1. Who operates Kelpie
Kelpie is a personal-finance application operated by its developer. Questions or privacy requests can be sent to tanmaynargas291@gmail.com.
2. Information Kelpie processes
Account and app data
Kelpie processes your account identifier and email address, financial accounts you create, balances, budgets, transactions, subscription records, categories, notification preferences, and other information you choose to enter or import.
Device and notification data
Kelpie stores device notification tokens and delivery preferences needed to send transaction, review, recap, and widget updates through Apple Push Notification service.
Optional files and AI features
When you choose PDF import or another optional AI-assisted feature, Kelpie processes the content you submit to provide that feature. Do not submit information you do not want processed by the service.
3. Google Gmail data
Transaction Automation requests only the https://www.googleapis.com/auth/gmail.readonly scope. This permission technically allows Kelpie to read the connected mailbox, but Kelpie limits its use to finding and processing authenticated DBS Singapore card and PayNow transaction alerts for the user-facing automation feature.
- Gmail push notifications are used only as a signal that mailbox history changed.
- Kelpie checks metadata for new Inbox messages.
- A full message body is fetched only when sender and subject match the DBS alert template and Gmail authentication results show aligned DKIM and DMARC passes for
dbs.com. - Kelpie extracts transaction reference, date, time, card suffix, currency, amount, and merchant needed to create or review a transaction.
- For authenticated DBS alerts, Kelpie stores a normalized email-text snapshot so you can compare the source alert, parser extraction, and recorded transaction. The transaction reference is masked before storage, and the snapshot is encrypted with AES-256-GCM.
- Kelpie does not retain attachments, raw MIME content, or Gmail authentication headers.
- Kelpie stores Gmail message identifiers, sync history state, parsed transaction information, an encrypted refresh token, and a keyed hash of the DBS transaction reference for security and duplicate prevention.
Google user data is not used for advertising, credit decisions, surveillance, or sale to data brokers. Humans do not read connected mailbox content except when you explicitly ask for support involving specific data, when required for security, or when required by law.
Kelpie’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How information is used
Kelpie uses information to provide account tracking, transaction automation, categorization, reconciliation, notifications, recaps, imports, support, security, duplicate prevention, and service maintenance. Data is not used for unrelated advertising or marketing profiles.
5. Service providers and disclosures
Information is disclosed only as needed to operate requested features, protect the service, comply with law, or complete a business transfer with required consent. Current infrastructure may include:
- Supabase for authentication and database hosting.
- Vercel for application hosting and server execution.
- Google Gmail API and Google Cloud Pub/Sub for Gmail connection and event delivery.
- Apple Push Notification service for notifications.
- OpenAI for optional features where you choose to submit content for processing.
- Brandfetch for subscription brand information such as merchant logos.
Kelpie does not sell personal information or Google user data.
6. Retention and deletion
Account and financial records are retained while needed to provide Kelpie or until you delete them. Disconnecting Gmail stops the watch, revokes the Google grant, and removes the stored encrypted refresh token. Existing transactions, review events, and encrypted email audit snapshots remain until separately deleted because they form part of your financial records. Infrastructure providers may retain limited logs or backups under their own retention schedules.
7. Security
Kelpie uses HTTPS in transit, access controls, service-only database tables, encrypted Gmail refresh tokens and email audit snapshots, scoped credentials, authenticated Pub/Sub delivery, and secret storage intended to reduce unauthorized access. No system can guarantee absolute security.
8. Your choices and rights
You can decline Gmail access and use other Kelpie features. You can disconnect Gmail from Transaction Automation, revoke Kelpie from your Google Account permissions, change notification preferences, and request access, correction, export, or deletion by contacting the address above. Applicable law may provide additional rights.
9. Children
Kelpie is not directed to children under 13 and is not intended for anyone unable to consent to processing of personal financial information.
10. Policy changes
This policy may be updated when Kelpie’s features or data practices change. The effective date above will be updated. Material changes to Google user-data use will be disclosed before the new use begins and may require renewed consent.
