Kepla ("Kepla," "we," "us," "our") operates getkepla.com and related services for photography businesses, currently in pre-launch. Kepla is the data controller for personal data described in this policy. Contact for all privacy matters: support@getkepla.com. We aim to acknowledge privacy inquiries within 72 hours.
This policy covers data processed when you visit our website, join our waitlist, use our interactive demos or our free tools (Kepla File Transfer, the metadata remover, the RAW to JPG converters), connect third-party accounts (such as Instagram), or communicate with us. It does not cover third-party websites we link to, which have their own policies.
If you received a download link from someone else, you are a recipient of a transfer, not a Kepla account holder. What we hold about you is covered in the file-transfer rows of Section 3. The per-person part of it (your address, the token in your link, when you opened it, whether you downloaded) is deleted when the transfer expires or is revoked. The sender's own record of the transfer, which lists the addresses it was sent to, keeps the sender's 12-month clock described in Section 8.
We collect no more than the following. If it is not listed here, we do not collect it.
| Category | Data | Source |
|---|---|---|
| Waitlist signup | Name, email address; optionally: studio name, role, primary shoot type, current tools, survey answers, how you heard about us | Provided by you |
| Referral | A randomly generated referral code for your signup; the referral code of whoever referred you, if any | Generated by us / your referrer's link |
| Attribution | UTM parameters and referring-page URL at the time of your visit | Your browser |
| Demo interactions | Text you submit to interactive demos and the AI responses generated | Provided by you |
| Website ingestion | Publicly available pages of a website URL you voluntarily submit to the booking demo | Public web, at your direction |
| Instagram (only if you connect) | See Section 5 | Instagram API, with your consent |
| Free file transfer (sender) | Your email address (required); your name or studio name (optional, shown to your recipients); the recipient email addresses you enter; the title and message you write; the number of files, total size and ZIP name; a truncated one-way hash of your IP address. We also keep a per-sender-email row with running totals (how many transfers, how many bytes, how many files, first and last send) | Provided by you |
| Free file transfer (recipients, opens and downloads) | For each address the sender enters we create a row holding that address and a unique token, which is embedded in that recipient's link so that opening and downloading can be attributed to them without anyone typing anything. Each time a transfer is opened or downloaded, from an emailed link or a shared one, we record an event: the kind (opened or downloaded), the time, the archive size for a download, a truncated keyed hash of the IP address, and the browser's user-agent string (up to 300 characters). The sender can see, per recipient, whether and when their transfer was opened and downloaded, and receives one email the first time each emailed recipient downloads. We never show a recipient's activity to other recipients | The sender (your address); your browser (opens and downloads) |
| Free file transfer (the files) | The files you send, packaged by your browser into a single ZIP and uploaded from your browser straight to encrypted storage. Nobody at Kepla opens, inspects, scans or indexes their contents, and the file bytes never pass through our servers | Provided by you |
| Browser-only tools | No file content, no filename. We record that a tool was opened and, when files go through it, how many and their total size, with a truncated keyed hash of your IP address for abuse control. The metadata remover and the RAW to JPG converters run entirely in your browser; your photos are never uploaded to us or to anyone else | Not collected |
| Guide subscribers | Your email address, the guide you asked us to send, and the page you asked from. Used to send that guide and one email when a new guide is published, nothing else; you are never added to the waitlist or any other list | Provided by you |
| Free tool feedback | A star rating, an optional comment, and a truncated one-way hash of your IP address. This includes the delivery rating a transfer recipient can leave after downloading, which is about Kepla and never reaches the sender. No email address and no identity are requested or stored | Provided by you |
| Technical | IP address (used transiently for rate limiting and abuse prevention; for file transfers and tool feedback a truncated keyed hash is stored with the record, computed under a secret that exists only in our server configuration, so it cannot be reversed to the address without that secret); the browser's user-agent string, stored with file-transfer open and download events; coarse analytics (page views via Vercel Analytics, which does not use cookies for tracking) | Your browser |
What we deliberately do not do: we do not use third-party advertising trackers or advertising cookies; we do not buy data about you from data brokers; we do not collect payment card data during the waitlist phase; we do not add file-transfer senders or recipients to the waitlist, to any mailing list, or to any marketing audience, and those addresses live in their own tables, kept apart from the waitlist for exactly that reason; we do not open, scan, index or train on the files you send through the transfer tool; we do not knowingly collect data from anyone under 18 (our services are for business users; if you believe a minor's data reached us, email us and we will delete it promptly).
We will not use your personal data for a materially new purpose without informing you first. We do not sell personal data and have not sold personal data; we do not "share" personal data for cross-context behavioral advertising as defined by the California Consumer Privacy Act (CCPA/CPRA).
When our Instagram connection feature is available and you explicitly authorize it through Instagram's own consent screen, we access only the scopes you approve. At most, that is: your basic profile information (username, account name, account type) and your media (posts, captions, and media URLs). We commit to the following, without exception:
We use the following service providers, each bound by data-processing terms, each receiving only what its function requires. We do not permit processors to use your data for their own purposes.
| Provider | Function | Data touched |
|---|---|---|
| Vercel | Hosting, serverless functions, privacy-respecting analytics | All site traffic (transit); coarse analytics |
| Neon | Database (encrypted at rest) | Waitlist, survey, referral, demo-interaction, file-transfer and tool-feedback records |
| Backblaze (B2) | Encrypted object storage for the free file transfer | The ZIP you upload, until the transfer expires |
| Resend | Transactional and update email delivery | Name, email, email content |
| Google (Gemini API) / OpenAI | AI generation for demos and product features | Text you submit to demos; public website text you direct us to read |
If this list changes, we will update this page before the new processor handles personal data.
The full description of these measures, in plain language, is on our Security page.
No internet service can guarantee absolute security; we commit to the measures above and to remedying gaps promptly when found.
| Data | Retention |
|---|---|
| Waitlist and survey records | Until launch onboarding completes or you request deletion, whichever is first; unconverted waitlist records are deleted no later than 24 months after our public launch |
| Demo interaction logs | Maximum 24 months from creation, then deleted or irreversibly de-identified |
| Instagram-derived data | Until disconnection or deletion request; then per Section 5 |
| Transferred files | The link stops working at the expiry the sender chose, which is at most 3 days from upload. The stored files are then deleted by a scheduled job that runs once a day, so they leave storage within 24 hours of expiry, with a storage-level backstop no later than 6 days after upload. There is no recycle bin and no way to extend or recover an expired transfer |
| File-transfer records (sender email and name, recipient addresses, title, message, file counts and sizes) | Maximum 12 months from creation, then deleted; the record outlives the files so we can answer "what happened to my transfer" and investigate abuse |
| Per-recipient records and open/download events | Deleted when the transfer expires or is revoked, at the next daily run. Two counts survive on the transfer record without any per-person detail: how many times it was opened and by how many distinct viewers |
| Per-sender transfer totals | Maximum 24 months from the last transfer, then deleted |
| Guide subscriber records | Until you reply "stop" to any guide email, then deleted at the next quarterly review; inactive records deleted 24 months after the last email you asked for |
| Free tool feedback | Maximum 24 months from creation, then deleted |
| IP addresses (rate limiting) | Transient, in-memory; not written to permanent logs by our application. Where a record needs an abuse marker (file transfers, tool feedback) we store a truncated keyed hash instead of the address, deleted with its record |
| Deletion-request records | Minimal record retained as evidence of compliance |
Our providers process data in the United States. Where data of EU/UK residents is transferred, our providers rely on recognized safeguards (such as Standard Contractual Clauses and, where applicable, the EU to US Data Privacy Framework). By using the service you acknowledge processing in the United States.
Regardless of where you live, we extend these rights to every user: access (a copy of your data), rectification (correction), erasure (deletion), restriction and objection (limits on our processing), and portability (a machine-readable export). Exercise any of them by emailing support@getkepla.com; identity verification and timelines are described in the Data Deletion Instructions. We will never discriminate against you for exercising privacy rights.
EU/UK residents: you additionally have the right to lodge a complaint with your supervisory authority. California residents: the rights above operate as your CCPA/CPRA rights to know, delete, correct, and opt out; as stated in Section 4, we do not sell or share personal information, so there is nothing to opt out of. We honor Global Privacy Control signals where legally required.
Waitlist members receive occasional product updates. Every email includes a plain-language way to stop them (reply "unsubscribe"); requests are honored within 10 days and typically immediately. Transactional emails (e.g., a signup confirmation you triggered) are sent as part of the service you requested.
Material changes will be posted here with a new effective date and version number. For material changes affecting data we already hold about you, we will notify waitlist members by email before the change takes effect. We keep prior versions available on request.
support@getkepla.com: for privacy questions, rights requests, complaints, or to request this policy's history.