KelvyrKelvyrHire a bird →
PRIVACY POLICY · LAST UPDATED 18 JULY 2026

Your data
stays yours.

The same plain-language rule that governs our employees governs this document. No dark patterns, no data hostage-taking, no fine print that says the opposite of the headline. Here's exactly what we collect, why, and how to make it disappear.

THE 20-SECOND VERSION
  • We collect only what an employee needs to do its job, plus the basics to run your account.
  • The golden rule: a bird can only ever touch accounts your own login can touch.
  • We never sell your data or train public models on your private business information.
  • Disconnect anytime — access dies instantly, and you can export or delete your workspace.
1 · What we collect

Three buckets, nothing hidden:

Account data — your name, email and workspace settings, so we can log you in and send reports. Connected-service data — when you link Google Ads, Search Console, or any tool via Equipment, your employees read the data they need to work (campaigns, search terms, rankings, tickets). Product usage — the actions your birds take, the reports they generate, and the ledger of what happened, so the office actually functions and you have a record.

IN PLAIN ENGLISH

We hold the keys to your connected accounts and a memory of the work — because that's the job. We don't scrape your inbox "just in case", and nothing you didn't connect is ours to see.

2 · How we use it

To run your employees, deliver your morning reports, keep the cause-and-effect ledger, and improve the product. That's the whole list. We do not sell your data, rent it to advertisers, or use your private business information to train models that other companies' birds can see. Aggregate, de-identified signals (e.g. "reports load slowly on large accounts") may guide engineering — never anything that identifies you or your customers.

3 · Your connected accounts

The golden rule is enforced in code: an employee can only ever access what your own Google (or other) login can access. Where a service offers OAuth, you authenticate on their page — we receive a revocable token, never your password. API keys and tokens are encrypted at rest (AES-256-GCM) and transmitted only to the service they belong to. Revoke access from your settings or the provider's, and the connection goes dark immediately.

4 · Who we share it with

Only the infrastructure that makes the product run: our cloud hosting, the AI model providers that power the employees, and the services you explicitly connect. Each is bound to process data on our instructions and protect it. We disclose data to authorities only when legally compelled — and, where the law allows, we'll tell you first. We never share your data for anyone else's marketing.

5 · How long we keep it

While your account is open, so your employees keep their memory and the ledger stays intact. Delete your workspace and we remove your personal data and connection tokens within 30 days, except the minimum we're legally required to retain (e.g. billing records). Cached data from disconnected services is purged promptly.

6 · Your rights & choices

You can access, correct, export or delete your data, and object to or restrict certain processing — rights granted under GDPR, CCPA and similar laws, extended to everyone regardless of where you live. Your memory and ledger are yours to export in a portable format. We will never hold your data hostage as a way to keep you subscribed. To exercise any right, email support@kelvyr.com.

7 · Security

Encryption in transit and at rest, least-privilege access for our team, and the same adversarial testing we apply to employee behavior applied to our data handling. No system is perfectly secure, but we treat a data incident the way we treat a broken rule in the constitution — as a defect to fix at the root, and to tell you about honestly and promptly.

8 · Cookies, children & changes

We use essential cookies to keep you signed in and a minimal set of privacy-respecting analytics to understand product usage — no third-party ad trackers. Kelvyr is for businesses and isn't directed at children under 16. If we materially change this policy, we'll notify you in the product before it takes effect; the "last updated" date above always reflects the current version.

Questions about your data?

A real person answers. Write to support@kelvyr.com and we'll get back to you. See also our Terms of Service.