Kelpie privacy policy
Last updated 2026-10-04. Français
Kelpie is a personal assistant for your memory and your tasks, operated by an individual in Ontario, Canada. We will tell you who, on request. This page says what we collect, why, where it goes, how long we keep it, and what you can do about it. It follows Canada's Personal Information Protection and Electronic Documents Act and Québec's Act respecting the protection of personal information in the private sector.
Who is responsible
The person in charge of the protection of personal information for Kelpie answers every question, request and complaint about your information. Write to privacy@northlightfoundry.com.
What we collect
- From your sign-in: the identifier your sign-in provider (Google or GitHub, through WorkOS) gives us for you, and your email address. We do not keep your name or your picture.
- What you put in: your captures, tasks, projects, memories and daily plans.
- Your settings: your time zone, whether and when we email you, and the devices you have signed in on.
- Your acceptance: which version of these terms and this policy you accepted when you made your account, and when.
- Records the service keeps about its own work: what you decided in your confirmation queue, the "wrong to bring up" and "helpful" buttons you pressed, which emails we sent and whether they were delivered, and which tasks were moved between projects. These hold identifiers and outcomes, not your words.
- Your network address, held in the service's memory only, to limit how fast one address can sign in or write. It is not written to our logs or our database.
We use four cookies, all needed to sign you in and keep you signed in: a session cookie that lasts up to 12 hours, and three that last minutes while a sign-in, or the making of your account, is in progress. There are no advertising or analytics cookies, and no other site's scripts run on our pages.
Why we collect it
- to sign you in and keep your account separate from everyone else's;
- to store, organize and show you what you put in;
- to send you the daily email you chose, which carries a count and a link, never what you wrote;
- to keep the service working and safe: limiting abuse, and learning that an error happened;
- to measure, in totals that name no one, whether the service does its job: how often a person moves a task we filed, how often a memory is marked wrong to bring up, and whether our emails arrive;
- to delete your account when you ask.
We do not sell your information, use it for advertising, or share it with anyone for their own purposes.
Information from Google
If you sign in with Google, we receive your Google account's identifier and email address, through WorkOS. We use them only to sign you in and to send the emails you chose. We store them with your account, share them with no one but the providers listed below, and delete them with your account.
Who else handles it, and where
| Provider | What they receive | Where |
| DigitalOcean | Everything above: it runs our servers and our database | Toronto, Canada |
| Amazon Web Services (S3) | An encrypted copy of the database, which only we can read, kept seven days | Montréal, Canada |
| WorkOS | Your sign-in: your identifier and email address. WorkOS also keeps the name and picture your Google or GitHub account shows, which Kelpie does not keep | United States |
| Google or GitHub | That you signed in to Kelpie, if you use them to sign in | Their own locations |
| Amazon Web Services (SES) | Your email address, each email's count and link, and identifiers that match its delivery report to your account | Montréal, Canada |
| Sentry | A report of an error in our code: its kind and where it happened, with no personal information | European Union |
Your information is stored outside Québec, and some of it is handled outside Canada, as the table says. There, it is subject to the laws of that place, which may allow its authorities to see it.
Kelpie does not yet use an AI model on what you write. Before it does, this page will say which provider receives what, and you will be told.
How long we keep it
- Your account and what you put in are kept until you delete your account. What you mark done, retire or correct stays in your account until then, unless you ask us to delete it.
- When you delete your account, it is removed from our database within minutes, and from our backups within seven days, when they expire. Your sign-in is deleted at WorkOS at the same time.
- Your network address is kept in memory for as long as the service needs it to limit sign-ins and writes, and is gone when the service restarts.
- Our providers keep their own records of delivery and security under their terms.
What you can do
- See and correct your information. What you put in is in the app, where you can change it, and memories can be corrected.
- Get a copy. Ask us at privacy@northlightfoundry.com for a copy of the information we hold about you, and we will send it within 30 days, in a structured, commonly used format (JSON) you can take elsewhere. There is no download button yet.
- Delete a single item. What you mark done, retire or correct stays in your account. Ask us at privacy@northlightfoundry.com to delete a particular item, and we will within 30 days.
- Stop our emails from Settings, or with the link at the foot of any email.
- Withdraw your consent and delete your account at any time. Here is how. If you signed in through Google or GitHub, you can also remove Kelpie's access in that service's settings.
Complaints
Write to privacy@northlightfoundry.com. We will acknowledge your complaint and answer it within 30 days. If you are not satisfied, you can complain to the Commission d'accès à l'information du Québec, or to the Office of the Privacy Commissioner of Canada.
How we govern your information
A summary of our governance policy, which the person in charge of the protection of personal information approves:
- Who is responsible: the person in charge of the protection of personal information, who is also the only person with access to our servers and database.
- Keeping and destroying: as "How long we keep it" says above. An account is never kept after it is deleted.
- Before information leaves Québec, or a new provider receives it, we assess how it will be protected, and put the provider's obligations in writing.
- Incidents: we record every incident affecting personal information. If one creates a risk of serious injury, we tell you and the Commission d'accès à l'information, and the Office of the Privacy Commissioner of Canada where its law requires.
- Requests and complaints are answered within 30 days, as below.
How we protect it
Every connection to Kelpie is encrypted. Each account's information is kept apart from every other account's by the database itself, not only by our code. Our backups are encrypted before they leave our database's provider. Access to our servers and database is limited to the people who run Kelpie.
Age
Kelpie is for people 18 and older. We do not knowingly collect information from anyone younger.
Changes to this policy
When this policy changes, we update this page and its date. Before a change in who receives your information or what we do with it, we will tell you.