Skip to content

Last updated September 2026

Privacy Policy

Kelven exists to reduce how much of you AI companies get to see. This page describes exactly what we hold, who else touches it, and how to take it back.

Who we are

Kelven is the trading name of Kelven, a sole proprietorship based in the United States. We are the data controller for the personal information described here. Questions go to hello@kelven.ai. Paddle, our reseller and merchant of record, is a recipient of purchase information for payments, subscription management, tax compliance and invoicing.

What we hold

  • Account details: your email address and sign-in identity, so you can sign in.
  • Memory you asked Kelven to keep in the cloud: facts, preferences and project context you saved. Anything you marked as device-only is never uploaded.
  • Settings: your privacy mode, sensitive-category rules, provider permissions and model preferences.
  • Plan and usage records: your subscription state and monthly request counts, used to apply your allowance.
  • Operational records: request routing metadata (which model handled a request, how long it took, how much was protected) and failure records containing an error type, a page and a short sanitized message.
  • Connected applications: which applications you authorised, what they may read, and a log of what they retrieved — counts and outcomes, never the content.

What we don't hold

  • We don't store the maps between your real values and their placeholders on a server. Those are created on your device for one request and dropped when it finishes.
  • We don't put message content, memory content or attachment content into logs, failure records or analytics.
  • We don't sell your data, and we don't use it to train AI models.
  • We don't hold your card details — Paddle, our merchant of record, does.

How a request travels

Sensitive detail is found and protected on your device before anything is sent. Depending on the mode you choose, a model provider receives either your text as written, a version with identities replaced by placeholders, or nothing at all — in Local Only the model runs on your device, and in Offline no network request is made for the task. The Privacy Center explains each mode.

Companies that process data for us

These are the only processors involved in running Kelven today:

  • OpenAI — processes requests routed to its models.
  • Google — processes requests routed to Gemini models.
  • Lovable — hosting, the database and authentication behind your account, and the gateway that reaches the model providers above.
  • Paddle — payments, subscription billing and tax compliance as the merchant of record for our orders.
  • DuckDuckGo and Microsoft Bing — receive a search query when a request needs current information, in modes where live search is allowed.

If we add a processor we will update this list. Providers are US companies and requests are routed to US regions.

How long we keep things

  • Memory, projects, settings and connected-application permissions: until you delete them or erase your account.
  • Usage counters and plan records: kept while your account exists, because they determine your allowance and billing.
  • Routing and connected-application access logs: kept so you can audit what happened; removed when you erase your account.
  • Failure records: metadata only, kept for operational debugging.
  • Erasing your account deletes all of the above and the sign-in itself. It is immediate and cannot be undone.
  • Model providers apply their own retention to the requests they receive. Kelven records what each provider states, and rules a provider out of Confidential mode when its terms don't meet that bar.

Your controls

  • Export: download everything Kelven holds for you as one file, from Your account.
  • Erase: delete your account and its memory for good, from Your account.
  • Sign out everywhere: end every session on every device.
  • Revoke: turn off any connected application's access at any time.
  • Choose the boundary: set your privacy mode, decide which categories are always protected, and refuse a provider permission to ever see an exact value.

Children

Kelven is not intended for children. We don't knowingly collect information from anyone under the age at which they can agree to these terms where they live.

Contact

Privacy questions, data requests and complaints go to hello@kelven.ai. We answer data requests within 30 days.