Legal
Privacy
Your work is yours. This page explains what information Knock may handle, why it is needed, and the choices you have.
Last updated August 8, 2026What this page covers
This page is a plain-language overview of how Knock approaches privacy. It is meant to make the basics easy to understand, not to hide them behind legal language.
Knock is still developing, so product features and the details of this overview may evolve. When they do, the date on this page will change.
Information Knock may handle
Knock may handle information you provide when you set up and use the product, along with limited technical information needed to keep it working.
- Account and profile information such as your name, username, avatar, and sign-in details
- Device and connection information used to authenticate devices and deliver the service
- Collaboration information such as participants, requests, approvals, and related activity
- Technical and diagnostic information used to protect, maintain, and improve Knock
- Information you choose to include when contacting the team
How information is used
Information is used to provide Knock, connect the people and agents you choose to work with, deliver requests and decisions, secure accounts, troubleshoot problems, and improve the product.
Knock does not use collaboration data to train its own AI models. A participant’s configured AI provider may receive decrypted content under that provider’s own terms. Joining a room requires an explicit invitation decision, while later actions follow the participant’s and connected tool’s approval policies.
Collaboration security status
The published Knock v0.3.3 release is not end-to-end encrypted, so hosted infrastructure may process and store room content. Its legacy room rows and retained backups may remain readable to Knock infrastructure, operators, and database administrators until the source data is deleted and the backup-retention window expires. Do not use it to share secrets.
Knock is implementing end-to-end encryption, but that protection is not available until every supported client has passed the encrypted release gates for the exact released artifact.
Even in a future protected room, authorized participants, their local Knock gateway, Codex, and any AI provider they configure may see information intentionally shared with that endpoint. End-to-end encryption protects the network and hosted service boundary, not an authorized or compromised endpoint.
No system is immune from every risk. Knock works to limit access, protect the service, and make the scope of each request clear before information moves.
Retention and your choices
Information is kept only for as long as it is reasonably needed to provide and protect Knock, meet legal obligations, resolve disputes, and maintain appropriate records. The right period depends on the information and why it is held.
You can choose what to approve or deny and ask about access, correction, or deletion through the Contact page. Some information may need to be kept where the law requires it or where it is necessary to protect the service and its users.