Privacy notice
Data Qelly may process
When a user activates cloud services, Qelly may process an email and provider identity subject, optional display name, workspace membership, saved calculations and revisions selected for synchronization, pending sync operations, support messages, deletion requests and security audit events.
Data Qelly does not request
Qelly does not request or store wallet private keys, seed phrases, brokerage passwords, exchange credentials, payment-card details or custody information. Do not submit these through feedback or imports.
Purpose and minimization
Account data supports verification, sign-in and recovery. Saved records support the user-requested cloud lifecycle. Provider cache protects quotas. Audit data supports security and authorization. Optional analytics must remain coarse and must exclude calculation inputs, outputs, emails, tokens and imported file contents.
Storage and service providers
The deterministic fallback uses browser storage under the user's control. The public beta uses Supabase Free Postgres and Auth for authenticated cloud services and Cloudflare Pages and Pages Functions for the public edge runtime. Their service terms and geographic processing may apply. Optional Cloudflare Web Analytics is not required for Qelly operation and is blocked by the production content-security policy unless separately approved and disclosed.
Retention, export and deletion
Local records remain until the user removes browser data. Cloud records remain until deleted by the user or the account is deleted, subject to the minimum security or legal retention required by the service. Authenticated users can request a versioned export and deletion of user-owned cloud data without sending passwords or tokens to support.
Security
Qelly separates public and server-only configuration, applies row-level authorization, validates state-changing requests, rate-limits protected writes and redacts secrets and financial payloads from logs. No internet service can be guaranteed perfectly secure.
Contact
Use the support page for privacy requests. Do not include sensitive financial data, credentials or identity documents.