Transparency

What we can and cannot see.

A gate has to read what it prices and delivers. That is an uncomfortable fact, so here it is in full detail: what passes through our software, what a human could ever look at, what we store, and for how long. This page is maintained by the operator of Knock and describes current practice — it is not an independent certification or audit.

Last updated July 31, 2026

1. What passes through software

Every gated message is processed automatically. This processing is the product: a gate cannot price, route, or deliver a message it has not read.

Sender addressMatched against your allow and block lists, used for duplicate detection, and used to decide whether a sender already knocks free.
SubjectRead to classify the message into a category (sales, recruiting, press, agent, newsletter) and to pick the deposit that applies.
BodyRead for the same classification and pricing decision, for duplicate detection, and to render the message to you in the queue or the forwarded email.
HeadersRead for authentication results and for list and automation markers that identify newsletters and bulk mail so they take the newsletter lane instead of the deposit lane.

All of the above is machine processing. None of it produces an advertising profile, and none of it leaves the service for any purpose other than running the gate.

2. What humans can see

No one at Knock reads messages in normal operation. The only human access path is reviewing a specific dispute or abuse report raised by a sender or recipient. Content is never used for advertising, never sold, never used to train AI models.

3. What we keep, and for how long

Held messagesKept until settlement — release, claim, block, or the automatic 14-day refund.
Settled contentSubject and body are permanently removed 90 days after settlement. Ninety days is the card networks' chargeback-evidence window; after it, the content is no longer needed to defend a dispute.
Payment recordsAmounts, fees, settlement outcome, and payment identifiers are retained as long as financial and dispute obligations require.
Card numbersNever touch our servers. Card details are entered on our payment processor's own pages and we only ever hold their references.
Sender addresses on payment recordsStored hashed, so a settled transaction record can be matched and deduplicated without keeping the address in the clear.
  • The full legal statement of what is collected and why lives in the privacy policy.
  • The settlement outcomes that end a hold are set out in the four verdicts.

4. Where we are going

We are engineering toward holding less: per-user encryption of stored content, immediate content deletion on refund and expiry, and a blind mode where flat-price gates never process message bodies at all. Each will be announced here when it is live — not before.