Privacy Policy
Welcome to Knogents. This Privacy Policy describes how Knogents (“Knogents”, “we”, “us”, or “our”) collects, uses, processes, stores, and protects personal data and business information when you use our website, cloud platform, AI-powered knowledge base agents, application programming interfaces (APIs), and embeddable chat widgets (collectively, the “Service”).
Knogents operates primarily as a business-to-business (B2B) software-as-a-service provider. When business customers (“Customers” or “Account Owners”) create an account, upload documentation, or deploy our AI widget to their websites, Knogents processes both Customer account data and the inquiries submitted by end visitors (“Visitors” or “End Users”). This policy outlines our technical and legal commitments to both audiences.
1. Eligibility & Minimum Age
The Service is designed and intended strictly for business use by individuals who are at least 18 years of age. We do not knowingly offer our services to, or collect personal information from, individuals under 18 years old. If you become aware that an individual under the age of 18 has registered an account or provided us with personal information, please contact us immediately, and we will take prompt steps to terminate the account and remove the data.
2. Information We Collect and How We Collect It
2.1 Customer Account Information
When you register for an account with Knogents, we collect:
- Identity & Contact Information: Your full name and business email address.
- Authentication Credentials: Password hashes. Passwords are never stored in plaintext; they are hashed using the PBKDF2-SHA512 algorithm with 210,000 iterations and cryptographic salts (with backward-compatible verification for legacy 10,000-iteration credentials that automatically upgrade upon subsequent login).
- Single Sign-On (Google OAuth): If you choose to authenticate via Google Single Sign-On, we receive your verified email address, full name, and unique Google OAuth identifier from Google LLC.
- Geographic Data Note: Our database schema includes fields for country and state to accommodate future localized features; however, we do not currently collect, derive, or populate user country or state during registration, via IP geolocation, or through billing profile forms.
2.2 Knowledge Base & Training Content
To train and ground your AI agent in verified company knowledge, Customers provide:
- Website URLs & Crawled Content: Public URLs submitted for automated indexing. Knogents extracts text, page titles, and structure to generate vector embeddings.
- Uploaded Documentation: PDF documents, text files, product sheets, and manuals uploaded directly to the Knowledge Base.
- Business Profile Information: Customer support email addresses, business phone numbers, physical company addresses, and agent branding preferences configured in your Agent Studio or extracted from your public web footprint.
- Custom Instructions: Custom system prompts and behavioral instructions configured by the Customer to direct agent tone and response parameters.
2.3 Visitor & End-User Interactions (Embedded Widget)
When an End User interacts with the Knogents chat widget deployed on a Customer’s website, we process:
- Visitor Queries & AI Responses: The text of messages sent by visitors and the corresponding responses generated by the agent. These are stored in conversation logs linked to a pseudonymous session token and the Customer’s tenant ID.
- Ephemeral Page Context: To assist the AI in answering questions specific to the page currently being viewed, the widget may transmit live contextual parameters from the visitor’s browser, such as the current page URL, page title, and visible text snippets.Strict In-Memory Isolation: Page context is held strictly in volatile server memory with an automatic Time-To-Live (TTL) of 30 minutes, pruned by a recurring 5-minute background sweep. Page context is never written to database tables or permanent storage.
- Blocked Request Logs: If a visitor submits an inquiry after a Customer’s monthly message credit quota has been exhausted, our server records the event in a blocked requests log (containing the tenant ID, bot ID, session token, the text of the attempted visitor message, the block reason, and timestamp). No IP address is logged. These records currently persist indefinitely until manually cleared.
2.4 Technical Data, Rate Limiting, and IP Addresses
We do not store or log visitor IP addresses in our database.
When incoming chat requests are received by our API, the client IP address (extracted from HTTP request headers such as x-forwarded-for) is processed transiently and in-memory solely to calculate sliding-window rate limits (protecting our infrastructure against denial-of-service attacks and automated scraping). Rate-limit counters are tracked transiently in Upstash Redis (if configured) or in volatile server memory with a 5-minute eviction cycle.
Standard web hosting and edge cloud infrastructure providers (e.g., Vercel, reverse proxies, and CDN networks) may log IP addresses in transient HTTP connection logs as an essential operational safeguard. Knogents application code does not persist or query IP addresses.
2.5 Account Notifications & Team Workspaces
- Notifications: We store administrative, operational, and credit-threshold alerts in our database. Customers may dismiss or delete individual notifications through the dashboard. Stored notifications persist until manually deleted.
- Team Member Invitations (Planned Feature): Database structures exist to support multi-user team workspaces with role-based access. However, multi-user team sharing is currently disabled in production. Accounts currently operate strictly as single-user workspaces.
3. AI Processing Architecture & Prompt Disclosures
Knogents uses Retrieval-Augmented Generation (RAG) to produce grounded, domain-specific AI responses without model hallucinations. To generate each completion, our backend constructs a structured prompt payload transmitted to our AI inference partners.
What Is Transmitted in an LLM Prompt:
- Visitor Query: The exact text submitted by the visitor.
- Recent Chat History: Up to the last 10 conversation turns within the active session to maintain contextual dialogue.
- Active Page Context: The URL, page title, and visible text snippet of the webpage the visitor is actively browsing (if transmitted via the widget).
- Customer Instructions: The custom system prompt and persona instructions defined by the Customer in Agent Studio.
- Business Contact Details: Company email, phone number, and physical address retrieved from verified Customer profile metadata.
- Knowledge Chunks: The top 4 most relevant text passages retrieved from the Customer’s ingested knowledge base via semantic vector similarity.
AI Service Providers & Cross-Border Processing:
We route AI inference through OpenRouter (openrouter.ai), which acts as our unified AI infrastructure gateway:
- Chat Completions: Routed via OpenRouter to Z.ai running the GLM-5.3-FlashX model.
- Semantic Embeddings: Vector embeddings are generated via OpenRouter using Perplexity (
pplx-embed-v1-4bwith 2,560 dimensions). - Cross-Border Processing Disclosure: By using the Service, you acknowledge and agree that prompts and vector embeddings are processed by OpenRouter and its underlying model providers (Z.ai and Perplexity) on secure cloud infrastructure that may be located outside your country or territory of residence (including the United States and other international jurisdictions).
4. Sub-Processors & External Services
We work with verified third-party infrastructure providers to host, secure, and deliver the Service. These sub-processors have access to data solely to perform specific technical tasks:
| Service / Entity | Purpose | Data Processed |
|---|---|---|
| OpenRouter | AI inference orchestration | Chat prompts, context, knowledge excerpts |
| Z.ai & Perplexity | LLM completions & embeddings | Prompt text, document chunks for indexing |
| Neon PostgreSQL | Cloud database & vector store | Account data, vector chunks, chat logs (TLS/SSL in transit) |
| Google LLC (OAuth) | Federated Single Sign-On | Name, email, OAuth user identifier |
| Google Favicon API | Agent avatar brand icons | Customer website domain hostname only |
| Jina Reader (r.jina.ai) | Scraping fallback for web apps | Public web page URLs submitted for ingestion |
| Google Fonts CDN | Typography asset delivery | Standard browser HTTP request headers |
| Upstash Redis (Optional) | Distributed rate limiting | Hashed rate-limit keys and request counts |
| Razorpay (Planned) | Merchant payment gateway | Designated payment processor once paid subscriptions and add-on billing are activated |
5. Data Retention & Conversation History
Conversation Logs: Inquiries submitted to your deployed agent and the AI responses generated are retained in our database for the lifetime of your account. This allows Account Owners to inspect conversation telemetry, analyze resolution metrics, and convert unanswered visitor questions directly into permanent FAQ entries.
Important Note on Dashboard Features: The Knogents web dashboard does not currently include a self-service feature to delete individual conversation logs. Conversation records remain associated with your tenant until your account is formally terminated and purged.
Knowledge Base Content: Customer documents, crawled URLs, and vector chunks remain stored until explicitly modified or deleted by the Customer within the Knowledge Base dashboard.
Disaster Recovery Backups: System backups maintained for business continuity and disaster recovery are cycled automatically on rolling retention schedules and permanently overwritten.
6. Technical Security Measures
We implement industry-standard technical and organizational safeguards designed to protect personal data against unauthorized access, loss, and alteration:
- Session Security: Authenticated sessions use cryptographic HMAC-SHA256 signed session tokens delivered in
httpOnly,sameSite: "lax", secure cookies with a strict 7-day expiration lifetime. - Encryption in Transit: All data transmitted between your browser, our servers, external APIs, and our managed PostgreSQL database is encrypted using Transport Layer Security (TLS/SSL with
sslmode=require). - Multi-Tenant Data Isolation: Every database query and vector retrieval operation strictly enforces tenant boundaries (
client_id) server-side, preventing cross-tenant data leakage. - CORS & Origin Validation: Widget APIs strictly validate registered allowed domains to protect against unauthorized embed spoofing and cross-origin abuse.
- Breach Notification: In the unlikely event of a confirmed security breach impacting your personal data, we will notify affected account holders without undue delay in accordance with applicable statutory timelines.
7. Your Data Rights & Account Deletion Process
Depending on your location, you may have rights under applicable privacy laws (including GDPR, UK GDPR, and applicable national regulations) to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete personal information.
- Request the complete deletion of your account and associated data.
- Object to or request restrictions on our processing of your data.
Manual Account & Data Deletion Workflow
Because an automated self-service account deletion button is not currently implemented in the web settings dashboard, all account closure and data deletion requests are processed manually by our engineering team.
To request the deletion of your account, email our support team at [SUPPORT EMAIL] from your registered account email address with the subject line “Account Deletion Request”. We will verify your identity and permanently delete your user record, chatbots, ingested knowledge files, vector embeddings, and conversation logs within 30 days, retaining only those records required for legal, tax, or regulatory compliance.
8. Rights Under Applicable Indian Law
For users accessing the Service from India, data processing is carried out in adherence to the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (as effective).
Indian users have the right to access summaries of personal data processed, seek correction or erasure of inaccurate personal data, nominate an individual in the event of death or incapacity, and access grievance redressal mechanisms as set out below.
9. Grievance Redressal Officer
In accordance with the Information Technology Act, 2000 and the rules made thereunder, any questions, concerns, or grievances regarding the processing of your personal information may be addressed to our designated Grievance Officer:
We acknowledge grievances within forty-eight (48) hours of receipt and endeavor to resolve complaints within thirty (30) days in accordance with statutory guidelines.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect enhancements to our platform features, evolving technical architectures, or changes in legal and regulatory obligations.
When material changes are made, we will revise the “Last Updated” date at the top of this page and, where appropriate, provide notice via email or a platform notification. We encourage you to review this policy periodically.
11. Contact Us
If you have questions, feedback, or requests regarding this Privacy Policy or our data protection practices, please contact our team: