and deletable by you.

  • Waitlist signups, today

    Right now the only thing Kelven actually stores is the email address (and optional note) you send through this site.

Not stored

What it won’t do.

  • Conversation data as a business model

    Kelven is intended to be paid for by the people who use it. Selling private conversations or behavioural profiles is not part of the plan.

  • A profile attached to every request

    The design goal is the opposite: retrieve what's relevant to this request, send that, and nothing more.

  • Memory you can't see

    Anything remembered should be viewable, editable and removable by you.

Memory

Where your memory lives.

Three options, each with an honest description of what it does and does not protect.

Memory is stored by Kelven. Relevant context still travels to the AI provider handling a request.

All three are available in Kelven today, chosen from the app and applied to every conversation until you change it.

Tokenization

The model answers
without knowing who.

Most reasoning doesn’t need real identities. Before a request leaves your device, Kelven finds the sensitive values in it and decides which ones the task actually needs. The rest become typed stand-ins — a person, a client, a company, a property — so the structure of your situation survives and the identities don’t.

The answer comes back about the stand-ins. Kelven puts the real details back locally, and the mapping is destroyed.

Credentials are a harder rule: passwords, API keys, recovery phrases, card and government numbers are removed outright and never sent anywhere.

This is minimisation, not invisibility. A provider still processes the abstracted request — and Kelven shows you exactly what that request contained.

  1. You
  2. Your device
  3. Privacy gateway
  4. Approved model

What you write

Jordan Lee runs Northstar Labs and needs to reply to client Casey Morgan about Project Aurora at a project site in Austin, Texas, where a delivery arrived damaged.

What the model receives

PERSON_1 runs COMPANY_1 and needs to reply to client CLIENT_1 about Project PROJECT_1 at a project PROJECT_2 in Austin, Texas, where a delivery arrived damaged.

5 values were replaced before the request left the device. The model reasons on the abstracted version; the real names are put back locally when the answer comes home.

Context

What travels with a request.

The design principle is context minimisation: retrieve what the request needs, send that, and leave the rest where it is.

Nine of these memories stay where they are. Three are relevant to the request.

  1. Your memory

    Everything you've told it, at rest.

  2. Local retrieval

    Only the request decides what's relevant.

  3. 3 relevant memories

    Not a profile. Three items.

  4. Kelven

    Assembles the minimum context needed.

  5. The model that answers

    Receives the request and that context.

Precision

Four things people get told, that aren’t quite true.

  • What Kelven stores vs. what a provider processes

    These are separate questions with separate answers. Kelven may keep no memory at all while a request is still processed by an AI provider in order to be answered.

  • Local memory is not local inference

    Keeping memory on your device means Kelven doesn't need a copy in its cloud. It does not mean the answer is produced on your device — the relevant context still travels to whichever model answers.

  • End-to-end encryption has limits here

    A cloud model needs readable text to answer a question. So we won't describe a cloud-answered request as end-to-end encrypted. Storage encryption and transport encryption are real; inference-time secrecy is not.

  • Retention is per route, not one number

    Different providers retain differently, and their policies change. Route-level retention will be stated where we can verify it, with the date we last checked.

Status

Every privacy capability, with its real status.

One status vocabulary, used the same way across this whole site: Available — working in the product today. Beta — working, still being hardened — expect rough edges. Planned — designed and on the roadmap, not built yet. By arrangement — delivered as part of a contract, not self-serve.

  • Available

    Privacy modes

    Standard, Private, Confidential and Local Only as one control in the composer, not a settings page.

  • Available

    Provider transparency

    Every answer shows which route handled it, why it was chosen, what context was shared and what was replaced before sending.

  • Available

    Bring your own AI

    Connect your own OpenAI or Google credentials for a direct relationship and your own billing, with routing and minimisation unchanged.

  • Available

    Portable export

    One structured export of memory, preferences, projects and instructions that you keep.

  • Beta

    Local processing

    Retrieval, classification and sensitive-data detection run on your device; on-device answering works on supported hardware.

  • By arrangement

    Kelven Private

    Organisation-controlled credentials, private memory infrastructure, retention rules, routing policies, allowlists and audit logs.

  • Planned

    Connected applications acting for you

    Approved external actions carried out on your behalf, inside the ceilings you set.

Your data is not our business model.

If improving Kelven ever involves your content, that will be an explicit choice you make — not a line in a policy document. Questions we haven’t answered here are worth asking directly.

The formal privacy policy governs; this page is the plain-language description of what Kelven does with data.