Last updated 1 September 2026
These have not been reviewed by a lawyer. They describe honestly how KnocklyKnocks works today and are a starting point for a professional to review, not a substitute for that review.
KnocklyKnocks is operated by [operator not configured]. This policy covers two groups of people whose data passes through the product, and they are treated differently because their relationship to it is different:
Customers are the businesses that sign up and use KnocklyKnocks to reach prospects. Recipients are the businesses a customer contacts. A recipient never signs up, never agrees to anything, and can stop all contact at any time.
Connecting Google is optional, and KnocklyKnocks cannot send email or book meetings without it. Four permissions are requested, and this is what each one is actually used for:
KnocklyKnocks never deletes or edits your existing mail or existing calendar entries. Your Google tokens are encrypted before they are stored, and you can disconnect at any time from your dashboard or from your Google account security settings, which revokes access immediately.
KnocklyKnocks's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through these permissions is used only to provide the features described above. It is never sold, never used for advertising, and never used to train any machine learning model.
To write a relevant email, KnocklyKnocks gathers information that is already public: business name, address, phone number, category and review counts from Google Places, a publicly listed email address from the business's own website, and text from the public pages of that website.
Most of this describes a company rather than a person. Some of it does not. A business email address like jane@example.com and a contact name on a website are personal data under laws including the GDPR and the CCPA, and are treated as such here.
KnocklyKnocks does not buy lead lists, does not scrape social networks, and does not attempt to find personal email addresses, home addresses, or mobile numbers of individuals.
Every message includes a working one-click unsubscribe link and the sender's postal address, as US law requires. Unsubscribing takes effect immediately and permanently: the address is added to a suppression list that blocks it across the entire platform, not just for the customer who contacted you. No further email is sent.
You can also write to pivotngoyb@gmail.com to ask what is held about you, to correct it, or to have it deleted. Depending on where you live you may have those rights by law; they are offered here regardless.
KnocklyKnocks is built on other companies' services, and data passes through them to make the product work:
KnocklyKnocks does not sell personal information and does not share it for advertising.
Each business gets its own workspace. Leads, drafts, sent mail, replies, bookings, calendar access and Google tokens are stored against that workspace and are readable only by it. This is enforced in the database itself through row-level security keyed on the workspace, rather than only in application code.
One deliberate exception: the unsubscribe suppression list is shared across the whole platform. If someone opts out of one customer's outreach, no customer can email that address. This is a decision that favours recipients over customers, and it means one customer's opt-out can prevent another customer contacting the same business.
Customer data is kept for as long as the account exists. If you close your account, tell us and it will be deleted within 30 days, except records the law requires be kept: the audit log of what was sent, to whom, and when, and the suppression list, which must survive account deletion or an unsubscribe could be undone by closing an account.
Prospect data is deleted when the customer deletes the lead or closes the account, subject to the same two exceptions.
Google tokens are encrypted before storage. All traffic is over HTTPS. Access to the production database is limited to the operator. KnocklyKnocks is a small product run by a small business, and it would be dishonest to claim a formal security certification it does not hold. If that matters for your use, ask before signing up.
Material changes will be notified by email to the address on the account. Questions about anything here go to pivotngoyb@gmail.com.