Privacy policy.
What we collect, why, and what we never do with it.
Last updated 5 May 2026
1. Who we are
Knave AI is operated by Blue Dog Digital, a sole trader registered in Wales (UK), trading as Knave AI. For UK GDPR purposes:
- Controller for your account data (your name, email, billing address, login activity).
- Processor for the customer brand content, contact lists and integration data you upload to the platform. You are the controller of that data. Our processor obligations are in the DPA.
Data Protection contact: legal@knave.app.
2. What we collect
From you, the account holder:
- Name, email, business name, country.
- Billing details (handled and stored by Stripe; we hold an ID, not the card).
- Login activity, IP address, browser, device fingerprint for security and abuse prevention.
- Support messages and any content you send to us by email or in-app chat.
From your workspace (you're the controller, we're the processor):
- Brand documents, voice samples, product info, FAQs you upload.
- Contact lists you import or sync from your CRM-lite or email tool.
- OAuth tokens for connected integrations (Klaviyo, Mailchimp, Brevo, GA4, Google Search Console, Instagram, Facebook, LinkedIn, X, Shopify).
- Content we generate on your behalf (drafts, approvals, published versions).
3. Why we collect it (lawful basis)
Contract. Most processing is necessary to deliver the service you signed up for. Account data, billing, generating content, sending the emails you asked us to send.
Legitimate interest. Security logs, fraud prevention, abuse detection, product analytics on aggregate usage. We balance these against your rights and document the assessment.
Consent. Where you explicitly opt in. For example, if you opt in to let us use anonymised samples of your generated content to improve our prompts. Default is off. You can withdraw consent any time.
Legal obligation. Tax records, accounting, responding to lawful regulator or court requests.
4. Sub-processors
We use a small set of sub-processors to run the service. Each one has a written contract with us that includes the same data protection terms we offer you, and where they're outside the UK or EU, the transfer mechanism named below.
| Sub-processor | Purpose | Location | Transfer |
|---|---|---|---|
| Anthropic | Large language model. Generates draft content from your brand brief. | USA | Standard Contractual Clauses (UK + EU IDTA) |
| OpenAI | Image generation and text embeddings for retrieval. | USA | Standard Contractual Clauses (UK + EU IDTA) |
| Resend | Transactional email (sign-up, password reset, billing receipts). | USA | Standard Contractual Clauses |
| Stripe | Payment processing and subscription billing. | USA + Ireland | Standard Contractual Clauses |
| Cloudflare | CDN, custom hostname SSL via Cloudflare for SaaS, R2 object storage. | Global edge, EU data residency where configured | Standard Contractual Clauses |
| Hetzner | Application servers and Postgres database. | Germany / Finland (EU) | No transfer required (EU) |
We give 30 days notice before adding a new sub-processor. If you object, you can cancel and get a pro-rata refund on any prepaid period.
5. Data residency
Application servers and the primary Postgres database run in Hetzner's EU regions (Germany and Finland). Backups stay in the EU. Cloudflare R2 storage for generated assets is configured to EU data residency.
Some processing has to leave the EU because the underlying model providers (Anthropic, OpenAI) are US-based. We use Standard Contractual Clauses and the UK International Data Transfer Addendum to cover those flows. We send the minimum data needed for the request, no more.
6. Retention
Active accounts: we keep your data for as long as your account is active.
Cancelled accounts: 30-day grace period (your data stays live, you can come back), then 14 days to fully delete. Total: 44 days from cancellation. Backup tapes age out within 30 days of the next rotation cycle.
Export: you can export your data at any time from the dashboard. Email legal@knave.app if you need help with a bulk export.
Some records (invoices, tax records) we keep for the period UK law requires, even after account deletion. Currently 6 years.
7. Your rights
Under UK GDPR you have the right to:
- Access the data we hold about you (Article 15).
- Have it corrected if it's wrong (Article 16).
- Have it deleted (Article 17).
- Restrict our processing of it (Article 18).
- Receive it in a portable format (Article 20).
- Object to processing based on legitimate interest (Article 21).
- Not be subject to automated decisions with legal effect (Article 22). Knave doesn't make automated decisions of this kind.
Email legal@knave.app to use any of these. We respond within 30 days, usually faster. No fee for reasonable requests.
8. Cookies
Knave uses one strictly necessary auth cookie and the cookies Stripe sets during the billing flow. No marketing cookies, no third-party trackers. Details in the cookie policy.
9. International transfers
Where data leaves the UK or EU we rely on Standard Contractual Clauses (and the UK International Data Transfer Addendum). The transfer mechanism for each sub-processor is in the table above. Copies of the executed clauses are available on request.
10. Children
Knave is for businesses. We don't knowingly collect personal data from anyone under 18. If you believe a child has signed up, email legal@knave.app and we'll delete the account.
11. Security incidents
If we become aware of a personal data breach affecting your data, we'll notify you within 72 hours of becoming aware, with what we know at that point and what we're doing about it. We'll keep you updated as we learn more. Details on our security posture are in the security overview.
12. Updates
We can update this policy. For material changes we'll email account holders at least 90 days before the change takes effect. Minor edits get posted with a new "last updated" date.
13. Complaints
Talk to us first: legal@knave.app. If we can't resolve it, you have the right to complain to the Information Commissioner's Office (ICO), the UK regulator, at ico.org.uk. EU residents can also complain to their local supervisory authority.
If anything's unclear, email legal@knave.app. Saul Brennan, our General Counsel, replies within one business day.