What we hold, and why.
This page is maintained by the operator of Knock to explain what personal data the service handles. It describes current practice and is not an independent certification or audit. For a concrete, line-by-line account of what the gate reads, what a human could ever see, and how long anything is kept, read what we can and cannot see.
Last updated July 31, 2026
1. Data we collect
- Account data — the email address you sign up with, or the basic profile returned by Google if you sign in with it, plus the handle and display name you choose.
- Message data — the sender address, subject, body, and category of messages submitted to your attention gate or received at your alias, together with the deposit amount and its status.
- Settings — your pricing rules, forwarding address, and allow and block lists.
- Payment references — identifiers returned by our payment processor for each deposit. Card numbers never reach our servers.
- Technical data — standard server logs generated when you use the service.
2. How we use it
We use this data to operate the service: authenticating you, classifying and pricing inbound messages, showing your queue, authorizing and settling deposits, enforcing your allow and block lists, and preventing abuse of the deposit mechanism.
Message content is processed by software — classification, pricing, routing, duplicate detection. No human reads your messages except when reviewing a dispute or abuse report that a party raises. Content is never used for advertising, never sold, and never used to train AI models.
We do not sell personal data, and we do not use the content of your messages for advertising.
3. If you contacted someone through a gate
When you send a message through an attention gate, the recipient sees the address you provided and the content you wrote. That is the point of the product. We keep the record so the deposit can be released, claimed, or expired correctly, and so disputes can be reviewed.
4. Service providers
- Cloud hosting and database — runs the application, stores accounts, messages, and settings.
- Payment processor — authorizes, captures, cancels, and refunds card deposits, and handles card details directly.
- Email routing provider — receives mail addressed to your alias and forwards it to the service.
These providers process data on our instructions for the purposes above. If stablecoin settlement launches in the future, deposits settled on a public blockchain would, by the nature of those networks, be publicly visible as transactions; this does not apply to card deposits today.
5. Retention and deletion
Messages and their deposit records are retained while your account is active so your queue and settlement history remain accurate. Deleting your account removes your profile, aliases, pricing rules, lists, and message content; we retain the minimum transaction records needed to satisfy financial and dispute obligations.
The content of settled messages (subject and body) is permanently removed 90 days after settlement; only the transaction record — amounts, settlement outcome, payment identifiers — is retained.
7. Your rights
You can access, correct, export, or delete your data. Account settings cover most of this directly; for anything else, write to us from your account email and we will respond within a reasonable period. If you are in a jurisdiction with statutory privacy rights, such as the EEA or UK, those rights apply in addition.
8. Security
Access to your queue and settings requires authentication, and database access rules restrict each account to its own records. Traffic to the service is encrypted in transit. No system is perfectly secure; if you believe you have found a vulnerability, contact us rather than testing against other people's accounts.
Traffic is encrypted in transit and data is encrypted at rest; messages are not end-to-end encrypted — the gate must read a message to classify, price, and deliver it, and we keep that processing to software.
9. Contact
Privacy questions, deletion requests, and security reports can be sent to the operator of this service at the support address listed in your account.