PRIVACY / PUBLIC SITE
A small public surface with a clear data boundary.
This public website accepts no holdings and creates no Qelly Portfolio user account.
What exists today
Public pages and direct email contact.
- Site traffic
- The page shell, local assets, LiveView heartbeats, and context-only BLS data may contact Qelly. Normal hosting and security logs may record request metadata needed to operate and protect the site.
- Choosing a mail link hands the message to your mail provider. You can also write directly to luis@qelly.ai.
- Interactive demo
- The visitor premise, reviewed factors, results, and evidence packet stay local in a verified browser worker. They are not sent through LiveView or an evaluation API, are not written to Qelly storage, and are not sent to third parties. This release adds no client analytics.
- Public agent endpoint
- The public agent endpoint at /demo/mcp sends bounded synthetic tool arguments to Qelly for validation and server-side evaluation. It does not accept holdings, does not create a user account, and does not persist a decision case. Its time-limited signed run reference expires within 60 minutes and contains only the reviewed synthetic scenario needed to reconstruct the result. The signature protects integrity; it does not encrypt that scenario. Do not enter confidential information in the public premise.
- Operational records
- Public-page and public-agent request logs can identify requested paths and normal security metadata. The browser-local demo does not create a server run record, while the public MCP endpoint returns a signed synthetic reference without storing a decision case. A downloaded local evidence envelope is unique to the browser and is not server-attested.
- Future workspace
- Any authenticated Portfolio workspace, customer-data processing, and retention policy will receive separate review and terms before launch.