Privacy Policy for Kepler
Last updated: January 4, 2026
1. Introduction
Welcome to Kepler ("we," "our," or "us"). We provide an AI-powered data analyst service that allows users to analyze their data using Python code generation. We are committed to radical transparency regarding how your data is processed and secured.
2. Information We Collect
A. Personal Information
- Account Data: Your name, email address, and profile picture (via Google Sign-In).
- Billing Data: Processed securely by Stripe. We do not store credit card details or billing addresses on our servers.
B. Connected Data (Google Sheets & Files)
When you connect a Google Sheet or upload a file for analysis:
- File Access: We access only the specific spreadsheets or files you authorize.
- Data Storage: We download a copy of the file to our secure cloud storage (Cloudflare R2) to allow our analysis engine to read it.
- Metadata: We store file names, sheet names, and column headers to help you organize your workspace.
C. Usage & Generated Content
- Chat History: We store the questions you ask and the text answers generated by Kepler.
- Logic Logs: We store the Python code snippets generated by the AI and the execution results (charts, tables, logs) so you can review the analysis history.
3. How We Use Your Data
We use your data strictly to provide the analysis service. We do not use your data to train our AI models.
- Data Analysis: We load your data into a secure, ephemeral sandboxed environment (Modal) where our AI agent executes Python code to answer your questions.
- AI Processing: We send metadata only (e.g., column names, row counts, data types) to our AI providers (Anthropic, Google, OpenAI) to generate the analysis code. We do not send your raw dataset rows to the AI provider.
- Service Maintenance: We use error logs to fix bugs and improve performance.
4. Google User Data (Limited Use Disclosure)
Kepler's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
We use limited file access permissions. Kepler can only access files you explicitly select in the file picker. Your other Google Drive documents, photos, and files remain completely private and inaccessible to Kepler, even if they're in the same folder.
Specifically:
- We only request access to files you explicitly choose to analyze.
- We do not sell your Google user data.
- We do not use your Google user data for advertising purposes.
- We do not share your Google user data with third parties, except for the sub-processors listed below required to provide the analysis service.
5. Data Sharing and Sub-Processors
We do not sell your data. To operate the service, we share data with trusted infrastructure providers:
| Provider | Purpose |
|---|---|
| Cloudflare R2 | Secure object storage for your uploaded/connected data files. |
| Modal | Isolated sandboxed environment for running Python analysis code. |
| Anthropic, Google, OpenAI | LLM providers. They receive schema/metadata only; they do not receive raw data rows. |
| Stripe | Payment processing. |
6. Data Retention and Deletion
- Retention: We retain your connected data and chat history to allow you to revisit past analyses.
- Deletion: You may request full deletion of your account and all associated data (including files stored in R2) by emailing [email protected]. We will process these requests within 30 days.
7. Security
We use industry-standard encryption for data in transit (TLS) and data at rest. Your data analysis runs in ephemeral, isolated sandboxes that are spun down when not in use.
8. Contact Us
If you have questions about this policy, please contact us at [email protected].