Last updated 11 September 2026

Privacy Policy

Kelpie is bookkeeping software for Australian sole traders. You trust it with your financial records and with information about the people you deal with, so this policy is written to be read: what we collect, what we do with it, who touches it, where it goes, how long we keep it, and how you get it back or make it disappear. The short version — your data is yours, we use it only to do your books, and we never sell it.

1. Who we are, and what this covers

Kelpie (getkelpie.com.au and the Kelpie application) is operated from Australia by Bower Software Pty Ltd (ACN 702 077 254) (“Kelpie”, “we”, “us”). This policy covers the website, the application, the built-in assistant, our support channels and the emails we send. It forms part of our Terms of Service.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we hold ourselves to the APPs whether or not the Act’s small-business threshold would otherwise apply to Bower Software Pty Ltd. Contact for anything in this policy: help@getkelpie.com.au.

2. Two kinds of information

Information about you — our customer, or a person invited into a customer’s books. We collect it and decide how it is handled, and this policy is our promise to you about it.

Information in your books about other people — your customers, suppliers and contacts, the people you support and those who pay for their support, and anyone named in a document you upload or a note you write. You decide what goes into Kelpie; we hold and process it on your instructions to provide the Service, and we use it for nothing else. If you are bound by the Privacy Act, you have your own obligations for it. If you are one of those people and want to know what a Kelpie customer holds about you, ask that business; we will help it respond, and we act on our own account only where the law requires us to.

3. What we collect

Account and identity. Your email address and a password (stored only as a cryptographic hash — we cannot read it), the business names, business types and ABNs you register, GST registration status, the contact details and logo you choose to print on documents, and your settings.

Billing. Your subscription is paid through Stripe. Card details go to Stripe directly and never touch our systems; we hold Stripe’s reference for your subscription, its status, and the receipts and payment history we need to keep for our own tax and accounting obligations.

Your books. Everything that makes up your records: bank statement files you upload and the transactions read from them; invoices, quotes, bills and their lines; receipts, bills and other documents you drop in, and what Kelpie read from them; Shoebox documents and notes; logbook trips; time entries; manual journals; the categorisation rules Kelpie learns from your confirmations; your bank accounts (name, BSB and the last digits of the account number, for matching statements); supplier bank details you enter for payment files, and your own account details as the remitter; and the audit trail of who did what, when.

Support work. If you switch on support work, the records of the people you support: name, NDIS number where you enter one, address, support coordinator, plan dates, how their funding is managed, who is invoiced, the supports and rates you usually deliver, and the shift notes you write on their invoices. The record is designed to work without a date of birth, a diagnosis, health information or plan budgets, and Kelpie asks you not to enter them; when Kelpie reads an invoice you sent into a person’s record, it is instructed to leave such details out even if they are printed.

The assistant. Your questions to the assistant, its replies, the tools it used to answer, and — when a document is dropped into the conversation — what it read from the document. Conversations are stored so the assistant can follow a thread. If a conversation is handed to a person on our team, that person sees it.

Emails. A log of the emails Kelpie has sent for you and to you (recipient, subject, status, and delivery errors), so you can see what went where and we can find out why something did not arrive.

Support and feedback. What you tell us when you ask for help, report a bug or make a suggestion, in the app or by email.

Technical information. Standard server logs generated by our hosting providers — IP address, browser type, pages requested, timestamps — kept for security and reliability. We use only essential cookies: the ones that keep you signed in and remember which business you have open. Your browser also keeps a few preferences on your own device (the theme, a chosen view, and a draft passed between two screens), which never leave it. No advertising trackers, no third-party analytics cookies, no fingerprinting.

What we do not want. Card numbers (Stripe holds those), bank passwords or internet-banking logins (Kelpie has no bank feeds and never asks for them), tax file numbers, and anyone’s health or sensitive information. If you upload a document that happens to contain such things, it is stored as your document, but please redact what your books do not need.

4. How we collect it

Directly from you, when you sign up, enter records, change settings, write to us or use the assistant. From files you upload, through Kelpie’s AI reading them. From people you invite, who sign in with their own accounts. From Stripe, as the status of your subscription. And automatically, as the technical information above. We do not buy information about you and do not collect it from data brokers or social networks.

5. What we use it for

To provide the Service: keeping your books, categorising and reconciling your transactions, reading your documents, generating your invoices, quotes, reports and tax-time figures, sending the emails you ask Kelpie to send, and answering your questions through the assistant.

  • To run your subscription and keep the records of it that tax and accounting law require of us.
  • To support you, including reading a conversation you have handed to a person, and to respond to feedback and bug reports.
  • To keep the Service secure, prevent fraud and abuse, enforce our terms, and investigate problems.
  • To send you service emails, and the optional reminders and digests you can turn off in Settings.
  • To improve Kelpie, using de-identified, aggregated measures — how many statements import cleanly, how often a suggestion is corrected — that never identify you or anyone in your books.
  • To comply with the law, and to establish, exercise or defend legal claims.

We do not use your information for advertising, do not build profiles of you for anyone else, and never sell or rent it. If we ever want to use your data for a purpose not in this policy, we will ask you first.

6. AI processing — said plainly

Kelpie is AI-native. To categorise your transactions, read statement files, bills, receipts and other documents, draft documents, and answer questions about your books, we send the relevant records — for example, a batch of statement lines, a receipt image, an invoice PDF, or the figures the assistant looks up to answer you — to our AI provider, Anthropic, through its commercial developer platform, from our servers. We do not use consumer chat products for this.

Under Anthropic’s commercial terms, the data we send is not used to train its models. Anthropic may hold what we send it briefly for its own trust-and-safety checks, and content its systems flag can be kept longer for that purpose; Anthropic processes data in the United States. Card details never go to the AI, and nothing about you goes to it that the task in hand does not need.

The AI drafts; you approve — nothing the AI suggests changes your books without your confirmation. Kelpie learns from the categorisations you confirm in order to categorise your own transactions better; we do not use your records to train models used for other customers without telling you first and changing this policy. AI processing is integral to the Service and cannot be switched off, but you control what you enter and what you drop in.

7. Who else touches your data

We run Kelpie on a small set of established providers, each of which processes data only to provide its service to us and is bound by its own commercial terms and security commitments:

  • Supabase — database, authentication and file storage.
  • Vercel — hosting of the website and application.
  • Anthropic — AI processing, as above, in the United States.
  • Resend — email delivery.
  • Stripe — payments and subscription billing.

Some of these providers process data on servers outside Australia, including in the United States. By using Kelpie you understand that your information may be disclosed to overseas recipients in those countries, and that while we choose providers with strong security practices and bind them through their terms, we may not be able to ensure that an overseas recipient handles it as the APPs would require.

Our team. A small number of people at Bower Software Pty Ltd can reach your data through our providers’ consoles to support you, fix a problem, or keep the Service running. They do so only for those purposes, under confidentiality, and the application itself runs under your permissions rather than an administrator’s.

People you invite, and people you email. If you give your accountant, bookkeeper or a colleague access, they see what their role allows. When you email an invoice or quote from Kelpie, the recipient receives the document you approved.

Where the law requires. We will disclose information if a law, court order or regulator validly requires it, telling you where we are allowed to. If Kelpie is ever sold or transferred to a successor, your information would go with it under this policy, and we would tell you.

Beyond these, we do not disclose your information to anyone. We do not share it with advertisers or data brokers, and we never sell it.

8. How we protect it

Your data is encrypted in transit and at rest. Access is enforced at the database layer: every record is scoped to your business, and the application operates under your permissions, not an administrator’s. Your books are append-only — entries are never silently edited or deleted, and corrections are visible reversing entries. Every posting requires your approval and is written to an audit log. Documents are stored in private storage that only your business can reach. Passwords are hashed; invitations are single-use. Our database provider keeps backups of the database so that your books survive a failure on our side; the files attached to your records are stored separately and are not part of those backups, which is one reason to keep your own copies of source documents.

No security is perfect, and you have a part in it: use a strong, unique password, keep your list of invited people current, and tell us at help@getkelpie.com.au at once if you think your account has been accessed. We do not claim any security certification we do not hold.

9. How long we keep it

While a Business is open we keep its records — that is the Service. Cancelling your subscription does not delete anything; your books stay, and we will provide an export on request.

When you close a Business, its attached files are deleted at once and it can be restored for seven days; after that, every record of that Business is erased from the live service and cannot be recovered. Backup copies age out on our providers’ retention cycles shortly after.

Your account stays until you ask us to delete it, which we do once every Business on it is closed. We keep the records of your subscription and our dealings with you — receipts, invoices we issued you, and support correspondence — for as long as tax, accounting and consumer law require us to, and then delete them. Server logs are kept for a short period for security. De-identified statistics are not personal information and may be kept.

Australian law generally requires businesses to keep their own financial records for five years — export yours before you close a Business. The export includes your profit and loss, balance sheet, trial balance, general ledger and supporting records.

10. Your rights: access, correction, deletion, export

You can see, correct and export almost everything yourself in the app, and you can delete your account as described above. For anything else — a copy of the information we hold about you, a correction, deletion of something you cannot remove yourself, or a question about how we have handled your information — email help@getkelpie.com.au. We will confirm who you are, and respond within 30 days. There is no charge.

If you are named in a Kelpie customer’s books and want to exercise these rights over that information, the business that holds it is the one to ask; tell us if you cannot reach them and we will help.

11. Complaints

If you think we have mishandled your information, tell us at help@getkelpie.com.au. We will acknowledge your complaint, look into it, and respond within 30 days with what we found and what we will do. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992).

12. If something goes wrong

If a data breach occurs that is likely to result in serious harm to anyone whose information we hold, we will notify the people affected and the OAIC in accordance with the Notifiable Data Breaches scheme — promptly, plainly, and with what you need to do next. Where the information affected is in your books about other people, we will help you meet any obligations you have to them.

13. Cookies and your browser

Kelpie sets only the cookies it needs: a sign-in session, and a cookie that remembers which business you have open. There are no advertising trackers and no third-party analytics. Your browser also holds a few preferences locally on your device — your theme, a view you chose, and a draft handed from the assistant to a form — and those never leave your browser. Blocking cookies will stop you signing in.

14. Children

Kelpie is for people running a business and is not directed at anyone under 18. We do not knowingly collect information from children; if you believe a child has created an account, tell us and we will delete it.

15. Changes to this policy

When we change this policy we update the date at the top. For a material change we tell you in the app or by email before it takes effect. Continuing to use Kelpie after a change means the updated policy applies. Questions: help@getkelpie.com.au.