Knock
Privacy Security Support EN · UK

Privacy Policy

Last updated: 2026-09-27 · Draft, pending legal review — see the placeholders in brackets below. This policy exists only in English, which is its authoritative version.

This Privacy Policy explains what information Knock ("Knock", "we", "us") processes when you use the Knock app or this website, and why. Knock is currently distributed as a private alpha through TestFlight; this policy will be revised before any public release.

1. Who operates Knock

Knock is operated by [LEGAL ENTITY / OPERATOR NAME].
Contact: [CONTACT EMAIL]
Postal address: [POSTAL ADDRESS IF REQUIRED]

2. Scope, and content vs. metadata

This policy covers the Knock mobile app and this website. Two terms recur throughout:

  • Message content is what you write, send or share inside a conversation: text, photos, videos, voice messages, files, reactions, replies, edits and deletions. Knock encrypts this end-to-end: our server stores and relays it only as ciphertext it cannot read.
  • Metadata is information Knock needs to operate the service — for example, your username, who you're talking to, when a message was sent, and delivery status. Metadata is not end-to-end encrypted, and our server does process it.

Section by section below, this policy says which category applies. See also the Security page.

3. Account information

To create an account you choose a username and password. We store your username, display name, and a salted, one-way cryptographic hash of your password (scrypt) — never the password itself. We also store which devices are signed in to your account, a generic device name and platform (e.g. "iPhone", "ios"), and when a device was last active.

4. Profile photo

Adding a profile photo is optional. Unlike message content, a profile photo is not end-to-end encrypted: it is stored as an ordinary image file our server and storage host can access, reachable only by people signed in to Knock. Removing or replacing your photo deletes the stored file.

5. Device information

Each device you sign in on gets a device identifier and publishes its public encryption keys to our server (never private keys). We store the device's platform and a generic name, not your device's actual set name.

6. Encrypted messages

Message text is end-to-end encrypted (message content, §2). Our server sees and stores: which conversation a message belongs to, its sender, its timestamp and order, its (padded) encrypted size, and delivery/read metadata — never the decrypted text.

7. Encrypted media

Photos, videos, voice messages and files are message content (§2): encrypted on your device with a random key before upload, and never readable by our server or storage host. They see only an encrypted blob, its size, its kind (photo/video/voice/file), the uploader, and timestamps.

8. Server-visible metadata

Beyond the specific sections above, our server processes, as metadata:

  • account and device identifiers, usernames, display names;
  • conversation membership (who you talk to);
  • message timestamps and delivery order;
  • delivery receipts, read positions, and typing indicators (typing is never stored, only relayed live);
  • Knock events (an ephemeral "knock" between two accounts): sender, recipient, and time, kept only briefly and never stored as a message;
  • public encryption key material for your devices;
  • connection times and IP addresses, used transiently for abuse prevention.

9. Friends and Knock Code

Knock does not access your phone's contact list. You add someone by their exact username, or by scanning their Knock Code — a QR code tied to their account that they can rotate (revoke and reissue) at any time. Resolving a Knock Code reveals only the public profile (username, display name, profile photo if any) of the account it points to.

10. Knock Code

Your Knock Code is created the first time you use it and is public by design — anyone who scans or opens it can see your public profile and start a conversation with you. You can rotate it from Settings at any time, which invalidates the old code.

11. Presence / last seen

Presence (whether you're online right now, and a minute-precision "last seen" time) is server-coordinated metadata, not end-to-end encrypted. It is visible only to people you share a conversation with, and only while you also allow them to see it (this setting is reciprocal, and defaults to visible to people you talk to). You can turn it off in Settings.

12. Read receipts

Your read position (how far you've read in a conversation) is sent to our server so your own devices and unread counts stay in sync; whether it is shared with the other participant is controlled by a reciprocal setting you can turn off in Settings.

13. Push notifications

If you enable notifications, we register an encrypted push token for your device and use it to ask Apple (APNs) or Google (FCM) to notify you. Those notifications carry only generic text (e.g. "New message"), opaque identifiers, and — only if you turn on "Show names" — the sender's first name. They never carry message content, encryption keys or ciphertext. Apple and Google process this per their own privacy terms as the notification providers.

14. IP address / network logs

Your IP address is used transiently (kept for a few minutes at most) to apply rate limits against abuse; it is not written into our persistent application logs. Your network provider, and our hosting provider's infrastructure, see connection-level metadata the way they would for any encrypted (HTTPS/WSS) connection.

15. Security and diagnostic logs

Our servers keep structured logs (timestamps, request identifiers, which endpoint was called, status codes, and error categories) to operate and debug the service. These logs do not contain message content, passwords, session tokens, encryption keys, or full request bodies.

16. Support communications

If you contact us for support, we keep that correspondence to help you and to improve Knock.

17. Diagnostics / crash data

The Knock app does not currently include any analytics or crash-reporting software of its own. While Knock is distributed through Apple TestFlight, Apple separately collects crash reports and feedback that testers choose to submit, under Apple's own terms.

18. Cookies and this website

This website (knock.cykor.net) does not set cookies and does not use analytics or advertising trackers. There is no cookie banner because there is nothing non-essential to consent to.

19. Third-party processors

The following parties process data on our behalf, or as part of delivering the service:

  • our hosting/VPS provider, which hosts our servers, database and encrypted media storage (this is where your account and message data lives — not this website);
  • a backup storage provider for encrypted database backups [BACKUP PROVIDER — CONFIRM, not yet chosen];
  • Apple (push notifications via APNs; TestFlight distribution) and Google (push notifications via FCM);
  • Expo/EAS, which builds our app from source; it does not receive user data at runtime;
  • GitHub, for source code hosting;
  • our DNS provider and Let's Encrypt, for domain resolution and TLS certificates;
  • [WEBSITE HOSTING PROVIDER — CONFIRM, e.g. Vercel], which serves this website (knock.cykor.net) only — it never receives account data, message content or metadata, since the app never communicates with this site's domain.

None of these are advertising or analytics partners, and none of them receive message content.

20. Hosting location

Our servers — the ones that hold your account, messages and encrypted media — are located in [HOSTING LOCATION / COUNTRY — CONFIRM]. This website (knock.cykor.net) may be served from a separate, geographically distributed hosting/CDN provider; see §19.

21. Backups

We back up our database, which contains the metadata described above and ciphertext we cannot read — never decrypted message content or private encryption keys. Backups are retained for [BACKUP RETENTION PERIOD — CONFIRM] and are deleted or overwritten on that schedule. Encrypted media (photos, videos, voice messages, files) is not currently backed up separately; losing the underlying storage would make previously sent media permanently unavailable, even though the surrounding conversation would not be lost.

22. Retention

[RETENTION PERIOD — CONFIRM]: as of this version of the policy, Knock does not yet automatically delete delivered messages, their metadata, or server logs after a set period. We intend to add automatic retention limits and will update this policy, and the effective date above, when we do.

23. Account deletion

In-app account deletion is not available yet. To delete your account, contact us at [SUPPORT EMAIL] with your username; because this is irreversible, we will confirm you're the account holder before proceeding. See Support for details. When we delete an account:

  • your username, password and encryption keys are removed, so no one can sign in to it or start a new encrypted session with it;
  • your profile photo is deleted;
  • messages you already sent, and that were already delivered to someone else, remain on their device — end-to-end encryption means we cannot reach into another person's device and remove what they've already received, the same way we could not read it in the first place;
  • data may remain in backups until they age out on the schedule in §21;
  • anything stored only on your own device is deleted when you delete the app, or from within it, not by us.

24. Security

Our approach to encryption and its limits are described in full on the Security page. No online service, including this one, can guarantee absolute security.

25. International data transfers

[INTERNATIONAL TRANSFERS — CONFIRM whether applicable, and the safeguards used, e.g. Standard Contractual Clauses]

26. Children's privacy

Knock is not directed at children. You must be at least [MINIMUM AGE — CONFIRM] years old to use Knock. We do not knowingly collect information from anyone younger than that; if we learn that we have, we will delete the account.

27. Your rights

Depending on where you live, you may have rights to access, correct, or delete your information, or to object to or restrict some of our processing. If you are in the EU or UK, this includes rights under the GDPR/UK GDPR: access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your local supervisory authority. To exercise any of these rights, contact us at [CONTACT EMAIL].

28. Changes to this policy

We may update this policy as Knock changes. We'll update the "Last updated" date above, and for material changes we'll tell you inside the app or by another reasonable means before they take effect.

29. Contact

[LEGAL ENTITY / OPERATOR NAME]
[CONTACT EMAIL]
[POSTAL ADDRESS IF REQUIRED]

See also: Terms of Use · Security · Support.

Privacy Terms Support Security

Knock is a project of [LEGAL ENTITY / OPERATOR NAME]. © 2026.