KnocklyKnocks

Privacy Policy

Last updated 1 September 2026

These have not been reviewed by a lawyer. They describe honestly how KnocklyKnocks works today and are a starting point for a professional to review, not a substitute for that review.

Who this covers

KnocklyKnocks is operated by [operator not configured]. This policy covers two groups of people whose data passes through the product, and they are treated differently because their relationship to it is different:

Customers are the businesses that sign up and use KnocklyKnocks to reach prospects. Recipients are the businesses a customer contacts. A recipient never signs up, never agrees to anything, and can stop all contact at any time.

What KnocklyKnocks accesses in your Google account

Connecting Google is optional, and KnocklyKnocks cannot send email or book meetings without it. Four permissions are requested, and this is what each one is actually used for:

  • Send email as you (gmail.send). Outreach is sent from your own mailbox so replies come back to you. KnocklyKnocks sends only messages you have approved, or, if you switch on automatic sending, messages you approved before they were scheduled.
  • Read email (gmail.readonly). Used only to search for replies from addresses KnocklyKnocks has emailed on your behalf, so a prospect who answers is flagged for you. It reads the matching message to classify the reply. It does not read, index, or store the rest of your mailbox.
  • See when you are free (calendar.freebusy). Used to show real availability on your booking page. KnocklyKnocks sees that a time is busy, not what the meeting is.
  • Create calendar events (calendar.events). Used to put a booked meeting on your calendar when a prospect picks a time.

KnocklyKnocks never deletes or edits your existing mail or existing calendar entries. Your Google tokens are encrypted before they are stored, and you can disconnect at any time from your dashboard or from your Google account security settings, which revokes access immediately.

KnocklyKnocks's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through these permissions is used only to provide the features described above. It is never sold, never used for advertising, and never used to train any machine learning model.

What KnocklyKnocks collects about prospects

To write a relevant email, KnocklyKnocks gathers information that is already public: business name, address, phone number, category and review counts from Google Places, a publicly listed email address from the business's own website, and text from the public pages of that website.

Most of this describes a company rather than a person. Some of it does not. A business email address like jane@example.com and a contact name on a website are personal data under laws including the GDPR and the CCPA, and are treated as such here.

KnocklyKnocks does not buy lead lists, does not scrape social networks, and does not attempt to find personal email addresses, home addresses, or mobile numbers of individuals.

If you received an email from a KnocklyKnocks customer

Every message includes a working one-click unsubscribe link and the sender's postal address, as US law requires. Unsubscribing takes effect immediately and permanently: the address is added to a suppression list that blocks it across the entire platform, not just for the customer who contacted you. No further email is sent.

You can also write to pivotngoyb@gmail.com to ask what is held about you, to correct it, or to have it deleted. Depending on where you live you may have those rights by law; they are offered here regardless.

Who else processes this data

KnocklyKnocks is built on other companies' services, and data passes through them to make the product work:

  • Anthropic receives prospect research and business profile text in order to write emails and texts. Anthropic does not train on data submitted through its API.
  • Google provides Places search, Gmail sending and Calendar.
  • Supabase hosts the database.
  • Vercel hosts the application.
  • Clerk handles sign-in and organisation accounts.
  • Amazon Web Services handles domain verification and system alerts.
  • Sentry receives error reports when something in KnocklyKnocks goes wrong, so it can be found and fixed. It gets the fault and where in the code it happened, and email addresses are removed before anything is sent. It does not receive your leads, your drafts, or any of your mail.

KnocklyKnocks does not sell personal information and does not share it for advertising.

How customers are kept separate

Each business gets its own workspace. Leads, drafts, sent mail, replies, bookings, calendar access and Google tokens are stored against that workspace and are readable only by it. This is enforced in the database itself through row-level security keyed on the workspace, rather than only in application code.

One deliberate exception: the unsubscribe suppression list is shared across the whole platform. If someone opts out of one customer's outreach, no customer can email that address. This is a decision that favours recipients over customers, and it means one customer's opt-out can prevent another customer contacting the same business.

How long data is kept

Customer data is kept for as long as the account exists. If you close your account, tell us and it will be deleted within 30 days, except records the law requires be kept: the audit log of what was sent, to whom, and when, and the suppression list, which must survive account deletion or an unsubscribe could be undone by closing an account.

Prospect data is deleted when the customer deletes the lead or closes the account, subject to the same two exceptions.

Security

Google tokens are encrypted before storage. All traffic is over HTTPS. Access to the production database is limited to the operator. KnocklyKnocks is a small product run by a small business, and it would be dishonest to claim a formal security certification it does not hold. If that matters for your use, ask before signing up.

Changes and contact

Material changes will be notified by email to the address on the account. Questions about anything here go to pivotngoyb@gmail.com.