Privacy Policy

What we hold, and why.

This page is maintained by the operator of Knock to explain what personal data the service handles. It describes current practice and is not an independent certification or audit. For a concrete, line-by-line account of what the gate reads, what a human could ever see, and how long anything is kept, read what we can and cannot see.

Last updated July 31, 2026

1. Data we collect

  • Account data — the email address you sign up with, or the basic profile returned by Google if you sign in with it, plus the handle and display name you choose.
  • Message data — the sender address, subject, body, and category of messages submitted to your attention gate or received at your alias, together with the deposit amount and its status.
  • Settings — your pricing rules, forwarding address, and allow and block lists.
  • Payment references — identifiers returned by our payment processor for each deposit. Card numbers never reach our servers.
  • Technical data — standard server logs generated when you use the service.

2. How we use it

We use this data to operate the service: authenticating you, classifying and pricing inbound messages, showing your queue, authorizing and settling deposits, enforcing your allow and block lists, and preventing abuse of the deposit mechanism.

Message content is processed by software — classification, pricing, routing, duplicate detection. No human reads your messages except when reviewing a dispute or abuse report that a party raises. Content is never used for advertising, never sold, and never used to train AI models.

We do not sell personal data, and we do not use the content of your messages for advertising.

3. If you contacted someone through a gate

When you send a message through an attention gate, the recipient sees the address you provided and the content you wrote. That is the point of the product. We keep the record so the deposit can be released, claimed, or expired correctly, and so disputes can be reviewed.

4. Service providers

  • Cloud hosting and database — runs the application, stores accounts, messages, and settings.
  • Payment processor — authorizes, captures, cancels, and refunds card deposits, and handles card details directly.
  • Email routing provider — receives mail addressed to your alias and forwards it to the service.

These providers process data on our instructions for the purposes above. If stablecoin settlement launches in the future, deposits settled on a public blockchain would, by the nature of those networks, be publicly visible as transactions; this does not apply to card deposits today.

5. Retention and deletion

Messages and their deposit records are retained while your account is active so your queue and settlement history remain accurate. Deleting your account removes your profile, aliases, pricing rules, lists, and message content; we retain the minimum transaction records needed to satisfy financial and dispute obligations.

The content of settled messages (subject and body) is permanently removed 90 days after settlement; only the transaction record — amounts, settlement outcome, payment identifiers — is retained.

6. Cookies and local storage

Knock does not use advertising or third-party tracking cookies. We use two categories of browser storage, and you choose whether the optional one is used.

  • Essential — your signed-in session and the record of your cookie choice. These are required for the service to function and cannot be switched off.
  • Optional (referral attribution) — when a promotional link brings you to the site, we store the referral marker for the duration of your browser session so we can tell which link led to a signup. Declining leaves this unset and no click is recorded.

You can change your choice at any time.

7. Your rights

You can access, correct, export, or delete your data. Account settings cover most of this directly; for anything else, write to us from your account email and we will respond within a reasonable period. If you are in a jurisdiction with statutory privacy rights, such as the EEA or UK, those rights apply in addition.

8. Security

Access to your queue and settings requires authentication, and database access rules restrict each account to its own records. Traffic to the service is encrypted in transit. No system is perfectly secure; if you believe you have found a vulnerability, contact us rather than testing against other people's accounts.

Traffic is encrypted in transit and data is encrypted at rest; messages are not end-to-end encrypted — the gate must read a message to classify, price, and deliver it, and we keep that processing to software.

9. Contact

Privacy questions, deletion requests, and security reports can be sent to the operator of this service at the support address listed in your account.