Legal
Privacy Policy
In plain English
- Your journal is private. Protecting it is our most important job.
- Your writing is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).
- We use Anthropic (Claude) to generate reflections and Deepgram to transcribe voice. Neither trains on your content.
- We never sell your data. We do not share it with advertising networks.
- You can download or delete everything from Account → Privacy at any time.
- You must be 18 or older to use Knoweth.
- Questions or requests: hello@knoweth.app.
The full policy follows below.
This Privacy Policy explains how Knoweth collects, uses, discloses, and protects your personal information. It covers both the marketing website at knoweth.app and the app itself at my.knoweth.app. Knoweth is a self-reflection and journaling companion built to help you understand yourself through writing. Because your writing is at the heart of this product, we take the privacy of that writing seriously.
By visiting our website or using our app, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use Knoweth.
Who we are
Knoweth is operated by Knoweth LLC, based at 110 16th Street, Suite 1460, Denver, CO 80202. For any privacy question, data request, or complaint, contact us at hello@knoweth.app. We aim to respond within 5 business days and resolve requests within 30 days.
What we collect
We describe below what we collect on the marketing website versus what we collect once you create an account and use the app.
On the marketing website (knoweth.app)
- Waitlist email. If you submit your email to be notified about launch or updates, we store your email address and the date you signed up.
- Server logs. Standard web-server logs including your IP address, browser user-agent, request timestamps, and referral URL. Kept for 30 days on a rolling basis and used for security monitoring and traffic analytics.
- Cookies and similar technologies. Only essential cookies today (session state, form CSRF token). We plan to add privacy-respecting product analytics (PostHog); when we do, this policy will be updated and, where required, we will show a cookie consent notice.
In the app (my.knoweth.app), once you sign up
- Account information. Email address, hashed password (via Supabase Auth), optional display name, date of birth (used only to verify you are 18 or older; not retained after validation), time zone, preferred language.
- Preferences. Appearance settings, primary color, typeface, reflection-lens toggles, home widget layout, notification preferences.
- Your writing. The journal entries you create, associated topics or journals, timestamps, and any attached mood check-ins, photos, or handwritten-page scans.
- Mood and feelings. Mood scores (1 to 10) and any feeling labels you pick from the Feelings Wheel.
- Goals and check-ins. Titles, descriptions, frequency, emoji, and each recorded completion.
- Contacts. Names and relationships you optionally add for relationship-tracking features. We do not access your device contacts.
- Voice recordings. If you use voice journaling (Pro), your audio is streamed to our transcription vendor (Deepgram) for text conversion. The transcript is stored with your entry. The audio itself is not persisted on our servers or on Deepgram's servers after transcription.
- Photos and handwriting captures. Images you attach to entries (Pro).
- AI-generated content. Reflection prompts, journey follow-up questions, insights, lens reflections, milestone messages, and process plans generated by our AI vendor (Anthropic Claude) based on your entries. Stored so you can revisit them.
- Safety indicators (internal only). A machine-generated tag on each entry (safe, grief_loss, breakup_conflict, crisis) used to decide whether to surface crisis-resource cards in the app. This tag is never displayed to you as a label, never triggers external alerts, never notifies staff, and never restricts your access to the app.
- Consent history. A timestamped log of every consent action you take (Terms acceptance, Privacy Policy acceptance, Washington MHMDA acknowledgment, marketing opt-in, consent revocations, data export requests). Includes a hashed version of your IP address (not the raw IP), your user-agent, and the version of the policy in effect at the time.
- Usage telemetry. Sign-in timestamps, entry counts, streak length, feature adoption events. Used to compute your streak and to inform product improvements. We do not read your entry content to inform product decisions.
- Payment information. Payment is processed by Stripe and managed by RevenueCat. Knoweth does not store your full card number. Stripe stores your payment method and provides Knoweth with a token, receipt data, and your billing name and address.
- Communications with Knoweth. Support messages, feedback submitted through the app, and emails sent to hello@knoweth.app are retained so we can respond and resolve inquiries.
- Email delivery log. Which transactional and promotional emails were sent to you and their delivery status. Retained for 90 days rolling.
Sensitive categories
Because Knoweth is used for personal reflection, some of the content you write may reasonably be characterized as consumer health data under the Washington My Health My Data Act, or sensitive personal information under California and other US state privacy laws, or special category data under the EU/UK GDPR. We handle this content with the additional protections those laws require, including obtaining your affirmative consent before AI processing and never selling this data. See "Your rights and choices" below.
Why we collect it
- To provide the service. Storing your entries, moods, goals, and preferences so you can access them across sessions and devices.
- To generate personalized AI reflections. Your entries and voice transcripts are sent to Anthropic (for Claude language models) and Deepgram (for voice transcription) to generate reflective responses, insights, lens reflections, and process plans. Neither vendor uses your content to train their models. See "Sub-processors" below.
- To secure your account. Password security, session management, and fraud prevention.
- To communicate with you. Transactional emails (welcome, weekly recap, subscription confirmations, milestone messages, cap-reset reminders, inactivity re-engagement). Optional promotional emails only if you opt in.
- To improve Knoweth. Aggregated, anonymized analytics on feature usage. We do not read your journal entries for product decisions.
- Legal and safety obligations. Detecting abuse, responding to legal requests, and complying with tax and financial-records laws.
Sub-processors
Knoweth uses the following third-party services to deliver the product. Each is bound by a Data Processing Agreement with Knoweth and maintains independent security standards.
- Supabase (Supabase, Inc., US). Database, authentication, file storage, and edge-function hosting. Data is hosted on Amazon Web Services infrastructure in the United States. Supabase does not access your content.
- Anthropic (Anthropic PBC, US). AI reflection generation via the Claude API. Anthropic does not train its models on your content under their standard commercial API terms. API request content may be retained by Anthropic for up to 30 days for abuse-monitoring purposes and is then deleted.
- Deepgram (Deepgram, Inc., US). Voice-to-text transcription for the voice journaling feature. Audio is transcribed and not retained afterward.
- Resend (Resend, Inc., US). Transactional and marketing email delivery. Also handles the authentication emails sent by Supabase Auth (password resets, email verification).
- Stripe (Stripe, Inc., US). Payment processing. Card details are handled by Stripe on their hosted checkout, not by Knoweth. Stripe is PCI DSS Level 1 certified.
- RevenueCat (RevenueCat, Inc., US). Subscription-state management across web and future mobile apps.
- Sentry (planned). Error tracking. When added, we will configure Sentry to scrub personal information from error events. This Privacy Policy will be updated and you will be re-prompted for consent.
- PostHog (planned). Product analytics for feature-usage events. When added, we will configure PostHog with pseudonymous user IDs and disable session recording. This Privacy Policy will be updated and you will be re-prompted for consent.
We may add or change sub-processors from time to time. Material changes will bump the version of this Privacy Policy and trigger a re-consent prompt on your next authenticated visit to the app. A current list of sub-processors is always available on this page.
How long we keep your data
- While your account is active: we retain your content and account data.
- After you request account deletion: your account enters a 30-day soft-delete grace period. You can restore your account by signing in during that window. After 30 days, your entries, moods, goals, contacts, and other content are permanently deleted from active systems.
- Backups: encrypted backups may contain your data for up to 90 days after hard deletion for disaster recovery. These backups are not accessed in day-to-day operations and are rolled off on that schedule.
- Voice audio: never persisted. Audio is processed only during the transcription request; only the transcript is retained.
- Payment and subscription records: retained for the period required by tax and financial regulations (typically 7 years in the US) even after account deletion. This is a legal requirement.
- Consent audit log: retained for the life of the account, then deleted with the account, subject to the backup retention above.
- Server logs on the marketing site: 30 days rolling.
- Email delivery log: 90 days rolling.
Your rights and choices
You have the following rights over your personal information. Most can be exercised directly in the app under Account → Privacy. For anything not available in-app, contact us at hello@knoweth.app.
- Access. Download a complete archive of your data from Account → Privacy → Download my data.
- Delete. Delete your account from Account → Delete Account. Content follows the deletion timeline described above.
- Correct. Edit any entry, mood, goal, or profile field directly in the app.
- Port. The Download my data archive is provided in machine-readable JSON so you can move your data to another service.
- Revoke consent. Withdraw consent for AI processing of your entries from Account → Privacy → Revoke consent. Future entries will not be sent to Anthropic or Deepgram after revocation. Existing entries remain available to you and are not deleted.
- Restrict processing. Same mechanism as revoking consent above.
- Opt out of promotional emails. Use the unsubscribe link in any promotional email, or manage preferences in Account → Notifications. Transactional emails cannot be turned off while your account is active.
- Non-discrimination. Exercising any of these rights will not affect the quality of the service you receive. Your free-tier features remain free; your Pro subscription remains active until you cancel.
California residents (CCPA / CPRA)
If you reside in California, you have the additional right to know what personal information we have collected about you, to know whether we have disclosed it to any third parties (we disclose to sub-processors only, as listed above), to request deletion, to correct inaccurate information, to limit the use and disclosure of sensitive personal information, and to not be discriminated against for exercising these rights.
Knoweth does not sell or share personal information for cross-context behavioral advertising as those terms are defined by the CCPA and CPRA. To exercise your rights, contact hello@knoweth.app or use the in-app Privacy tools.
California Civil Code §1789.3 notice. California users are entitled to the following consumer rights notice: the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs may be contacted in writing at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210. Knoweth may be contacted at hello@knoweth.app or at 110 16th Street, Suite 1460, Denver, CO 80202.
Washington residents (My Health My Data Act)
The Washington My Health My Data Act (WMHMDA) applies to consumer health data, which includes journaling and mood-tracking content used to understand your mental state. Under this law you have the right to confirm whether we are processing your consumer health data, to access it, to delete it, and to withdraw the consent you gave at signup.
Withdraw consent from Account → Privacy → Revoke consent, or by contacting hello@knoweth.app. Knoweth does not sell consumer health data. Knoweth does not use geofencing around healthcare facilities. Knoweth does not share consumer health data with advertising networks.
European Union and European Economic Area residents (GDPR)
If you are in the EU or EEA, our lawful bases for processing your personal data are:
- Consent: for AI processing of your entries, for marketing communications, and for the special-category (health-related) content some of your writing may contain.
- Contract: to provide the paid subscription service you signed up for.
- Legitimate interests: for fraud prevention, service security, transactional communications, and product improvement.
- Legal obligation: for tax records, breach notifications, and complying with law-enforcement requests.
You have the additional rights to object to processing based on our legitimate interests, to restrict processing, to data portability, and to lodge a complaint with your national data protection authority. To exercise any of these rights or request immediate hard-deletion (bypassing the 30-day grace period), contact hello@knoweth.app.
United Kingdom residents
The UK Data Protection Act 2018 and UK GDPR grant rights substantially similar to the EU GDPR above. Complaints may be raised with the UK Information Commissioner's Office (ICO).
Other US state residents
Residents of Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Delaware, Nebraska, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, and Rhode Island have similar rights under their state privacy laws. To exercise them, contact hello@knoweth.app or use the in-app Privacy tools.
Security
We use industry-standard measures to protect your data:
- Encryption in transit: TLS 1.2 or higher on all connections between your device and our servers, and between our servers and every sub-processor.
- Encryption at rest: AES-256 encryption on database storage, object storage, and backups, provided by our managed hosting infrastructure.
- Passwords stored as salted hashes, never in plain text.
- Row-level database security so authenticated users can only access their own records.
- Multi-factor authentication available on your account.
- Payment card data is handled entirely by Stripe (PCI DSS Level 1 certified) and never stored on our systems.
- Signed Data Processing Agreements with every sub-processor.
- Documented incident-response procedures and cyber-liability insurance.
Despite our best efforts, no security system is unbreakable. If we discover a data breach affecting your personal information, we will notify affected users within the timeframes required by applicable law.
How AI processes your content
Knoweth uses artificial intelligence to generate the personalized reflections, prompts, and insights that make the product work. This section explains, in plain terms, how AI touches your content and what we do to keep that safe.
Which AI systems we use
- Anthropic Claude (via the Claude API from Anthropic PBC) for reflection prompts, journey follow-up questions, insights, lens reflections, milestone messages, process plans, generated summaries, and the internal safety classifier described elsewhere in this policy.
- Deepgram (via the Deepgram streaming API) for voice-to-text transcription of your voice journal recordings (Pro).
Both are US-based commercial API providers. We use their standard commercial API terms.
What we send to them
- Excerpts from your journal entries and mood data go to Anthropic's Claude API when a reflection, insight, prompt, or process plan is being generated.
- Voice audio streams to Deepgram only during the transcription request; the audio is not persisted server-side afterward.
- We do not send your name, email, or account identifiers to either vendor. Content is sent under a per-request context, not as part of a personal profile.
What they do (and do not do) with your content
- Neither vendor uses your content to train their models under their standard commercial API terms.
- Anthropic may retain API request content for up to 30 days for abuse-monitoring purposes and then deletes it, unless a zero-retention agreement is in place.
- Deepgram does not persist audio server-side after transcription completes.
What Knoweth does NOT do with AI
We want to be explicit about the boundaries:
- No automated decisions with legal or similarly significant effect on you. The AI does not restrict your access to the app, does not trigger external alerts to third parties, does not notify staff, does not report you to authorities, does not modify your account tier, and does not decide any question about your account for you.
- No human review of your entries in normal operations. Knoweth staff do not read your journal entries. Access to production data is restricted to specific technical-support scenarios that require your explicit request or a valid legal order.
- No employment, hiring, credit, legal, or medical decisions. The AI is not used to make decisions about you in any of these categories, and its output should never be treated as advice in these areas.
- No advertising personalization. We do not use AI outputs to target ads or share AI-generated inferences with advertisers.
- No sale of AI inferences. We do not sell or share the reflections, insights, or patterns the AI generates about you.
- No cross-user profiling. The AI generates content for you based on your own entries; it does not compare you against other users or build a shared behavioral profile.
The internal safety classifier
Knoweth uses a small internal classifier (also AI-based, running on Anthropic Claude) to tag each entry with a safety indicator (safe, grief_loss, breakup_conflict, or crisis). This tag decides whether to surface crisis-resource cards in the app. It is never displayed to you as a label, never triggers external alerts, never notifies staff, and never restricts your access to the app.
AI-generated content: limitations you should understand
AI-generated content can be inaccurate, incomplete, or inappropriate for your specific situation. It may:
- Reflect biases present in the training data used to build the underlying language models
- Miss context, tone, or nuance that a human would catch
- Sound confident while being factually wrong (commonly called "hallucinations")
- Generate different responses to the same prompt at different times
- Fail to understand cultural, spiritual, or personal context that matters to you
You use AI-generated content at your own discretion. It is not medical, legal, financial, or professional advice. If you are making significant decisions, please consult qualified professionals. See our Terms and Conditions for the full "AI-generated content" clause.
Your control over AI
- Revoke consent to AI processing at any time from Account → Privacy → Revoke consent. Future entries will not be sent to Anthropic or Deepgram after revocation. Existing content remains available to you.
- Delete AI-generated content with the entry it relates to. When you delete an entry, associated reflections, insights, and lens outputs are deleted with it.
- Skip AI features entirely by using Knoweth's non-AI features (basic journal entries, mood tracking, goals, contacts) without ever triggering the AI-processing paths.
International data transfers
Knoweth's servers and all current sub-processors are located in the United States. If you are outside the US, your data will be transferred to the US for processing. For EU and EEA users, we rely on the Standard Contractual Clauses adopted by the European Commission. For UK users, we rely on the UK Addendum to those clauses.
Age restriction (18 and older only)
Knoweth is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. Our signup flow includes an age gate that requires users to certify they are 18 or older. If we learn that we have collected personal information from a person under 18, we will terminate that account and delete the associated data. If you believe we have collected information from a person under 18, contact hello@knoweth.app.
Do Not Track and Global Privacy Control
Knoweth does not currently respond to Do Not Track browser signals because the standard is inconsistent and not widely enforced. We honor the Global Privacy Control (GPC) signal where required by state law. If your browser sends a GPC signal, we treat it as an opt-out request for any future sale or sharing of your personal information (we do not sell or share today, so this is a forward-looking commitment).
Changes to this policy
We update this Privacy Policy from time to time. When material changes occur, we will: update the version number and the Last Updated date at the top; trigger a re-consent prompt in the app on your next authenticated visit; and, for major changes, send you an email notification at least 30 days before the change takes effect, unless the change is required by law and must take effect immediately. Continuing to use Knoweth after a change constitutes acceptance of the updated policy.
Contact us
Questions, concerns, complaints, or requests should be directed to hello@knoweth.app.
If you reside in the EU or EEA, you may also raise your concern with your national data protection authority. If you reside in the UK, you may raise your concern with the Information Commissioner's Office.
Governing law and jurisdiction
This Privacy Policy is governed by the laws of Colorado without regard to conflict-of-laws principles. Any legal action arising from this Privacy Policy will be brought in the courts of Colorado, subject to the arbitration provision in our Terms and Conditions.