Legal · Privacy

Privacy Policy

Last updated: May 15, 2025

Quelvo (“we,” “our,” or “us”) is committed to protecting your privacy. This policy explains what information we collect, how we use it, and the choices you have.

1. Information We Collect

Account information

When you create a Quelvo account, we collect your name, email address, and profile information provided through your OAuth provider (Google or GitHub via Clerk).

Workspace and portal data

To connect your Notion workspace, we store an encrypted OAuth access token. We do not store the content of your Notion databases — data is fetched in real time from the Notion API and cached briefly (up to 60 seconds) to improve performance.

Portal client data

Client email addresses you add to portals are stored so we can send magic-link login emails. We store only what is necessary to authenticate clients and apply your access controls.

Usage data

We collect standard server logs including IP addresses, browser type, pages visited, and timestamps. This data is used for security monitoring and aggregate analytics.

Billing data

Payment processing is handled by Stripe. We store only a customer reference ID and subscription status — never raw card numbers or full payment details.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Quelvo service
  • Authenticate you and your portal clients
  • Send transactional emails (magic links, billing receipts, digests)
  • Enforce plan limits and detect abuse
  • Respond to support requests
  • Comply with legal obligations

We do not sell, rent, or share your personal data with third parties for marketing purposes.

3. Notion Integration

Quelvo connects to your Notion workspace via an OAuth integration you explicitly authorize. We request only the minimum scopes necessary. Your Notion access token is encrypted at rest using AES-256-GCM and is never exposed to portal clients or third parties. You can revoke Quelvo’s access at any time from your Notion settings.

4. Data Sharing

We share data only with service providers necessary to operate the platform:

  • Clerk — authentication and identity management
  • Notion Labs — to query databases on your behalf
  • Stripe — payment processing
  • Resend — transactional email delivery
  • Vercel — infrastructure and hosting (including Blob storage)
  • Neon — PostgreSQL database hosting
  • Upstash — Redis caching

Each provider processes data only as directed by us and under appropriate data processing agreements. We may also disclose information if required by law or to protect the rights and safety of Quelvo and its users.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law or legitimate business interests (e.g., billing records).

Portal client email addresses are removed when you delete the corresponding portal or client record. Magic-link tokens expire after 15 minutes and are deleted immediately upon use.

6. Security

We apply industry-standard security practices: encryption in transit (TLS), encryption at rest for sensitive credentials, HTTP-only cookies for session tokens, and rate-limiting on authentication endpoints. However, no system is perfectly secure. If you believe your account has been compromised, contact us immediately at info@quelvo.co.

7. Cookies

Quelvo uses cookies for session management. Portal client sessions use an HTTP-only, SameSite=Lax cookie scoped to the portal slug. We do not use third-party advertising or tracking cookies. Vercel Analytics collects anonymous, privacy-preserving usage data with no cross-site tracking.

8. Your Rights

Depending on your location, you may have rights to access, correct, or delete your personal data, object to processing, or request data portability. To exercise any of these rights, email us at info@quelvo.co. We will respond within 30 days.

If you are located in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

9. Children

Quelvo is not directed at children under 13. We do not knowingly collect personal information from children. If you believe we have collected data from a child, contact us and we will delete it promptly.

10. Changes to This Policy

We may update this policy from time to time. When we do, we will update the “Last updated” date at the top and, for material changes, notify account holders by email. Continued use of Quelvo after changes take effect constitutes acceptance of the revised policy.

11. Contact

Questions about this policy? Reach us at info@quelvo.co.