KNOTAPP — PRIVACY POLICY
Version 1.0 — Effective date: [effective date pending]
1. Who is responsible
The data controller for account and billing data is KnotApp S.L., [address pending], Spain ("KnotApp", "we"). Contact for privacy matters: contact@knotapp.io. For the organizational content our customers store in KnotApp (see Section 3), the customer is the controller and we act as processor on the customer's behalf.
2. Data we collect
Account data: name, email address, password (stored hashed), company name and profile information you provide. Billing data: subscription plan, invoices, and payment status — card details are collected and stored by Stripe, our payment processor; we never see or store full card numbers. Customer content: the organizational information you and your team store or generate in KnotApp (Vault entries, decisions, documents, conversations with the Boardroom). Voice and audio: if you send voice notes (e.g., through the Telegram bot) or upload recordings, we process the audio solely to transcribe it; audio files are deleted after transcription and only the transcription is retained as customer content. Usage data: technical logs, feature usage, and AI-consumption metering needed to operate limits and billing. Feedback: opinions you submit through the in-app feedback feature, together with your choice on public visibility. We do not use advertising trackers.
3. Your organizational content — you own it
Customer content belongs to the customer. We process it only to provide the service: storing it, retrieving it, and submitting the relevant parts to our AI providers to generate the deliberation and analysis you request. We do not sell customer content, we do not use it to train our own or third-party models, and our AI providers process it under paid API agreements that exclude the use of customer data for model training.
4. Purposes and legal bases (GDPR)
We process data to: provide the contracted service (Art. 6(1)(b) GDPR); manage billing and comply with tax and accounting obligations (Art. 6(1)(c)); secure and improve the service, prevent abuse, and enforce usage limits (legitimate interest, Art. 6(1)(f)); publish testimonials and send product communications where you have consented (Art. 6(1)(a) — withdrawable at any time).
5. Service providers (sub-processors)
We rely on the following providers to operate KnotApp: Supabase (database and storage hosting — region: EU (Ireland) — eu-west-1); Vercel (application hosting and delivery); Anthropic and Google (AI processing of the text needed to generate deliberation — paid APIs; no training on customer data); OpenAI (Whisper — transcription of the voice notes and audio you choose to send; audio is deleted after transcription); Telegram (messaging channel, only if you connect the KnotApp bot — messages you send to the bot transit Telegram's platform under Telegram's terms); Stripe (payment processing); Resend (transactional email); and, for our affiliate program, Refgrow (referral attribution — no customer content is shared). Each provider processes data under a data-processing agreement. Where processing occurs outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses or an equivalent lawful mechanism.
6. Google user data (Google API Services)
If you choose to connect your Google Calendar, we access your calendar data on a read-only basis and use it solely to generate your meeting briefings inside KnotApp. KnotApp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide this feature or as required by law, and we do not permit humans to read it except with your explicit consent, for security purposes, or to comply with applicable law. You can disconnect Google Calendar at any time from the app, which stops all access.
7. Retention and deletion
Account and customer content are retained while your account exists — including in read-only mode after cancellation, so that your organizational memory is preserved for you. If you delete your account (or a company tenant), deletion is implemented by cryptographic erasure: the tenant's master encryption key is destroyed, rendering the tenant's data immediately and irreversibly unreadable, with residual encrypted copies purged on the backup cycle. Data we must retain to comply with legal obligations (e.g., invoicing records) is kept for the legally required period. Audio files are deleted upon transcription (see Section 2). Feedback published as a testimonial is unpublished immediately upon withdrawal of consent; the internal record is retained for traceability.
8. Your rights
Under the GDPR you may exercise the rights of access, rectification, erasure, restriction, portability, and objection by writing to contact@knotapp.io. You may also lodge a complaint with the Spanish supervisory authority (AEPD, www.aepd.es). If you are a business user in other jurisdictions (including the United States): we do not sell personal information, and you may contact us at the same address to exercise any privacy rights available to you under your local law.
9. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit, per-tenant encryption with tenant-specific keys, hashed credentials, role-based access, isolation between customer tenants, audit logging of administrative actions, and the principle of least privilege. No system is perfectly secure; we will notify affected customers and authorities of personal-data breaches where legally required.
10. Cookies
KnotApp uses strictly necessary cookies for authentication and session management only. We do not use third-party advertising cookies. For details, see our Cookie Policy. If non-essential cookies (e.g., affiliate attribution or analytics) are introduced, the Cookie Policy and a consent mechanism will be updated accordingly before they are activated.
11. Changes and contact
We may update this policy; material changes will be notified in-app or by email before taking effect. The version in force and its date appear in the header. Contact for any privacy matter: contact@knotapp.io.