KeyliaGet Started

Legal

What Keylia does with your data.

A plain account of what Keylia collects, where it goes, how long it stays, and how to get it out or get it deleted.

Last updated July 29, 2026

Who this is for

Keylia is a text-message assistant for residential real-estate agents working in Ontario. Two kinds of people turn up in this policy. First, you, the agent, texting Keylia from your own phone. Second, your contacts: buyers, sellers, past clients, and anyone else whose details land in the system because you put them there.

Canada's federal privacy law, PIPEDA, sets the rules we work under, alongside CASL for commercial messages and the CRTC rules for calls. Keylia is accountable for your account data. The contact records you bring with you belong to your business, and we handle that information on your instructions. None of this page is legal advice about your own compliance.

What we collect

Most of what Keylia knows, you typed into a text message. The rest arrives from the tools you choose to connect and from ordinary service logs. We collect what the product needs to draft a listing launch, get an open house on the calendar, and chase the offer paperwork. Holding less is easier than holding more, so that is the habit.

Billing runs through an outside payment processor, so card numbers never touch our servers. We see the plan you are on, the amount, and whether the charge cleared. Email support and the thread is filed with your account, so the next person who picks it up already knows which listing you were asking about.

  • Your name, mobile number, email, brokerage, and the market you work in.
  • Every text you send Keylia, the replies it sends back, and any listing photos attached.
  • Contact records you sync or upload, down to notes, deal stage, and consent history.
  • From connected tools: email threads, calendar events, CRM leads, past post history.
  • Logs of timestamps, delivery receipts, the edits you make before approving, and errors.
  • Voice call records, including recordings and transcripts, when calling is switched on.

How we use it

The short version is that we use it to do the job you hired it for. Keylia reads your messages to work out what you are asking for, gathers the context, and writes the draft. Listing launches, open-house invites, Friday newsletters, a follow-up to the buyer who went quiet after the second showing. Nothing goes out under your name until you approve it.

That same information runs the compliance check before a message sends, keeps showings and conditional deadlines on your calendar, answers your support requests, helps us find bugs and shut down abuse, and gets the invoice right. De-identified, aggregate numbers tell us which parts of the product get used and which sit idle.

We do not sell your data or your contacts' data. Nobody rents a list from us, no advertising profiles get built, and contact information is not handed to anyone who wants to market to it. Should that ever change, you would hear about it before it happened, not afterward in a changelog nobody reads.

How the AI part works

Keylia's drafting runs on Anthropic's Claude API, which we pay for as a customer like anyone else. When you ask for something, the relevant slice of your thread plus the context needed to answer it, which can include listing details, past messages, and contact notes, travels over an encrypted connection, and the draft text comes back.

Under Anthropic's commercial terms for the API, customer content is not used to train their models, and inputs and outputs are held briefly for safety monitoring under their own policy. On our side, no model is trained on your messages, on your deal notes, or on anything belonging to your contacts.

A draft stays a draft. Keylia will not publish a post, send an email blast, or text a lead until you say yes. Nothing about a person gets decided automatically from what the model writes, and you stay the one who decides what leaves the system and what gets deleted unsent.

Who handles data, and where it sits

Keylia runs on other companies' infrastructure, so your information passes through theirs on the way to you. Each provider is under contract to use it only for the service it supplies to us. None of them are free to do anything else with your listings, your contacts, or your messages.

These providers are based in the United States, which is where your information is stored and processed. We are telling you plainly because PIPEDA asks for that, and we hold providers to comparable protection. While data sits on American servers, US courts and agencies can compel access to it under American law.

  • Text messages in and out ride on Sendblue, which reports delivery status back.
  • Voice calls run through Vapi, which returns the call records to us.
  • Anthropic's Claude API turns the context we send it into draft copy.
  • Supabase (Postgres) holds the database, the uploaded listing photos, and logins.
  • None of these companies endorse Keylia. We are a paying customer, nothing more.

The tools you connect

Gmail, Google Calendar, Instagram, and kvCORE connect only if you connect them. You authorize each link, we hold it as an access token, and the scope stays narrow: reading a thread to draft the reply, dropping a showing on your calendar, publishing a post you already approved, pulling leads out of your CRM.

Disconnect any of them in settings, the token is revoked, and we stop reaching that account. Whatever was already pulled in stays until you ask us to delete it. Once a post lands on Instagram or an email reaches a recipient's inbox, that platform's own privacy policy governs what happens to it next.

Keylia reaches these services through their public APIs, on your behalf and with your permission. We are not partnered with, certified by, or endorsed by Google, Meta, kvCORE, Sendblue, Vapi, Anthropic, Supabase, or anyone else named on this page. Listing them describes the plumbing and nothing more.

How we protect it

Traffic runs over TLS, data sits encrypted at rest in Supabase, and each agent's records are walled off so one account cannot read another's. Access tokens for connected tools are encrypted, service keys stay server-side, and incoming webhooks get signature-checked before we act on whatever they claim.

Inside the company, access is limited to the few people who need it to keep the service running, and every look is logged. No system is perfectly secure and we are not going to pretend otherwise. If a breach creates a real risk of significant harm, we notify the people affected and the Privacy Commissioner, which is what PIPEDA requires.

How long we keep it

Your account and your message history stay while the account is open, since last spring's thread is what lets Keylia recall which past client asked about the semi on Maple Grove. Close the account and we delete account data and message content within ninety days, sooner if you ask, and asking takes two lines of email.

Consent and opt-out records outlive the rest. We hold them for at least three years after the last message, because we have to be able to show why a message was allowed to send. Deleted rows can also sit in encrypted backups for up to thirty days before those backups roll off on their own.

One contact, one conversation, or the whole account: any of it can be deleted whenever you want. Tell us and it gets done. There is no retention pitch, no exit interview, and no waiting period beyond the time it takes to run the deletion and confirm it back to you.

Your rights, and your contacts' rights

Under PIPEDA you can ask what we hold about you, get a copy of it, have mistakes corrected, withdraw consent, and have your information deleted. Write to us and we answer within thirty days. Expect a question or two confirming who you are first, which protects your file rather than stalling it.

If you are a contact rather than an agent, start with the agent who added you, since it is their relationship and their record. Write to us anyway if that goes nowhere. We can locate your information, pass the request along to the agent, and stop the messaging from our side either way.

Not satisfied with how we handled it? The Office of the Privacy Commissioner of Canada takes complaints at priv.gc.ca or 1-800-282-1376, and you are entitled to go straight there. We would rather hear from you first and put it right ourselves, but that route stays open regardless.

  • Ask for a copy of your account data and your full message history.
  • Fix a wrong number, a misspelled name, or a stale deal stage in a record.
  • Consent can be withdrawn, a connected tool cut off, the account closed.
  • One contact, one thread, or everything: deletion runs and we confirm it back.

Children, updates, and reaching us

Keylia is a working tool for licensed real-estate professionals. It is not built for anyone under eighteen, and we do not knowingly collect information about children. If a contact record about a minor ends up in the system, tell us and we take it out.

When this policy changes in a way that affects you, we text and email before the change takes effect, rather than posting a quiet update and hoping you notice. This version is dated 29 July 2026. Older versions are available on request.

Privacy questions, access requests, and complaints go to privacy@keylia.ca, where a person reads them. Ask for a mailing address and we will send it. If your question concerns a contact's data rather than your own, name the agent you have been dealing with so we can find the right record.

Your new head of marketing is a text away.

Get Started