Legal
Privacy Policy
This policy describes what Knowl Cloud holds about you, why, who else touches it, and what you can make us do about it.
The shortest version: we hold what runs your account, what you deliberately publish, and a record of who did what. We do not upload or sync your repository, your code index, your embeddings or your agent session history — we receive only what you explicitly publish, which may include code if you chose to put code in it. We never train on any of it.
1. Who is responsible
ĐỖ GIANG THÀNH ĐẠT and TRƯƠNG THÀNH LONG, both individuals resident in Vietnam, operate Knowl Cloud. In this policy "we" means both of us.
Our role differs between two kinds of data, and the difference matters more than the labels:
Account, workspace, audit, device, security and operational data — we decide why and how it is processed. Where the law calls that role a controller, that is our role, and we hold it jointly. We have a written arrangement between us covering who does what.
Customer Content — the knowledge you deliberately publish — is decided by you. You, or the organisation whose workspace it is, choose what goes in and why. Where that content contains personal data and the law calls our role a processor, we process it to provide the service on your behalf and not for our own purposes.
You do not need to work out which label applies before contacting us. Write to [email protected] and we will sort it out.
2. What we collect
| What | Example | Why | Where it comes from |
|---|---|---|---|
| Account identity | Your email address and display name | To have an account, and to show teammates who published what | Google or GitHub, when you sign in |
| Workspace information | Memberships, invitations, roles, permissions | To control who can read and change what | You and your workspace admins |
| Customer Content | The atoms you and your agents publish, with their category, reasoning, evidence, origin repository and author — including code or logs if you put them there | Storing and sharing it is the service | You, deliberately, when you publish |
| Audit records | Every publish, update, membership change and role change, with who did it and when | So a workspace can answer "who changed this, and when" — and so a role change cannot be quietly backdated | Generated by us as you use the service |
| Devices | The name a machine reported when you signed the CLI in, and when it was last used | So you can see your approved devices and revoke one | Your CLI, at sign-in |
| Server logs | Your IP address, the request path, timing, and the response status | Rate limiting, abuse prevention, and working out what broke | Generated automatically on every request |
| Acceptance records | Which version of these documents you were shown, and when | So we can both tell what you actually agreed to | Recorded when you sign in |
| What you send us | Support requests, privacy requests, vulnerability reports | To answer you and keep a record of what we did | You |
We collect nothing for advertising, we build no profile of you, and we do not sell personal data.
3. What we do not collect automatically
Your repository contents, your code index, your embeddings and your agent session history are not uploaded, not mirrored, and not what publishing sends. There is no background sync.
Publishing is an explicit act: it transmits the item you or your agent chose to share, and nothing around it.
That distinction is the honest version of a claim you will see stated more loudly elsewhere. If you deliberately paste a code snippet into an atom as evidence and publish it, we receive that code — because you chose to send it. What we do not do is take the repository around it.
4. Why we process it
Vietnamese law is the law that governs us, and it works from consent together with a set of circumstances in which processing is permitted without it. We rely on those permissions:
- To provide the service you asked for and to perform our agreement with you — everything needed to run your account, your workspace and your published knowledge.
- To keep the service secure and working — rate limiting, abuse prevention, diagnosing failures.
- To meet a legal obligation, or to establish or defend a legal claim.
- With your consent, where consent is what the law requires. You can withdraw it, and withdrawing it does not make earlier processing unlawful.
Where the GDPR or UK GDPR applies to a particular person — broadly, where we offer the service to people in those places or monitor their behaviour there — our bases are performance of the contract, our legitimate interests in security and abuse prevention, compliance with a legal obligation, and consent where required.
5. Who else touches it
We use a small number of other companies to run the service. Each receives only what it needs.
| Who | What they do | What they see | Where |
|---|---|---|---|
| Supabase | Authentication and the database | Everything we store | Amazon Web Services, us-east-1 (N. Virginia, United States) |
| Our own servers | Run the application | Traffic in transit and server logs, including IP addresses. These servers hold no customer data at rest — everything is stored in the database above | Amazon Web Services, us-east-1 (N. Virginia, United States) |
| Cloudflare | Carries traffic to our servers and terminates TLS at its edge | Traffic in transit, including IP addresses and request metadata | Global edge network |
| Resend | Sends invitation and notification email | Recipient address and message contents | United States |
| Google, GitHub | Sign you in | That you signed in to Knowl Cloud | Their own infrastructure |
Google and GitHub are independent controllers, not our processors — they decide their own purposes for the sign-in data they hold, under their own policies. When we introduce paid plans, the merchant of record who sells them will also be an independent controller for payment data, and we will never hold your full card details.
There is no analytics, no error-tracking service, and no third-party script on this site or in the application. The only cookie we set is the one that keeps you signed in, which is strictly necessary and cannot be turned off without signing you out. That is why you have never seen a cookie banner here, and why you will not. If that ever changes we will update this policy and ask for consent where the law requires it.
6. Where your data is stored
Your data lives in the United States. Both the database and the servers that run Knowl Cloud
are in Amazon Web Services' us-east-1 region in Northern Virginia. Your account information, your
published knowledge and your audit history are held in the database there; the application servers
beside it hold nothing at rest. Cloudflare's edge network carries traffic to us and is global by
design.
We are two individuals resident in Vietnam, so everything above is a cross-border transfer under Vietnamese law — there is no part of this service that keeps personal data inside the country. The obligations attaching to that transfer, including assessments, records and any filing required, are ours to meet. If a provider's own arrangements move where data is processed in a way that matters, we will update this policy.
7. We never train on your knowledge
Customer Content is never used to train, fine-tune, evaluate or improve any machine learning model. Not ours, not a third party's, not on a free plan, not in aggregate, not "anonymised". We do not sell it to model providers.
This is also §4 of our Terms of Service, so it is a contractual commitment and not only a policy statement.
8. Keeping and deleting
Knowl does not delete knowledge, it supersedes it. An atom can be superseded, deprecated or archived, and all of those stay readable with the chain that says what replaced what. That is the product's model, and it is why the word "delete" appears less here than you might expect.
Nothing is hard-deleted because a payment failed, a workspace was archived, or an account went quiet. That guarantee is about how the product behaves. It does not stand in the way of the law: we will delete, anonymise or redact content where an authorised workspace admin asks, where a valid privacy right requires it, where the law requires it, where content is unlawful, or where it is necessary to protect the service or another person.
Account deletion is available on request. Write to [email protected]. We will delete or anonymise the personal data we hold about you within the time the law requires, and in any event within 30 days. We do this by hand today — there is no button in the product yet, and we would rather say so than describe a feature that does not exist.
Knowledge published into a shared workspace belongs to that workspace and is not removed by deleting your account. Where a privacy request concerns your attribution inside that history, we can usually remove or anonymise the attribution while leaving the technical history intact — turning an author into a deleted user rather than erasing what the team learned.
Audit and acceptance records are kept as long as needed to show what happened in a workspace and to meet our legal obligations. Where the identifying part is no longer needed, we anonymise it rather than destroying the event history.
Server logs are written to a small rotating buffer — at most 30 MB per service — and older entries are discarded automatically as new ones arrive. At our traffic that is days of requests, and it cannot grow into months. We keep no separate archive of them and we do not mine them. We describe the bound this way rather than as a number of days because a size limit is what is actually configured and therefore what we can promise. Where a log is needed for a specific security investigation, that copy is kept for as long as the investigation requires.
Cloudflare keeps its own connection logs under its own retention. Those are theirs, not ours, and we do not control how long they last.
Backups of the database are taken and held by Supabase on its own schedule, which we do not control and cannot configure on our current plan. Data you delete can therefore persist inside a Supabase backup until it rotates out — currently up to about seven days, on Supabase's published schedule rather than a period we set. We have no access to those backups and do not restore from them, so deleted data is never brought back into use by us.
9. Your rights
You can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything wrong;
- delete your account and data, as described in §8;
- export your knowledge — this needs no request, it is in the product on every plan;
- restrict or object to processing;
- withdraw consent, where we relied on it.
Write to [email protected]. We will act within the period the law requires for that kind of request — some kinds have shorter statutory deadlines than others, so we do not flatten them all into a single number — and in any event we will acknowledge you promptly and complete ordinary requests within 30 days.
We may ask for enough information to be confident you are who the data is about, and no more. We will not charge you, and we will not ask why.
Occasionally the law lets us refuse part of a request — where we must keep something to meet another obligation, or where deleting it would affect someone else's rights. If that happens we will tell you, and say why so far as we are allowed to.
10. Children
Knowl Cloud is not for children. You must be at least 16 to have an account. We do not knowingly collect data about anyone younger, and if we learn we have, we will delete it.
11. Security
The mechanisms are on our Security page, with what is not yet true listed alongside what is — including that we have no third-party penetration test and no compliance certification to show you.
The short version: workspaces are isolated at the database level rather than by a filter in application code, your browser never holds an access token, and every publish is scanned for credentials on the server.
No service is perfectly secure. If a personal data breach happens, we will investigate it and notify the people and authorities the law requires us to notify. If you find a vulnerability, write to [email protected] before you tell anyone else.
12. Changes to this policy
This policy carries a version number and an effective date, both at the top, and every previous version stays published at its own address.
For a material change we will publish the new version at least 30 days before it takes effect and email every workspace owner. Where the law requires consent before a new kind of processing begins, publishing a new policy is not a substitute for asking.
13. Contact and complaints
[email protected] — for anything in this policy, including exercising a right under §9.
If you are not satisfied with our answer, you can complain to a supervisory authority: in Vietnam, the Department of Cybersecurity and High-Tech Crime Prevention (A05) of the Ministry of Public Security; elsewhere, the data protection authority where you live or work. We would rather you came to us first, but you do not have to.
In effect since