Privacy notice
Data Qelly may process
When a user activates cloud services, Qelly may process an email and provider identity subject, optional display name, workspace membership, saved calculations and revisions selected for synchronization, pending sync operations, support messages, deletion requests and security audit events.
Data Qelly does not request
Qelly does not request or store wallet private keys, seed phrases, brokerage passwords, exchange credentials, payment-card details or custody information. Do not submit these through feedback or imports.
Purpose and minimization
Account data supports verification, sign-in and recovery. Saved records support the user-requested cloud lifecycle. Provider cache protects quotas. Audit data supports security and authorization. Optional analytics must remain coarse and must exclude calculation inputs, outputs, emails, tokens and imported file contents.
Storage and service providers
The deterministic fallback uses browser storage under the user's control. Qelly is configured to use Supabase Postgres and Auth for governed account services and Cloudflare Pages and Pages Functions for the public edge runtime. Configuration does not by itself prove end-to-end availability. Provider service terms and geographic processing may apply. Optional Cloudflare Web Analytics is not required for Qelly operation and is blocked by the production content-security policy unless separately approved and disclosed.
Retention, export and deletion
Local records remain until the user removes browser data. When authenticated cloud services are production-proven and used, cloud records remain until deleted by the user or the account is deleted, subject to minimum security or legal retention. Governed export and deletion contracts exist, but users should not assume availability until the application reports the authenticated lifecycle as proven.
Security
Qelly separates public and server-only configuration, applies row-level authorization to public application tables, validates state-changing requests, rate-limits protected writes and redacts secrets and financial payloads from logs. No internet service can be guaranteed perfectly secure.
Contact
Use the support page for privacy requests. Do not include sensitive financial data, credentials or identity documents.