KNOTAPP — PRIVACY POLICY

Version 1.0 — Effective date: 2026-10-01

1. Who is responsible

The data controller for account and billing data is KnotApp S.L., Larios 11, 29002, Málaga, Spain ("KnotApp", "we"). Contact for privacy matters: contact@knotapp.io. For the organizational content our customers store in KnotApp (see Section 3), the customer is the controller and we act as processor on the customer's behalf.

2. Data we collect

Account data: name, email address, password (stored hashed), company name and profile information you provide. Billing data: subscription plan, invoices, and payment status — card details are collected and stored by Stripe, our payment processor; we never see or store full card numbers. Customer content: the organizational information you and your team store or generate in KnotApp (Vault entries, decisions, documents, conversations with the Boardroom). Voice and audio: if you send voice notes (e.g., through the Telegram bot) or upload recordings, we process the audio solely to transcribe it; audio files are deleted after transcription and only the transcription is retained as customer content. Usage data: technical logs, feature usage, and AI-consumption metering needed to operate limits and billing. Feedback: opinions you submit through the in-app feedback feature, together with your choice on public visibility. We do not use advertising trackers.

3. Your organizational content — you own it

Customer content belongs to the customer. We process it only to provide the service: storing it, retrieving it, and submitting the relevant parts to our AI providers to generate the deliberation and analysis you request. We do not sell customer content, we do not use it to train our own or third-party models, and our AI providers process it under paid API agreements that exclude the use of customer data for model training.

4. Purposes and legal bases (GDPR)

We process data to: provide the contracted service (Art. 6(1)(b) GDPR); manage billing and comply with tax and accounting obligations (Art. 6(1)(c)); secure and improve the service, prevent abuse, and enforce usage limits (legitimate interest, Art. 6(1)(f)); publish testimonials and send product communications where you have consented (Art. 6(1)(a) — withdrawable at any time).

5. Service providers (sub-processors)

We rely on the following providers to operate KnotApp: Supabase (database and storage hosting — region: EU (Ireland) — eu-west-1); Vercel (application hosting and delivery); Anthropic and Google (AI processing of the text needed to generate deliberation — paid APIs; no training on customer data); OpenAI (Whisper — transcription of the voice notes and audio you choose to send; audio is deleted after transcription); Telegram (messaging channel, only if you connect the KnotApp bot — messages you send to the bot transit Telegram's platform under Telegram's terms); Stripe (payment processing); Resend (transactional email); and, for our affiliate program, Refgrow (referral attribution — no customer content is shared). Each provider processes data under a data-processing agreement. Where processing occurs outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses or an equivalent lawful mechanism.

6. Google user data (Google API Services)

If you choose to connect your Google Calendar, we access your calendar data on a read-only basis and use it solely to generate your meeting briefings inside KnotApp. KnotApp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide this feature or as required by law, and we do not permit humans to read it except with your explicit consent, for security purposes, or to comply with applicable law. You can disconnect Google Calendar at any time from the app, which stops all access.

7. Retention and deletion

Account and customer content are retained while your account exists — including in read-only mode after cancellation, so that your organizational memory is preserved for you. When you delete a company or your account, we delete the underlying records from our live database: your decisions and their reasoning, who took part in each one, your directors and their history, your rooms, your connector credentials, and your usage records. This cannot be undone and we cannot recover it for you afterwards. What we keep: records we are legally required to retain, in particular issued invoices, which contain your billing name, country and tax identifier. These are kept in a separate accounting ledger for the period Spanish law requires and are not affected by deletion of your account. We also keep one deliberately irreversible marker of the email address used to open an account: a keyed cryptographic hash, not the address itself. It records that an address was used to sign up, how many times and when, and whether the free trial has already been used. We keep it to prevent the free trial from being taken repeatedly, on the basis of our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR). It survives deletion of your account. It contains no name and no contact details, it cannot be used to write to you, and it cannot be turned back into your address. If you want this marker removed as well, tell us the address at contact@knotapp.io and we will delete it. Separately from our database, our payment processor keeps its own record of your payments for as long as its own legal obligations require; deleting your KnotApp account does not delete it. Some fields are additionally encrypted at rest with a key derived per company: your directors' private profiles, and the credentials of any connector you link. Your decisions and their content are stored unencrypted. Audio files are deleted upon transcription (see Section 2). Feedback published as a testimonial is unpublished immediately upon withdrawal of consent; the internal record is retained for traceability.

8. Your rights

Under the GDPR you may exercise the rights of access, rectification, erasure, restriction, portability, and objection by writing to contact@knotapp.io. You may also lodge a complaint with the Spanish supervisory authority (AEPD, www.aepd.es). If you are a business user in other jurisdictions (including the United States): we do not sell personal information, and you may contact us at the same address to exercise any privacy rights available to you under your local law.

9. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit, per-company encryption of sensitive fields with keys derived per company (see Section 7 for what this covers), hashed credentials, role-based access, isolation between customer tenants, audit logging of administrative actions, and the principle of least privilege. No system is perfectly secure; we will notify affected customers and authorities of personal-data breaches where legally required.

10. Cookies

KnotApp uses strictly necessary cookies for authentication and session management only. We do not use third-party advertising cookies. For details, see our Cookie Policy. If non-essential cookies (e.g., affiliate attribution or analytics) are introduced, the Cookie Policy and a consent mechanism will be updated accordingly before they are activated.

11. Changes and contact

We may update this policy; material changes will be notified in-app or by email before taking effect. The version in force and its date appear in the header. Contact for any privacy matter: contact@knotapp.io.

← Back to home