Privacy Policy
The company responsible for Kelvin Code and this policy is ANDERSON DE ALMEIDA MELO TECNOLOGIA DA INFORMACAO LTDA. Contact for support, privacy and requests about your data: security@kelvincode.com.
Kelvin Local — the app you download today — runs entirely on your machine. The contents of your sessions, screens and apps are NEVER sent to our servers: there is no server of ours in that path.
When you connect a local MCP host such as Claude Desktop, Kelvin gives that host only the inputs and outputs you or the agent request — for example, a capture returned by an action. This exchange does not pass through Kelvin servers, but the host and model provider you chose may process it under their own terms and privacy settings.
Kelvin Code Cloud is a separate, optional product, in closed alpha. When you opt into it, what leaves your machine is the app that will run, the evidence of the run — screen captures, the step by step and the hashes — and, in a live session, the screen images. There is no video in that path: neither side has anywhere to put one. Your Mac connects outbound only and exposes no shell, path or secret.
Retention, said the way it actually works today: what you sent to the Cloud stays for as long as your organization exists. Nothing is deleted on a schedule — no process sweeps evidence, and an expiry shown on a screen is the ceiling of what that package could survive, never a countdown.
To have something deleted, write to security@kelvincode.com and say what: we delete it by hand, because there is no button and no routine that does it on its own. The audit trail does not go with it — a trail that could be erased by removing its subject would not be an audit trail.
What does get deleted is a room's state when it ends: chat, proposals, tickets and seats. No storage is public, and the signed addresses that serve the images last minutes, not days.
Cloud sub-processors: Cloudflare (control plane, database and evidence storage), Vercel (the dashboard and this site) and Brevo, which delivers the only e-mail Kelvin sends — the named invitation to read a piece of evidence. Brevo receives that address in order to deliver the message; we do not keep the address, only a fingerprint of it.
About that e-mail, something we would rather not have had to write: the provider account still has its default tracking on, so the message being opened and the accept link being clicked both go through it. The message itself carries no image, no remote font and no attachment — what tracks there is the account, not the text you receive.
Data follows the regions and jurisdictions contracted with those providers. The Cloud Alpha does not promise Brazilian data residency — anyone who needs that stays on Kelvin Local.
The app you download counts nothing about how you use it: there is no usage collection and no failure report sent anywhere. What it fetches on its own is the update feed published on this site, to know whether a new version exists.
This site uses anonymous analytics only after your consent. We do not sell data, and nothing that passes through the Cloud trains any model. A privacy question, support request or request about your data: security@kelvincode.com.
PortuguêsEnglish