Privacy at Kelavi
Your life map is personal. We think your privacy should be understandable too.
Privacy in 30 seconds
- · Your exact locations and dates are encrypted before they're ever saved.
- · A photo only leaves your device if you choose to keep it as a memory.
- · Your map is private by default — only you can see it until you decide otherwise.
- · We don't use your data for advertising, and we have no analytics running today.
- · You can permanently delete your account and everything in it, at any time.
1. What Kelavi needs
An email address to create your account, and the photos you choose to upload. That's it — Kelavi doesn't ask for your name, a phone number, or payment details to use the core product.
2. What happens when you add photos
Reading a photo's location and date, and checking whether it's sharp/high-resolution enough and not a near-duplicate of one you just added, all happen on your own device — before anything is uploaded. You then choose, per photo, whether to keep it as a “memory” (the photo itself is kept) or just mark the place and date (the photo file never leaves your device).
3. What we store
- Precise location and date — encrypted (AES-256-GCM) before it's ever written to our database. Only ever decrypted for you, or for someone you've shared your map with.
- Photos you keep as memories — stored in a private area that isn't publicly accessible; every view is a short-lived link generated at the moment your map is actually opened.
- City and country names — resolved once when you add a photo (so chapters can show “Lisbon” instead of just coordinates), stored as plain text. This is less precise than the exact coordinates already shown on the map itself to anyone allowed to view it, so it isn't a separate exposure.
- A coarse, approximate location marker (accurate to roughly 150km — nowhere near precise enough to identify a specific place) and the year a photo was taken. Not currently used for anything visible in the product; kept ready for a possible future anonymized map feature that doesn't exist yet.
- Map title and chapter notes — plain text you've written yourself.
- Your sharing setting and any invite/public links that come with it.
- Account information — your email address, display name, timezone (used only to know your own local day for something like “on this day”), and your notification/email preferences.
- A short record of what Kelavi sent you — the type and channel (email/push) of each message and when, so we don't send you the same thing twice or more than the limits described below. Never the content of the message itself, and never your precise location.
- A basic signal that your shared map was viewed — enough to tell you “someone looked”, never who. Automated/crawler requests (e.g. a messaging app generating a link preview) and your own visits to your own shared link are excluded before anything is recorded.
4. What we don't use your data for
Kelavi doesn't sell your data, doesn't use it for advertising, and doesn't build a profile of you to target ads elsewhere. There is no advertising or marketing-tracking technology in the product today.
5. Location data
Precise coordinates and capture dates are encrypted with a key that only Kelavi's servers hold — never a plain-text database column. They're decrypted, server-side, only to render your map (or a map you've been given access to).
6. Memories/photos
A photo you don't explicitly keep as a memory is never uploaded — Kelavi only ever sees what it needs to place a dot on the map (location and date), read on your own device. A kept memory photo lives in a private storage area and is only ever served through a short-lived signed link, never a public URL.
7. Private / Invite / Public
Your map is private by default — visible only to you. Invite only lets you generate a link you control and can revoke at any time. Public makes your map reachable by anyone who has the link — it is never listed anywhere or made searchable, and switching to it is always something you choose explicitly, never a side effect of another action like sharing.
8. Notifications
Kelavi only asks for notification permission when you explicitly choose to turn notifications on — never automatically. Account has four categories (memory reminders, map activity, sharing activity, and a monthly reflection), each with its own email and/or push toggle, so turning one off never silently affects another. Kelavi updates (product news) is a separate, always-off-by-default choice, kept apart from anything about your own map. Messages are only ever sent when something in your own map/sharing history actually justifies it — Kelavi doesn't send reminders on a fixed schedule just to bring you back, and caps how often it sends anything at all (at most a couple of pushes and one email a week, one reflection a month).
9. Analytics cookies
Kelavi has no analytics provider connected today. If that changes, analytics will stay off until you explicitly allow it — see Cookies for the full, up-to-date breakdown and your current setting.
10. How to delete your data
From Account, deleting your account removes your stored photos immediately, then deletes the account itself — which automatically removes every place, chapter note, share link, and notification setting tied to it. This happens right away, not after a waiting period, and can't be undone.
11. Your rights
You can access, correct, export (by viewing your own map), or delete your data at any time from Account — most of this is self-service by design, rather than something you need to request from us.
12. Contact
TODO / configuration placeholder — a contact address for privacy questions hasn't been configured for this project yet.