Knogents Privacy Framework

Privacy Policy

Effective Date: [EFFECTIVE DATE]
Last Updated: [LAST UPDATED]
Entity: Knogents

Welcome to Knogents. This Privacy Policy describes how Knogents (“Knogents”, “we”, “us”, or “our”) collects, uses, processes, stores, and protects personal data and business information when you use our website, cloud platform, AI-powered knowledge base agents, application programming interfaces (APIs), and embeddable chat widgets (collectively, the “Service”).

Knogents operates primarily as a business-to-business (B2B) software-as-a-service provider. When business customers (“Customers” or “Account Owners”) create an account, upload documentation, or deploy our AI widget to their websites, Knogents processes both Customer account data and the inquiries submitted by end visitors (“Visitors” or “End Users”). This policy outlines our technical and legal commitments to both audiences.

1. Eligibility & Minimum Age

The Service is designed and intended strictly for business use by individuals who are at least 18 years of age. We do not knowingly offer our services to, or collect personal information from, individuals under 18 years old. If you become aware that an individual under the age of 18 has registered an account or provided us with personal information, please contact us immediately, and we will take prompt steps to terminate the account and remove the data.

2. Information We Collect and How We Collect It

2.1 Customer Account Information

When you register for an account with Knogents, we collect:

  • Identity & Contact Information: Your full name and business email address.
  • Authentication Credentials: Password hashes. Passwords are never stored in plaintext; they are hashed using the PBKDF2-SHA512 algorithm with 210,000 iterations and cryptographic salts (with backward-compatible verification for legacy 10,000-iteration credentials that automatically upgrade upon subsequent login).
  • Single Sign-On (Google OAuth): If you choose to authenticate via Google Single Sign-On, we receive your verified email address, full name, and unique Google OAuth identifier from Google LLC.
  • Geographic Data Note: Our database schema includes fields for country and state to accommodate future localized features; however, we do not currently collect, derive, or populate user country or state during registration, via IP geolocation, or through billing profile forms.

2.2 Knowledge Base & Training Content

To train and ground your AI agent in verified company knowledge, Customers provide:

  • Website URLs & Crawled Content: Public URLs submitted for automated indexing. Knogents extracts text, page titles, and structure to generate vector embeddings.
  • Uploaded Documentation: PDF documents, text files, product sheets, and manuals uploaded directly to the Knowledge Base.
  • Business Profile Information: Customer support email addresses, business phone numbers, physical company addresses, and agent branding preferences configured in your Agent Studio or extracted from your public web footprint.
  • Custom Instructions: Custom system prompts and behavioral instructions configured by the Customer to direct agent tone and response parameters.

2.3 Visitor & End-User Interactions (Embedded Widget)

When an End User interacts with the Knogents chat widget deployed on a Customer’s website, we process:

  • Visitor Queries & AI Responses: The text of messages sent by visitors and the corresponding responses generated by the agent. These are stored in conversation logs linked to a pseudonymous session token and the Customer’s tenant ID.
  • Ephemeral Page Context: To assist the AI in answering questions specific to the page currently being viewed, the widget may transmit live contextual parameters from the visitor’s browser, such as the current page URL, page title, and visible text snippets.
    Strict In-Memory Isolation: Page context is held strictly in volatile server memory with an automatic Time-To-Live (TTL) of 30 minutes, pruned by a recurring 5-minute background sweep. Page context is never written to database tables or permanent storage.
  • Blocked Request Logs: If a visitor submits an inquiry after a Customer’s monthly message credit quota has been exhausted, our server records the event in a blocked requests log (containing the tenant ID, bot ID, session token, the text of the attempted visitor message, the block reason, and timestamp). No IP address is logged. These records currently persist indefinitely until manually cleared.

2.4 Technical Data, Rate Limiting, and IP Addresses

We do not store or log visitor IP addresses in our database.

When incoming chat requests are received by our API, the client IP address (extracted from HTTP request headers such as x-forwarded-for) is processed transiently and in-memory solely to calculate sliding-window rate limits (protecting our infrastructure against denial-of-service attacks and automated scraping). Rate-limit counters are tracked transiently in Upstash Redis (if configured) or in volatile server memory with a 5-minute eviction cycle.

Standard web hosting and edge cloud infrastructure providers (e.g., Vercel, reverse proxies, and CDN networks) may log IP addresses in transient HTTP connection logs as an essential operational safeguard. Knogents application code does not persist or query IP addresses.

2.5 Account Notifications & Team Workspaces

  • Notifications: We store administrative, operational, and credit-threshold alerts in our database. Customers may dismiss or delete individual notifications through the dashboard. Stored notifications persist until manually deleted.
  • Team Member Invitations (Planned Feature): Database structures exist to support multi-user team workspaces with role-based access. However, multi-user team sharing is currently disabled in production. Accounts currently operate strictly as single-user workspaces.

3. AI Processing Architecture & Prompt Disclosures

Knogents uses Retrieval-Augmented Generation (RAG) to produce grounded, domain-specific AI responses without model hallucinations. To generate each completion, our backend constructs a structured prompt payload transmitted to our AI inference partners.

What Is Transmitted in an LLM Prompt:

  1. Visitor Query: The exact text submitted by the visitor.
  2. Recent Chat History: Up to the last 10 conversation turns within the active session to maintain contextual dialogue.
  3. Active Page Context: The URL, page title, and visible text snippet of the webpage the visitor is actively browsing (if transmitted via the widget).
  4. Customer Instructions: The custom system prompt and persona instructions defined by the Customer in Agent Studio.
  5. Business Contact Details: Company email, phone number, and physical address retrieved from verified Customer profile metadata.
  6. Knowledge Chunks: The top 4 most relevant text passages retrieved from the Customer’s ingested knowledge base via semantic vector similarity.

AI Service Providers & Cross-Border Processing:

We route AI inference through OpenRouter (openrouter.ai), which acts as our unified AI infrastructure gateway:

  • Chat Completions: Routed via OpenRouter to Z.ai running the GLM-5.3-FlashX model.
  • Semantic Embeddings: Vector embeddings are generated via OpenRouter using Perplexity (pplx-embed-v1-4b with 2,560 dimensions).
  • Cross-Border Processing Disclosure: By using the Service, you acknowledge and agree that prompts and vector embeddings are processed by OpenRouter and its underlying model providers (Z.ai and Perplexity) on secure cloud infrastructure that may be located outside your country or territory of residence (including the United States and other international jurisdictions).

4. Sub-Processors & External Services

We work with verified third-party infrastructure providers to host, secure, and deliver the Service. These sub-processors have access to data solely to perform specific technical tasks:

Service / EntityPurposeData Processed
OpenRouterAI inference orchestrationChat prompts, context, knowledge excerpts
Z.ai & PerplexityLLM completions & embeddingsPrompt text, document chunks for indexing
Neon PostgreSQLCloud database & vector storeAccount data, vector chunks, chat logs (TLS/SSL in transit)
Google LLC (OAuth)Federated Single Sign-OnName, email, OAuth user identifier
Google Favicon APIAgent avatar brand iconsCustomer website domain hostname only
Jina Reader (r.jina.ai)Scraping fallback for web appsPublic web page URLs submitted for ingestion
Google Fonts CDNTypography asset deliveryStandard browser HTTP request headers
Upstash Redis (Optional)Distributed rate limitingHashed rate-limit keys and request counts
Razorpay (Planned)Merchant payment gatewayDesignated payment processor once paid subscriptions and add-on billing are activated

5. Data Retention & Conversation History

Conversation Logs: Inquiries submitted to your deployed agent and the AI responses generated are retained in our database for the lifetime of your account. This allows Account Owners to inspect conversation telemetry, analyze resolution metrics, and convert unanswered visitor questions directly into permanent FAQ entries.

Important Note on Dashboard Features: The Knogents web dashboard does not currently include a self-service feature to delete individual conversation logs. Conversation records remain associated with your tenant until your account is formally terminated and purged.

Knowledge Base Content: Customer documents, crawled URLs, and vector chunks remain stored until explicitly modified or deleted by the Customer within the Knowledge Base dashboard.

Disaster Recovery Backups: System backups maintained for business continuity and disaster recovery are cycled automatically on rolling retention schedules and permanently overwritten.

6. Technical Security Measures

We implement industry-standard technical and organizational safeguards designed to protect personal data against unauthorized access, loss, and alteration:

  • Session Security: Authenticated sessions use cryptographic HMAC-SHA256 signed session tokens delivered in httpOnly, sameSite: "lax", secure cookies with a strict 7-day expiration lifetime.
  • Encryption in Transit: All data transmitted between your browser, our servers, external APIs, and our managed PostgreSQL database is encrypted using Transport Layer Security (TLS/SSL with sslmode=require).
  • Multi-Tenant Data Isolation: Every database query and vector retrieval operation strictly enforces tenant boundaries (client_id) server-side, preventing cross-tenant data leakage.
  • CORS & Origin Validation: Widget APIs strictly validate registered allowed domains to protect against unauthorized embed spoofing and cross-origin abuse.
  • Breach Notification: In the unlikely event of a confirmed security breach impacting your personal data, we will notify affected account holders without undue delay in accordance with applicable statutory timelines.

7. Your Data Rights & Account Deletion Process

Depending on your location, you may have rights under applicable privacy laws (including GDPR, UK GDPR, and applicable national regulations) to:

  • Request access to the personal data we hold about you.
  • Request correction of inaccurate or incomplete personal information.
  • Request the complete deletion of your account and associated data.
  • Object to or request restrictions on our processing of your data.

Manual Account & Data Deletion Workflow

Because an automated self-service account deletion button is not currently implemented in the web settings dashboard, all account closure and data deletion requests are processed manually by our engineering team.

To request the deletion of your account, email our support team at [SUPPORT EMAIL] from your registered account email address with the subject line “Account Deletion Request”. We will verify your identity and permanently delete your user record, chatbots, ingested knowledge files, vector embeddings, and conversation logs within 30 days, retaining only those records required for legal, tax, or regulatory compliance.

8. Rights Under Applicable Indian Law

For users accessing the Service from India, data processing is carried out in adherence to the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (as effective).

Indian users have the right to access summaries of personal data processed, seek correction or erasure of inaccurate personal data, nominate an individual in the event of death or incapacity, and access grievance redressal mechanisms as set out below.

9. Grievance Redressal Officer

In accordance with the Information Technology Act, 2000 and the rules made thereunder, any questions, concerns, or grievances regarding the processing of your personal information may be addressed to our designated Grievance Officer:

Name: [GRIEVANCE OFFICER NAME]
Designation: Grievance Redressal Officer
Email: [GRIEVANCE OFFICER EMAIL]
Postal Address: [GRIEVANCE OFFICER ADDRESS]

We acknowledge grievances within forty-eight (48) hours of receipt and endeavor to resolve complaints within thirty (30) days in accordance with statutory guidelines.

10. Changes to This Policy

We may update this Privacy Policy periodically to reflect enhancements to our platform features, evolving technical architectures, or changes in legal and regulatory obligations.

When material changes are made, we will revise the “Last Updated” date at the top of this page and, where appropriate, provide notice via email or a platform notification. We encourage you to review this policy periodically.

11. Contact Us

If you have questions, feedback, or requests regarding this Privacy Policy or our data protection practices, please contact our team:

Entity: Knogents
Registered Address: [REGISTERED ADDRESS]
Support & Privacy Email: [SUPPORT EMAIL]
Contact Page: knogents.com/contact