Privacy Policy

Effective August 12, 2026

Who we are

Kelly (kelly-hq.com) is an AI assistant for real estate photographers. It connects to the tools you already use — your scheduling platform (Aryeo or HDPhotoHub), Dropbox, and Google Calendar — and acts on them at your direction: answering questions about your schedule, booking and rescheduling shoots, delivering media, editing photos, and running the daily automations you configure.

Questions or requests about your data: support@kelly-hq.com.

What we collect

Account information. Your email address, password (stored as a secure hash by our authentication provider), business timezone, and the preferences you set (editing style, saved notes, automation settings).

Conversations. Your chat messages with Kelly, Kelly's replies, images you attach, and a record of the actions (tool calls) Kelly took in a conversation so she can remember context between messages.

Connected-service credentials. When you connect an integration, we store the API key or OAuth token needed to act on your behalf. Credentials are encrypted at rest with a key held outside the database.

Connected-service data. Appointments, orders, clients, files, folders, and calendar events that Kelly reads from your connected services in order to answer you or run your automations. This data is processed when you ask for it; portions that appear in a conversation (for example, a schedule Kelly summarized for you) are retained as part of that conversation history.

Usage and billing records. Photo-edit usage events, automation run history, and — when subscriptions launch — billing status from our payment processor. We never see or store full card numbers.

How we use it

Solely to provide Kelly: answering your requests, taking the actions you approve, running the automations you enable, sending the emails you configure (for example, media-delivery emails to your editor), troubleshooting problems, and billing. We do not sell your data, share it with third parties for their marketing, or use it for advertising.

Google user data

If you connect Google Calendar, Kelly requests the narrowest scopes that support its features: viewing, creating, changing, and deleting events on calendars you own, and viewing your list of calendars.

Kelly accesses your calendar data only when you ask (for example, “what's on my calendar this week?” or “move the Main St shoot to 10:30”). Event details Kelly retrieves for you may be retained in your conversation history, like any other conversation content. Calendar data is never used for advertising, never sold, and never shared with third parties except the service providers listed below acting on our behalf. Google user data is not used to develop or train generalized artificial-intelligence or machine-learning models.

Kelly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google Calendar at any time from Settings → Integrations — Kelly revokes its access with Google and deletes the stored token. You can also revoke access from your Google Account's third-party connections page.

Service providers

Kelly runs on infrastructure and AI services that process data on our behalf, under their own confidentiality and data-protection terms: Supabase (database and authentication), Vercel (hosting), Anthropic (the AI model behind Kelly's chat — content of your conversations, including data retrieved from connected services, is sent to Anthropic's API to generate responses; Anthropic does not train models on this API data), Google (AI photo editing and voice transcription), Resend (email delivery), and Stripe (payments). We share only what each provider needs to do its job.

Retention and deletion

Your data is retained while your account is active. You can delete individual conversations in the app at any time, and disconnect any integration from Settings → Integrations (which deletes the stored credential and, where the service supports it, revokes the grant). To delete your account and its data entirely, email support@kelly-hq.com and we'll complete the deletion within 30 days.

Security

All traffic is encrypted in transit (HTTPS). Connected-service credentials are encrypted at rest with a key stored outside the database. Database access is protected by row-level security so each account can only reach its own records. No system is perfectly secure — if we learn of a breach affecting your data, we'll notify you promptly.

Changes to this policy

We'll update this page when our practices change and revise the effective date above. Material changes will be announced in the app or by email.