Skip to content
kepla
Try it Compare Speed Price Guides Free tools Get Early Access

Privacy Policy

Effective date: September 9, 2026 · Version 2.3 · Applies to getkepla.com and all Kepla services

1. Who we are

Kepla ("Kepla," "we," "us," "our") operates getkepla.com and related services for photography businesses, currently in pre-launch. Kepla is the data controller for personal data described in this policy. Contact for all privacy matters: support@getkepla.com. We aim to acknowledge privacy inquiries within 72 hours.

2. Scope

This policy covers data processed when you visit our website, join our waitlist, use our interactive demos or our free tools (Kepla File Transfer, the metadata remover, the RAW to JPG converters), connect third-party accounts (such as Instagram), or communicate with us. It does not cover third-party websites we link to, which have their own policies.

If you received a download link from someone else, you are a recipient of a transfer, not a Kepla account holder. What we hold about you is covered in the file-transfer rows of Section 3. The per-person part of it (your address, the token in your link, when you opened it, whether you downloaded) is deleted when the transfer expires or is revoked. The sender's own record of the transfer, which lists the addresses it was sent to, keeps the sender's 12-month clock described in Section 8.

3. Data we collect, exhaustive list

We collect no more than the following. If it is not listed here, we do not collect it.

Every category of personal data Kepla collects, the specific data in each category, and where it comes from.
CategoryDataSource
Waitlist signupName, email address; optionally: studio name, role, primary shoot type, current tools, survey answers, how you heard about usProvided by you
ReferralA randomly generated referral code for your signup; the referral code of whoever referred you, if anyGenerated by us / your referrer's link
AttributionUTM parameters and referring-page URL at the time of your visitYour browser
Demo interactionsText you submit to interactive demos and the AI responses generatedProvided by you
Website ingestionPublicly available pages of a website URL you voluntarily submit to the booking demoPublic web, at your direction
Instagram (only if you connect)See Section 5Instagram API, with your consent
Free file transfer (sender)Your email address (required); your name or studio name (optional, shown to your recipients); the recipient email addresses you enter; the title and message you write; the number of files, total size and ZIP name; a truncated one-way hash of your IP address. We also keep a per-sender-email row with running totals (how many transfers, how many bytes, how many files, first and last send)Provided by you
Free file transfer (recipients, opens and downloads)For each address the sender enters we create a row holding that address and a unique token, which is embedded in that recipient's link so that opening and downloading can be attributed to them without anyone typing anything. Each time a transfer is opened or downloaded, from an emailed link or a shared one, we record an event: the kind (opened or downloaded), the time, the archive size for a download, a truncated keyed hash of the IP address, and the browser's user-agent string (up to 300 characters). The sender can see, per recipient, whether and when their transfer was opened and downloaded, and receives one email the first time each emailed recipient downloads. We never show a recipient's activity to other recipientsThe sender (your address); your browser (opens and downloads)
Free file transfer (the files)The files you send, packaged by your browser into a single ZIP and uploaded from your browser straight to encrypted storage. Nobody at Kepla opens, inspects, scans or indexes their contents, and the file bytes never pass through our serversProvided by you
Browser-only toolsNo file content, no filename. We record that a tool was opened and, when files go through it, how many and their total size, with a truncated keyed hash of your IP address for abuse control. The metadata remover and the RAW to JPG converters run entirely in your browser; your photos are never uploaded to us or to anyone elseNot collected
Guide subscribersYour email address, the guide you asked us to send, and the page you asked from. Used to send that guide and one email when a new guide is published, nothing else; you are never added to the waitlist or any other listProvided by you
Free tool feedbackA star rating, an optional comment, and a truncated one-way hash of your IP address. This includes the delivery rating a transfer recipient can leave after downloading, which is about Kepla and never reaches the sender. No email address and no identity are requested or storedProvided by you
TechnicalIP address (used transiently for rate limiting and abuse prevention; for file transfers and tool feedback a truncated keyed hash is stored with the record, computed under a secret that exists only in our server configuration, so it cannot be reversed to the address without that secret); the browser's user-agent string, stored with file-transfer open and download events; coarse analytics (page views via Vercel Analytics, which does not use cookies for tracking)Your browser

What we deliberately do not do: we do not use third-party advertising trackers or advertising cookies; we do not buy data about you from data brokers; we do not collect payment card data during the waitlist phase; we do not add file-transfer senders or recipients to the waitlist, to any mailing list, or to any marketing audience, and those addresses live in their own tables, kept apart from the waitlist for exactly that reason; we do not open, scan, index or train on the files you send through the transfer tool; we do not knowingly collect data from anyone under 18 (our services are for business users; if you believe a minor's data reached us, email us and we will delete it promptly).

4. Purposes and legal bases

  • Operating the waitlist (position, referral tracking, product updates by email), performance of our agreement with you at your request; you may unsubscribe from emails at any time by replying "unsubscribe."
  • Running interactive demos, performance of the service you invoke; demo text is processed by AI model providers solely to generate the response you asked for.
  • Marketing attribution (which channel brought you here), our legitimate interest in measuring our own marketing; no advertising profiles are built.
  • Product improvement (aggregate analysis of demo interactions and survey answers), our legitimate interest in building the product; wherever practical we use de-identified or aggregated data.
  • Running the free file transfer (storing your files for the lifetime you choose, emailing the link to the recipients you name, emailing you a receipt, and deleting everything at expiry), performance of the service you invoke. The sender totals we keep per email address rest on our legitimate interest in understanding usage and stopping abuse of a free, unauthenticated upload endpoint; they are never used to market to you.
  • Security and abuse prevention (rate limiting, spam filtering, per-day transfer caps), our legitimate interest in protecting the service.
  • Legal compliance, where processing is required by applicable law.

We will not use your personal data for a materially new purpose without informing you first. We do not sell personal data and have not sold personal data; we do not "share" personal data for cross-context behavioral advertising as defined by the California Consumer Privacy Act (CCPA/CPRA).

5. Instagram data, strict terms

When our Instagram connection feature is available and you explicitly authorize it through Instagram's own consent screen, we access only the scopes you approve. At most, that is: your basic profile information (username, account name, account type) and your media (posts, captions, and media URLs). We commit to the following, without exception:

  • Single purpose: Instagram data is used solely to generate and maintain your Kepla studio setup (genre detection, brand-voice analysis, drafted packages, and portfolio selections for your booking page). It is never used for advertising, never used to train third-party AI models, never sold, rented, or shared with any third party except the processors in Section 6 acting on our documented instructions.
  • Data minimization: we persist only the derived setup (package drafts, voice description, selected media references, profile identifiers). We do not warehouse a copy of your full Instagram history.
  • No impersonation: we never post, comment, or message anyone from your account without a separate, explicit, revocable opt-in presented to you at the time, silence or inactivity is never treated as consent.
  • Revocation: you may disconnect within Kepla or revoke access in Instagram's settings at any time; access stops immediately upon revocation.
  • Deletion: upon disconnection or a deletion request, Instagram-derived data is deleted from production systems within 30 days and from encrypted backups within a further 30 days. See Data Deletion Instructions.
  • Platform terms: our use of Instagram data complies with Meta's Platform Terms and Developer Policies. Nothing in this policy overrides your rights under those terms.

6. Processors (sub-processors), closed list

We use the following service providers, each bound by data-processing terms, each receiving only what its function requires. We do not permit processors to use your data for their own purposes.

The closed list of processors Kepla uses, what each one does, and the data each one touches.
ProviderFunctionData touched
VercelHosting, serverless functions, privacy-respecting analyticsAll site traffic (transit); coarse analytics
NeonDatabase (encrypted at rest)Waitlist, survey, referral, demo-interaction, file-transfer and tool-feedback records
Backblaze (B2)Encrypted object storage for the free file transferThe ZIP you upload, until the transfer expires
ResendTransactional and update email deliveryName, email, email content
Google (Gemini API) / OpenAIAI generation for demos and product featuresText you submit to demos; public website text you direct us to read

If this list changes, we will update this page before the new processor handles personal data.

7. Security

  • All traffic is encrypted in transit (TLS/HTTPS, with HSTS enforced). Data is encrypted at rest by our database provider.
  • Access to production data is restricted to the founder and protected by multi-factor authentication on all provider accounts.
  • API credentials are stored in managed environment variables, never in code or URLs; administrative endpoints require authenticated keys and are rate-limited against brute force.
  • We apply standard hardening (parameterized database queries, input validation and length limits, honeypot and rate-limit abuse controls, security headers including anti-clickjacking and MIME-sniffing protections, CSV-injection neutralization on exports).
  • File transfers: your browser uploads directly to a private storage bucket, so file bytes never transit our application servers. The bucket is private, never publicly listable, and downloads are served through a signed URL that is issued per request and is never valid for longer than the transfer has left to live. Expiry is enforced three ways over: the signed URL cannot outlast it, so the link stops working the moment the transfer expires; a scheduled job that runs once a day deletes the stored objects, so the bytes leave storage within 24 hours of expiry; and a storage lifecycle rule deletes anything the job missed, no later than 6 days after upload. We can also revoke a transfer at any time, which deletes the objects immediately and kills the link.
  • Breach notification: if a breach affecting your personal data occurs, we will notify affected individuals and applicable authorities without undue delay and in any case within the timelines required by applicable law (e.g., 72 hours to supervisory authorities where GDPR applies).

The full description of these measures, in plain language, is on our Security page.

No internet service can guarantee absolute security; we commit to the measures above and to remedying gaps promptly when found.

8. Retention, specific periods

How long Kepla keeps each type of data before deletion or de-identification.
DataRetention
Waitlist and survey recordsUntil launch onboarding completes or you request deletion, whichever is first; unconverted waitlist records are deleted no later than 24 months after our public launch
Demo interaction logsMaximum 24 months from creation, then deleted or irreversibly de-identified
Instagram-derived dataUntil disconnection or deletion request; then per Section 5
Transferred filesThe link stops working at the expiry the sender chose, which is at most 3 days from upload. The stored files are then deleted by a scheduled job that runs once a day, so they leave storage within 24 hours of expiry, with a storage-level backstop no later than 6 days after upload. There is no recycle bin and no way to extend or recover an expired transfer
File-transfer records (sender email and name, recipient addresses, title, message, file counts and sizes)Maximum 12 months from creation, then deleted; the record outlives the files so we can answer "what happened to my transfer" and investigate abuse
Per-recipient records and open/download eventsDeleted when the transfer expires or is revoked, at the next daily run. Two counts survive on the transfer record without any per-person detail: how many times it was opened and by how many distinct viewers
Per-sender transfer totalsMaximum 24 months from the last transfer, then deleted
Guide subscriber recordsUntil you reply "stop" to any guide email, then deleted at the next quarterly review; inactive records deleted 24 months after the last email you asked for
Free tool feedbackMaximum 24 months from creation, then deleted
IP addresses (rate limiting)Transient, in-memory; not written to permanent logs by our application. Where a record needs an abuse marker (file transfers, tool feedback) we store a truncated keyed hash instead of the address, deleted with its record
Deletion-request recordsMinimal record retained as evidence of compliance

9. International transfers

Our providers process data in the United States. Where data of EU/UK residents is transferred, our providers rely on recognized safeguards (such as Standard Contractual Clauses and, where applicable, the EU to US Data Privacy Framework). By using the service you acknowledge processing in the United States.

10. Your rights, all users

Regardless of where you live, we extend these rights to every user: access (a copy of your data), rectification (correction), erasure (deletion), restriction and objection (limits on our processing), and portability (a machine-readable export). Exercise any of them by emailing support@getkepla.com; identity verification and timelines are described in the Data Deletion Instructions. We will never discriminate against you for exercising privacy rights.

EU/UK residents: you additionally have the right to lodge a complaint with your supervisory authority. California residents: the rights above operate as your CCPA/CPRA rights to know, delete, correct, and opt out; as stated in Section 4, we do not sell or share personal information, so there is nothing to opt out of. We honor Global Privacy Control signals where legally required.

11. Email communications

Waitlist members receive occasional product updates. Every email includes a plain-language way to stop them (reply "unsubscribe"); requests are honored within 10 days and typically immediately. Transactional emails (e.g., a signup confirmation you triggered) are sent as part of the service you requested.

12. Changes to this policy

Material changes will be posted here with a new effective date and version number. For material changes affecting data we already hold about you, we will notify waitlist members by email before the change takes effect. We keep prior versions available on request.

13. Contact

support@getkepla.com: for privacy questions, rights requests, complaints, or to request this policy's history.