Privacy Policy
This notice explains how we process personal data when you use the D-Know desktop app and related control-plane services. It is intended to help meet transparency duties under the EU General Data Protection Regulation (GDPR) and similar laws. It is not legal advice.
1. What we collect
- Account: email, display name, password hash (or Google account link), account type.
- Organization: workspace name, memberships and roles.
- Billing: plan, subscription status, Stripe customer/subscription IDs, payment history metadata. Card numbers are handled by Stripe — we do not store full card data.
- Product usage: knowledge files you upload (local and/or Azure Blob vault), chat/knowledge features as needed to provide the service.
- Technical: auth tokens, basic server logs for security and reliability.
2. Why we process it (lawful bases)
- Contract — to create your account, provide D-Know, and process subscriptions.
- Legitimate interests — security, fraud prevention, service improvement (balanced against your rights).
- Legal obligation — tax/accounting retention of billing records where required.
- Consent — where we ask (e.g. optional marketing, or web cookies on the admin console beyond strictly necessary).
3. Who we share with (processors / recipients)
- Stripe — payments and invoices.
- Google — optional Google sign-in (OAuth).
- Microsoft Azure — optional encrypted blob storage for org knowledge vaults.
- Hosting / database — Postgres and servers you or we operate for the control plane.
- Email provider (e.g. Resend) — payment and account notices when configured.
We do not sell your personal data.
4. International transfers
Some processors may process data outside the EEA. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by those providers.
5. Retention
- Account and org data — while your account is active, then deleted or anonymized after erasure requests (subject to legal holds).
- Billing/transaction records — retained as needed for accounting and dispute resolution.
- Backups — roll off on a limited schedule.
6. Your rights (EEA/UK)
You may have the right to access, rectify, erase, restrict, port, and object to certain processing, and to withdraw consent.
- In the app: Settings → Usage → Privacy & data — export your data or delete your account.
- API:
GET /me/data-export,POST /me/delete-account(authenticated). - Contact: privacy@dknowai.com
You may lodge a complaint with your local supervisory authority.
7. Security
We use TLS in transit where configured, hashed passwords, least-privilege admin roles, and Stripe for card processing. No method of transmission or storage is 100% secure.
8. Children
D-Know Personal and Business accounts are intended for adults (18+). We do not knowingly market Personal accounts to children under 18. School accounts should be set up and supervised by authorized staff / guardians. If you believe a minor’s data was collected without appropriate consent, contact privacy@dknowai.com.
9. Cookies (web admin console)
The desktop app does not use browser cookies for core product use. The optional web Platform Console may use local storage for your admin session token (strictly necessary). Analytics cookies are not used by default.
10. Changes
We may update this policy; the “Last updated” date will change. Material changes will be highlighted in-product when practical.