Privacy
Last updated 7 September 2026
Kelvix checks whether a website is technically able to appear in search results and AI answers. This page explains what it collects, what it does with anything it reads from Google Search Console, how long that is kept, and how to have it removed.
Who is responsible
Kelvix is operated by Gabriel Wang, a sole proprietor, who is the data controller for the information described here. For any question about this policy, or to ask for your data to be deleted, write to privacy@kelvixai.com.
Using Kelvix without an account
Running a check needs no account and no sign-in. When you submit a website address, Kelvix fetches up to 20 pages of that site the way a search engine would and stores what it found — the pages, the findings, and the resulting report — so the shareable report link keeps working.
Anyone who has a report link can open the report. Report links are unguessable but they are not private, so treat one as public.
Your IP address is used at the moment of submission to apply rate limits and to run the Cloudflare Turnstile anti-abuse check. It is held in a short-lived counter that resets within the hour and is not written to our database.
Connecting Google Search Console
Connecting Search Console is entirely optional. Kelvix can tell you that nothing is blocking a page; only Search Console can tell you whether Google has actually indexed it, so connecting is what turns that unknown into an answer.
What we ask for
Kelvix requests your name, email address and Google account identifier, plus one Search Console permission: https://www.googleapis.com/auth/webmasters.readonly. That permission is read-only. Kelvix uses it for exactly two things: listing the properties on your account so it can find the one matching the site in your report, and asking the URL Inspection API what Google reports about each page in that report. Kelvix never writes to, changes, or submits anything to your Search Console.
What we store
- Your Google account identifier, email address and name.
- The refresh token that keeps the connection working, encrypted with AES-256-GCM. It is never stored in readable form and is decrypted only at the moment a request to Google is made.
- Which Search Console property was matched, which permissions you granted, and when the connection was made and last used.
- What Google reported about each page in your report: the page address, the coverage state and verdict, the robots and indexing state, and when Google last crawled it. This is stored with the report so the report stays a record of what Google said on the day it was made.
What we never do
- Sell your data, or share it with anyone for advertising.
- Use it to train machine-learning or AI models.
- Use it for anything other than producing and improving your report.
- Ask for, or hold, any permission that can change your Search Console.
Limited Use
Kelvix’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How long it is kept
When you disconnect Search Console, Kelvix immediately tells Google to revoke its access, then stops using the connection. Everything it holds from that connection — the stored token, the connection record, and the indexation results Google returned — is permanently deleted within 30 days by an automated nightly job.
An account that has no connected property and has not been used for 30 days is deleted on the same schedule, along with its sign-in sessions.
The report itself is not deleted, because the share link is the product and other people may hold it. Once the Google data is removed the report simply stops showing the indexation section; it never continues to display what Google said. Crawled page content that is kept only to re-run checks is discarded after 30 days.
Removing your data
You can do either of these at any time, without asking us:
- Disconnect — from your account page, or from any report where you are connected. This revokes Kelvix’s access at Google straight away, stops any recurring checks of that site, and starts the 30-day deletion described above.
- Delete everything now — also on the report. This revokes access at Google and then deletes your account, your connection and every stored indexation result immediately, rather than waiting for the nightly job.
You can also revoke Kelvix’s access directly from your Google account at myaccount.google.com/permissions. If you would rather we did it for you, email privacy@kelvixai.com and we will action it and confirm.
Who else processes this data
Kelvix runs on a small number of providers, each acting on our instructions:
- Cloudflare — hosting, the anti-abuse check, and stored page snapshots.
- Neon — the database holding reports, accounts and connections.
- Resend — sending operational alert email to us. Your data is not sent through it.
- Google — the source of the Search Console data, when you connect it.
Cookies
Kelvix sets no advertising or analytics cookies and does not track you across sites. It sets two cookies, both strictly necessary: a short-lived one lasting 30 minutes that protects the Search Console connection while it is in progress, and a sign-in cookie lasting 30 days once you are connected. Signing out or deleting your data removes the second. Cloudflare may set its own cookie as part of the anti-abuse check.
Changes
If this policy changes in a way that affects what happens to data already collected, the date at the top will change and, where we hold an email address for you, we will tell you. Questions go to privacy@kelvixai.com.