1. Introduction

Knot (“Knot,” “we,” “us,” or “our”) is a sole proprietorship based in Ontario, Canada, providing subscription-based design services and an AI-powered design management platform to clients worldwide. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in connection with the Knot platform and all related services (collectively, “Services”).

This Policy applies to all individuals and entities who use our Services, visit our websites, or interact with us, regardless of location.

Please read this Policy carefully.

By using our Services, you acknowledge that you have read, understood, and agree to the practices described here. Where consent is required for specific processing, we will obtain it separately.

2. About this policy and applicable law

Knot operates globally and is subject to privacy legislation in multiple jurisdictions depending on the location of Customers and data subjects.

Canada.

Knot’s primary obligations arise under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation. For Quebec residents, the Act respecting the protection of personal information in the private sector (Law 25 / Bill 64) imposes additional obligations including enhanced transparency, privacy impact assessments (PIAs), and expanded individual rights.

European Economic Area and United Kingdom.

For individuals located in the EEA or UK, Knot acts as a data controller under the General Data Protection Regulation (GDPR) and UK GDPR. We are required to identify lawful bases for processing, implement appropriate safeguards for international data transfers, and honor data subject rights.

United States — California.

To the extent applicable, we respect the rights of California residents under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Other jurisdictions.

We respect applicable privacy laws in all jurisdictions where we operate. If you are located in a jurisdiction with specific privacy requirements not described here, please contact us.

3. Information we collect

We collect several categories of personal information when you use our Services:

3.1 Account and identity information

Collected during registration and onboarding: full name (registration form, required); email address (registration / Google OAuth, required); business name (onboarding form, required); password stored as a salted hash, never in plain text (required, or Google OAuth); Google OAuth profile including name, email, and profile photo (optional auth method); profile photo / avatar (optional); occupation / job title (optional); bio / about text (optional); social media handles (optional); how you discovered Knot / referral source (optional); theme preference — light / dark / system (optional); notification preferences (optional).

3.2 Billing and subscription information

Stripe Customer ID (auto-generated at subscription); Stripe Subscription ID; subscription status (e.g. active, trialing, past_due, canceled); subscription tier — Regular or Supercharged; trial start and end dates; active concurrent request limit (derived from tier); scheduled tier changes.

We do not store complete payment card numbers, CVV codes, or full bank account details.

All payment card processing is performed exclusively by Stripe, Inc. under its PCI DSS compliance program.

3.3 Design requests and project content

Design request titles, descriptions, and priority levels; files attached to Design Requests (images, PDFs, video, reference documents, and other formats); request status history and workflow transitions; comments and replies on Design Requests (including text and file attachments); request history timeline events (creation, edits, status changes, revision pins, deliverable uploads); bookmarked requests.

3.4 Communications data

Direct chat messages between you and Knot’s design team (text, images, embedded requests, embedded Drive files); voice message audio recordings sent through the team chat; message reactions; team chat messages (in team-enabled accounts); push notification subscription data (VAPID endpoint for web push); in-app notification records.

3.5 AI interaction data

AI conversation history — all messages and responses in Knot AI sessions (retained for duration of account); AI prompts and context — text you submit to Knot AI (retained for duration of account); AI agent tool call records — log of every AI agent action including tool name, parameters, result, execution time, and confirmation status (rolling 90 days); AI attachments metadata (duration of account); AI personalization settings — nickname, occupation, bio, tone preference, web search default (duration of account or until cleared); AI memory — factual notes accumulated by the AI about you, up to 1,000 characters (until cleared by you or account deletion); native AI reasoning tokens (duration of account); search grounding sources from AI web search results; AI attachment files stored in private Supabase bucket and transmitted to Google Gemini File API with 48-hour TTL; Instant Revision job metadata — edit prompts, selection context, job and candidate status (duration of account or until purged with related Deliverable/request data).

3.6 Voice and audio data

Voice messages in team chat: recorded via browser MediaRecorder API; uploaded as audio file to Supabase Storage (private bucket, retained for duration of account).

AI voice dictation audio: recorded via browser MediaRecorder API; transmitted to Groq, Inc. (Whisper model) for real-time transcription.

Not retained by Knot. Transmitted to Groq for transcription only. Groq’s data handling applies.

3.7 Uploaded files and brand assets

Brand assets — logos, brand guidelines, fonts, photography (Supabase Storage, private); design request reference files (Supabase Storage, publicly accessible via CDN); chat and comment file attachments (Supabase Storage, private); AI conversation file attachments — documents, audio, video (Supabase Storage, private; also temporarily processed via Google Gemini File API); completed design Deliverables (Cloudinary CDN).

3.8 Team and collaboration data

Team membership records (who is a member, roles, join dates); team invitation emails and invitation tokens; per-member feature access grants and permission settings; team activity feed events (request creation, file uploads, status changes, member actions); team-scoped conversation messages.

3.9 Style profile and design analysis data

AI-generated visual analysis of completed Deliverables (color palettes, typography, layout characteristics, brand personality signals, bounding-box annotations); website screenshots captured via Browserbase, Inc. when you provide a website URL for Style Profile seeding; computed CSS design tokens extracted from your public website during seeding (colors, typography, spacing, radii, shadows, etc.); AI-generated style overview prose; brand logo data extracted from your website if URL seeding is used.

3.10 Share link and external access data

Share link configurations (token, permission level, expiry date, bcrypt password hash if set); share link access and activity logs; share comments from external visitors (display name is optional; no account required; content and timestamp recorded).

3.11 Google Drive connection data

When you connect Google Drive: OAuth access and refresh tokens; connected Google account email; Knot Exports folder identifier; and metadata for files Knot creates or mirrors under the drive.file scope.

3.12 Instant Revision data

Instant Revision prompts and selection context; job and candidate status; source and candidate image files processed for edit inference and stored for the job lifecycle.

4. Information we collect automatically

4.1 Technical log data

When you access the Platform, our systems automatically process: IP addresses (primarily used for rate limiting via Upstash Redis; retained only for the duration of the active rate-limit window, typically minutes); HTTP request metadata (method, path, status code, timestamp); browser type and version; operating system and device type; session identifiers (Supabase Auth session tokens, stored as httpOnly cookies); referrer URLs.

4.2 Feature usage and activity data

Last activity timestamp (updated on every authenticated request; used to display online presence indicators); request open/view timestamps (stored per-user-per-request; used to power “new activity” badges); AI agent action audit entries (see Section 3.5); conversation last-seen timestamps.

4.3 Error and diagnostic data

We use Sentry (operated by Functional Software, Inc., USA) for error tracking and application performance monitoring. When errors occur, Sentry automatically collects: error messages and stack traces; application performance metrics; your Knot user ID and session context; and request metadata at the time of the error. Sentry data is used solely for diagnosing and resolving technical issues and is retained for approximately 90 days.

4.4 Analytics data

Our Platform may include Google Analytics and Google Tag Manager (operated by Google LLC, USA) on certain pages, collecting aggregated usage data including page views, session duration, and navigation patterns. We also use Vercel Speed Insights (operated by Vercel, Inc.) for real-user performance monitoring. This data is used to understand how the Platform is used and to improve it.

4.5 Cookies and similar technologies

Strictly necessary — authentication, session management, CSRF protection: sb-* Supabase Auth cookies; share auth cookies. No consent required.

Functional / preference — user preferences, AI mode, theme, drafts: knot-theme, knot-ai:mode, knot-ai:search, knot-ai-draft. No consent required (core functionality).

Analytics — usage statistics: Google Analytics cookies (_ga, _gid). Consent required where required by law.

Share Authentication Cookies. When you authenticate a password-protected share link, Knot sets a scoped httpOnly cookie (share_auth_<token>) containing an HMAC-signed credential valid only for that specific share link. This cookie is scoped to the /share/[token] path and is cleared when your browser session ends.

You may control cookies through your browser settings. Disabling necessary cookies will prevent login and core Platform functionality.

5. How we use information

We use personal information for the following purposes:

Creating and managing your account (Contract): account data, billing data.

Processing payments and managing subscriptions (Contract): account data, billing data.

Delivering design services and managing Design Requests (Contract): account data, request content, communications.

Operating the Platform and its features (Contract): all categories.

Operating AI Features — Knot AI assistant, analysis, style profiling (Contract): AI interaction data, account data, content.

Personalizing AI responses using memory and preferences (Contract / Legitimate interests): AI personalization, AI memory.

Processing voice dictation / transcription (Contract): voice dictation audio (transient).

Generating style profiles from website URL when requested (Contract / Consent): website screenshots, CSS tokens.

Sending transactional communications — billing, status updates, security (Contract / Legal obligation): account data, contact details.

Sending trial onboarding communications (Legitimate interests / Consent under CASL): account data, trial status.

Sending marketing communications (Consent): account data, contact details.

Providing team collaboration features (Contract): team data, communications.

Operating the public share link feature (Contract): share configuration, content.

Security, fraud prevention, and abuse detection (Legitimate interests / Legal obligation): IP addresses, usage data, account data.

Rate limiting to protect service stability (Legitimate interests): IP addresses, user IDs.

Error tracking and debugging (Legitimate interests): error data, session context.

Analytics and product improvement (Legitimate interests / Consent for cookies): aggregated usage data.

Legal compliance and responding to legal process (Legal obligation): all relevant categories.

Dispute resolution (Legitimate interests / Legal obligation): all relevant categories.

Conducting business administration using internal AI tools (Legitimate interests): account data, request data, subscription data.

Enforcing our Terms of Service (Legitimate interests): all relevant categories.

6. Legal bases for processing (GDPR)

For individuals in the European Economic Area (EEA) and United Kingdom, we identify the following legal bases under GDPR Article 6:

Performance of a contract (Art. 6(1)(b)):

Processing necessary to provide the Services you subscribe to, including account management, design service delivery, billing, AI features, and communications integral to the Services.

Legitimate interests (Art. 6(1)(f)):

Processing for security and fraud prevention, rate limiting, error tracking, internal business analytics, product improvement, operating internal administrative tools, and enforcing our Terms. We conduct legitimate interests assessments for each such processing activity and will provide them on request.

Legal obligation (Art. 6(1)(c)):

Processing required by applicable law, including tax record retention, responding to lawful legal process, and breach notification obligations.

Consent (Art. 6(1)(a)):

Processing for non-essential analytics cookies, marketing communications, and any other processing where consent is specifically sought. You may withdraw consent at any time without affecting the lawfulness of prior processing.

Where we process special categories of personal data (Art. 9 GDPR), we do so only to the extent you voluntarily disclose such information in your Content or communications, and we rely on your explicit consent (Art. 9(2)(a)) or the “manifestly made public” exception where applicable.

7. Sharing of information

We share your personal information only in the circumstances described below.

7.1 Subprocessors and service providers.

We share data with third-party vendors who process it on our behalf to deliver the Services. See the full subprocessors table in Section 8.

7.2 Knot design team.

Your Design Requests, project briefs, reference files, and communications are shared with Knot’s human design personnel solely for the purpose of fulfilling your design requests.

7.3 Team members.

In team-enabled accounts, Content and communications are shared with Team Members according to their assigned roles and permissions, as configured by the Team Owner.

7.4 Legal process and compliance.

We may disclose your information when required by applicable law, enforceable court order, government subpoena, or regulatory requirement. Where legally permitted, we will notify you before disclosure.

7.5 Protection of rights.

We may disclose information where necessary to protect the rights, property, or safety of Knot, our customers, or third parties, including to prevent fraud or enforce our Terms.

7.6 Business transfers.

If Knot undergoes a merger, acquisition, asset sale, restructuring, or similar transaction, your information may be transferred to the successor entity. We will notify you by email and/or prominent Platform notice before your information becomes subject to a different privacy policy.

7.7 External visitors via share links.

When you create a public share link, the content you designate is accessible to external visitors. External visitor IP addresses and browser metadata are processed by Knot’s infrastructure for security and rate limiting only.

7.8 With your explicit consent.

We may share information with third parties when you have provided explicit, informed consent for the specific sharing.

7.9 No sale or sharing for advertising.

We do not sell your personal information. We do not share your personal information with third parties for those parties’ own direct marketing or advertising purposes. We do not engage in cross-context behavioral advertising.

8. Subprocessors

The following third-party providers process personal data on Knot’s behalf:

Supabase, Inc. (USA):

Account data, all user content, AI conversation data, file storage, authentication tokens, team data. Purpose: database, authentication, realtime messaging, file storage. DPA: Yes.

Stripe, Inc. (USA):

Billing data, payment card data (exclusively). Purpose: payment processing, subscription management, invoicing. DPA: Yes (standard Stripe DPA).

Google LLC — Google Gemini / Google AI Studio (USA):

AI prompts, conversation content, uploaded file content (48-hour TTL in Gemini File API), search queries for grounding. Purpose: AI model inference, context caching, Google Search grounding. Covered by Google's Cloud DPA

Groq, Inc. (USA):

Voice dictation audio only (transient, for Whisper speech-to-text transcription). No LLM, text, or vision prompts are sent to Groq. Purpose: speech-to-text transcription. DPA: Contact support/legal

Resend, Inc. (USA):

Email address, name, email content (transactional and drip emails). Purpose: transactional email delivery, trial drip campaign. DPA: Yes.

Vercel, Inc. (USA, global edge network):

All HTTP request data, IP addresses; real-user performance metrics via Speed Insights. Purpose: cloud hosting, serverless function execution, edge CDN, and performance monitoring. DPA: Yes.

Cloudinary Ltd. (USA / Israel, global CDN):

Completed design Deliverables, file metadata. Purpose: media storage, CDN delivery, format transformation. DPA: Contact support

Upstash, Inc. (USA / Turkey):

IP addresses and user IDs used as rate-limit keys. Purpose: Redis-based rate limiting. DPA: Contact support

Browserbase, Inc. (USA):

Screenshots of your public website when URL seeding is used. Purpose: headless browser sessions for Style Profile URL seeding. DPA: Contact support

APIflash (UK):

Screenshots of your public website (fallback when Browserbase is unavailable). Purpose: screenshot API fallback. DPA: Contact support

OpenAI, Inc. (USA):

Instant Revision source images and edit prompts. Purpose: image-edit inference (gpt-image-2). DPA: Contact support / OpenAI DPA

Functional Software, Inc. / Sentry (USA):

Error messages, stack traces, user IDs, session context at time of error. Purpose: application error tracking and performance monitoring. DPA: Yes.

Slack Technologies, LLC / Salesforce (USA):

Slack workspace access token, Slack channel ID, message content sent via integration. Purpose: optional Slack workspace integration. DPA: Yes (standard Slack DPA).

Google LLC — Google Drive API (USA):

OAuth tokens, connected Google account email, and files/folders Knot creates in the customer’s Drive under the drive.file scope (including the Knot Exports folder). Purpose: optional Google Drive export/mirror integration. DPA: Covered by Google Cloud / Workspace terms as applicable

Google LLC — Google Analytics / GTM (USA):

Aggregated usage data, IP addresses (anonymized where applicable), browser/device metadata. Purpose: analytics and tag management. DPA: Yes.

9. International data transfers

Knot is based in Ontario, Canada. Canada has received an adequacy finding from the European Commission under PIPEDA, meaning that transfers of personal data from the EEA to Knot in Canada are generally permitted without additional transfer mechanisms, subject to the limitations of that adequacy finding.

However, Knot uses subprocessors located in the United States and other countries that may not have been granted an equivalence or adequacy determination. For transfers of EEA or UK personal data to such countries, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (2021 SCCs) and/or the UK International Data Transfer Agreement (IDTA) or UK Addendum as applicable, and other appropriate safeguards under GDPR Article 46 or UK GDPR as applicable.

We will provide copies of applicable transfer mechanisms on request. Contact us at support@knotdesign.ca with subject “Transfer Mechanism Request.”

10. Data retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, and thereafter only as required by applicable law, tax obligations, or legitimate business needs.

Account and identity information:

duration of active account + 90 days post-closure.

Design requests, project content, chat messages, voice messages, brand assets, AI conversations:

duration of active account + 90 days post-closure.

AI memory and personalization settings:

until cleared by you or account deletion.

AI agent action logs:

rolling 90 days.

Completed Deliverables (Design Drive):

duration of active account + 90 days; soft-deleted files permanently purged after the 7-day recovery window expires.

Soft-deleted Design Requests:

7-day recovery window; permanently purged thereafter.

Billing and payment records:

7 years from transaction date (legal / tax obligation).

IP addresses (rate limiting):

duration of the applicable rate-limit window (minutes to hours).

Error logs (Sentry):

approximately 90 days.

Analytics data (Google Analytics, aggregated):

up to 26 months.

Share link records and share comments:

until revoked or account closure + 90 days.

Instant Revision jobs and candidates:

duration of active account, or until purged with related Deliverable/request data.

Google Drive connection tokens and folder metadata:

until you disconnect Google Drive or your account is closed.

Trial drip email send records:

2 years from dispatch (CASL compliance).

Voice dictation audio:

not retained by Knot beyond the transcription session.

Website screenshots (Browserbase / URL seeding):

used for immediate style analysis; not independently stored by Knot beyond the session.

Push notification subscriptions (VAPID):

until revoked by you or account closure.

11. Security

We implement technical and organizational security measures proportionate to the nature and sensitivity of the personal information we process.

Technical measures:

TLS encryption for all data in transit; encryption of data at rest within Supabase infrastructure; Row-Level Security (RLS) controls on all database tables enforcing per-user data isolation; HMAC-signed tokens for share link authentication; bcrypt password hashing (cost factor 12) for share link passwords; rate limiting using Redis-backed counters; signed upload tokens for Cloudinary; audit logging of all AI agent actions and administrative operations; scope-restricted storage policies; Vercel edge security and WAF protection.

Organizational measures:

Access to production data limited to personnel with a need-to-know; subprocessors selected based on security and compliance capabilities; regular internal security review processes; monitoring of dependency security advisories.

Incident response:

In the event of a security breach involving personal data, we will: investigate and contain the incident promptly; notify affected individuals without undue delay where required by applicable law; notify applicable regulatory authorities within mandatory timeframes (72 hours under GDPR; as soon as feasible under PIPEDA); and document the incident and our response.

No security system is impenetrable. Despite our measures, we cannot guarantee the absolute security of information transmitted over the internet or stored on any system.

12. Your rights

12.1 Universal rights

All users of the Services may:

Access:

Review the personal information we hold about you through your account settings.

Correct:

Update inaccurate or incomplete profile and preferences data through your account settings.

Delete:

Request deletion of your account and associated personal data (see Section 12.5).

Review AI memory:

Access, edit, or clear your AI memory at any time through the AI settings in your account or by asking Knot AI directly.

Opt out of marketing:

Unsubscribe from marketing communications at any time via the unsubscribe link in any marketing email or by contacting us.

Portfolio opt-out:

Request that your Deliverables not be used in Knot’s portfolio (see Terms of Service Section 27.5).

12.2 GDPR rights (EEA and UK residents)

Right of Access (Art. 15):

Obtain confirmation of whether we process your personal data, and if so, a copy of it and information about the processing. Submit request to support@knotdesign.ca.

Right to Rectification (Art. 16):

Request correction of inaccurate personal data. Update in account settings or contact us.

Right to Erasure / “Right to be Forgotten” (Art. 17):

Request deletion of your personal data where one of the statutory grounds applies. Contact us (see Section 12.5).

Right to Restriction of Processing (Art. 18):

Request that we restrict processing while a dispute about accuracy or lawfulness is resolved. Contact us.

Right to Data Portability (Art. 20):

Receive personal data you provided to us in a structured, machine-readable format. Contact us — see Section 12.6.

Right to Object (Art. 21):

Object to processing based on legitimate interests or direct marketing; we will cease unless we can demonstrate compelling legitimate grounds. Contact us.

Rights Related to Automated Decision-Making (Art. 22):

Not to be subject to solely automated decisions that produce legal or similarly significant effects about you. Contact us — see Section 13.5.

Right to Withdraw Consent (Art. 7(3)):

Withdraw consent for consent-based processing at any time without affecting prior processing. Use unsubscribe links or contact us.

Response timeframes:

We will respond to rights requests within 30 days of receipt, extendable by 60 days for complex or multiple requests. We may require identity verification. You have the right to lodge a complaint with your local supervisory authority — EU: your national DPA; UK: ICO (ico.org.uk); Canada: OPC (priv.gc.ca).

12.3 CCPA/CPRA rights (California residents)

Right to Know:

Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties with whom we share it.

Right to Delete:

Request deletion of personal information we have collected, subject to certain exceptions.

Right to Correct:

Request correction of inaccurate personal information.

Right to Opt-Out of Sale / Sharing:

We do not sell personal information or share it for cross-context behavioral advertising. No opt-out is required, but we honor requests submitted to support@knotdesign.ca.

Right to Limit Use of Sensitive Personal Information:

To the extent we collect sensitive personal information, you may request that we limit its use to what is necessary to provide the Services.

Right to Non-Discrimination:

We will not discriminate against you for exercising any CCPA/CPRA rights. Submit requests by emailing support@knotdesign.ca with subject “California Privacy Request.”

12.4 Canadian privacy rights (PIPEDA)

Canadian residents have the right to: be informed about the purposes for which personal information is collected; access personal information held about them and challenge its accuracy; withdraw consent for the collection, use, or disclosure of personal information, subject to constraints, with reasonable notice; request correction of inaccurate, incomplete, or outdated personal information; and file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.

12.5 Quebec rights (Law 25 / Bill 64)

Residents of Quebec have additional rights including: the right to be informed of automated decision-making that produces legal effects or significantly affects you; the right to human intervention in automated decision-making; the right to deindexation — requesting that information disseminated on the internet be deindexed or de-listed where applicable; and enhanced data portability rights for computerized personal information.

12.6 Data portability and export

You may export certain data directly from your account settings, including AI personalization settings and AI memory. For a comprehensive export of your personal data, contact us at support@knotdesign.ca with subject “Data Export Request.” We will provide your data in a structured, machine-readable format within 30 days.

12.7 Account deletion and data deletion

You may request deletion of your account and personal data by: using the account deletion feature in your account settings (Danger Zone section), or contacting us at support@knotdesign.ca with subject “Account Deletion Request.”

Upon account deletion: we will delete or anonymize personal data within 90 days; billing and payment records will be retained for 7 years (tax and accounting obligations); data subject to legal holds may be retained for the duration of such proceedings; aggregated, anonymized data that cannot be linked to you will not be deleted.

13. AI features and automated processing

13.1 AI providers and data transmission

When you use AI Features, your Content, prompts, and related context are transmitted to third-party AI model providers:

Google LLC (Google Gemini):

Conversation text, uploaded files, design context, style profile summaries. Privacy policy: ai.google.dev/terms; policies.google.com/privacy.

Groq, Inc.:

Voice dictation audio only (transient Whisper transcription). No conversation text or brief content is sent to Groq. Privacy policy: groq.com/privacy.

OpenAI, Inc.:

Instant Revision images and edit prompts for gpt-image-2 image-edit inference. Privacy policy: openai.com/privacy.

13.2 AI memory

Knot AI maintains persistent memory — a store of factual notes about your preferences, work style, and context — to personalize future AI interactions. This memory: is stored in your Knot account (in the ai_personalization database record); is transmitted to Google Gemini as context at the start of each AI session; is limited to 1,000 characters with automatic trimming; can be reviewed, edited, or cleared at any time in your account AI settings or by asking Knot AI; and is cleared automatically upon account deletion.

13.3 AI personalization

You may configure the following AI preferences, which are stored in your account and used with every AI session: Nickname — what Knot AI calls you; Occupation — your professional role; About — a brief self-description; Tone — preferred response style (Balanced, Concise, Detailed, Casual, or Formal); Web Search Default — whether web search is enabled by default. These preferences can be updated or deleted at any time.

13.4 AI agent tool call logging

Every action taken by the Knot AI agent on your behalf is logged in an audit trail (the “agent_action_log”). This log records: tool name, input parameters, result, execution time in milliseconds, and whether the action was confirmed or cancelled by you. Agent logs are retained for 90 days on a rolling basis.

13.5 Automated processing and decision-making

Brief quality analysis (advisory only — no significant legal effect): AI scores your design brief and suggests improvements.

Query thinking budget classification (internal only — no user-facing effect): AI classifies your query to allocate appropriate processing resources.

Style profile generation (improves service quality): AI analyzes Deliverables to build your brand style fingerprint.

AI agent tool execution (consequential actions require your explicit confirmation before execution): AI takes actions on your behalf after you confirm.

Automated Design Request creation (results from your configuration — you control all parameters): cron-based system creates design requests per your automation configuration.

Trial drip email scheduling (administrative communications only): system determines which drip email to send based on trial day count.

We do not use fully automated processing (without human involvement) to make decisions that produce legal effects or similarly significant effects on you. AI agent actions that have material platform consequences require your explicit confirmation via the Platform’s confirmation gate system.

14. Voice and audio data

14.1 Voice messages

Voice message recordings created in the team chat are audio files captured in your browser using the standard MediaRecorder Web API. The completed audio file is uploaded to and stored in Knot’s private Supabase Storage bucket (voice-messages). These files are accessible to Knot’s design team through the messaging interface and to you through your chat history. Voice message audio is retained for the duration of your active account plus 90 days following account closure.

14.2 Voice dictation (AI interface)

Voice dictation in the Knot AI interface operates as follows: (1) your browser records audio from your device’s microphone using MediaRecorder; (2) after you finish speaking, the complete audio blob is transmitted over HTTPS to Knot’s server; (3) Knot’s server transmits the audio to Groq, Inc.’s Whisper speech-to-text API; (4) the transcribed text is returned to Knot and inserted as editable draft text in your AI input; (5) the audio file is not stored by Knot beyond the transcription request. The resulting transcript is treated as normal text input from that point.

14.3 Microphone access

Microphone access requires explicit permission through your browser’s permission system. Knot does not access your microphone without this browser-level grant. You may revoke microphone access through your browser settings at any time.

15. Website screenshot processing (style profile)

If you use the Style Profile URL seeding feature by providing your website URL, the following process occurs:

(1) Knot uses Browserbase, Inc.’s cloud browser infrastructure to load your public website in a headless browser.

(2) The Browserbase session captures: desktop and mobile viewport screenshots, scrolled-section screenshots, and computed CSS design tokens (colors, typography, spacing, etc.) extracted from DOM elements.

(3) These artifacts are transmitted to Google Gemini for AI analysis to generate your Style Profile.

(4) Knot stores your Style Profile analysis results in your account but does not independently retain raw website screenshots beyond the seeding session.

(5) Only your publicly accessible website is accessed — Knot does not log in to any account on your behalf or access content requiring authentication.

By using the URL seeding feature, you authorize Knot and Browserbase to access and screenshot your public website. This authorization covers your own website only; do not submit URLs for websites you do not own or have authorization to process.

16. Children

The Services are not directed to children under the age of 18 and we do not knowingly collect personal information from anyone under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will promptly delete it and close the associated account.

If you are a parent or guardian and believe that your child has provided personal information to Knot without your consent, please contact us immediately at support@knotdesign.ca with subject “Minor Data Concern.”

17. Marketing and email communications

17.1 Types of communications

Account transactional emails (confirmations, password resets): triggered by account actions. No opt-out available (necessary for account operation).

Billing emails (invoices, payment failures, renewal reminders): triggered by subscription events. No opt-out available (necessary for billing).

Design Request status updates: triggered by request status changes. No opt-out available (core service feature).

Security alerts: triggered by security events. No opt-out available (necessary for account security).

Team invitation emails: triggered by Team Owner action. No opt-out available (necessary for team operation).

Trial onboarding drip series (days 3, 5, 6, 7): triggered by trial activation. Opt-out available via unsubscribe link.

Marketing and promotional emails: sent with consent. Opt-out available via unsubscribe link or contacting us.

17.2 CASL compliance (Canada)

For recipients in Canada, we comply with Canada’s Anti-Spam Legislation (CASL). We send commercial electronic messages only where we have express consent from the recipient, or implied consent as defined under CASL (e.g., existing business relationship). All commercial electronic messages include: accurate identification of Knot; a functioning unsubscribe mechanism honored within 10 business days.

17.3 Opt-out

You may opt out of marketing and non-essential promotional communications at any time by: clicking the “Unsubscribe” or “Opt Out” link in any such email, or emailing support@knotdesign.ca with subject “Unsubscribe.” Opting out of marketing emails does not affect transactional communications related to your account and subscription.

18. Do not track

Our Platform does not currently respond to browser-initiated “Do Not Track” (DNT) signals. We will update this Policy if we implement DNT response functionality in the future. You may control tracking through browser cookie settings and any available cookie consent tool.

19. Third-party links and services

The Platform or Deliverables may contain links to third-party websites, services, or applications. This Privacy Policy does not apply to those third parties, and Knot is not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access.

20. Cookies and consent management

You may manage non-essential cookies through your browser settings at any time. Instructions for managing cookies are available in your browser’s documentation.

Disabling strictly necessary cookies (authentication, session management) will prevent you from logging in or using the Platform.

21. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or Platform features. When we make material changes, we will: post an updated Policy with a new “Last Updated” date; post a prominent notice on the Platform; and send an email notification to your registered email address.

Changes become effective upon posting unless otherwise specified. Your continued use of the Services following the effective date of a change constitutes acceptance of the updated Policy. If you do not accept the revised Policy, you should discontinue use of the Services and contact us to request account deletion.

22. Contact information and complaints

For privacy inquiries, data subject access requests, or any concern about our data practices, contact us at:

Knot

Ontario, Canada

Privacy email:

support@knotdesign.ca

Subject:

Please specify: “Privacy Inquiry,” “GDPR Rights Request,” “CCPA Request,” “Data Deletion Request,” “Data Export Request,” “Transfer Mechanism Request,” or other.

We aim to respond to all privacy inquiries within 30 days.

Supervisory authority contacts:

Canada:

Office of the Privacy Commissioner of Canada (OPC) — priv.gc.ca

Quebec:

Commission d’accès à l’information du Québec (CAI) — cai.gouv.qc.ca

EU:

Your national Data Protection Authority — edpb.europa.eu/about-edpb/about-edpb/members

UK:

Information Commissioner’s Office (ICO) — ico.org.uk

California:

California Privacy Protection Agency (CPPA) — cppa.ca.gov

You have the right to lodge a complaint with any applicable supervisory authority without prejudice to any other administrative or judicial remedy.

This Privacy Policy was last reviewed and updated on July 19, 2026.