Privacy Policy
Last updated: July 11, 2026
Template — this page describes what AgencyBrain actually does with data today, grounded in the real implementation, not generic boilerplate. It has not been reviewed by a lawyer and should be confirmed against your specific jurisdiction's requirements before real customers rely on it.
1. What We Collect
- Account data: name, email, hashed password, optional 2FA secret (encrypted at rest).
- Organization data: company name, billing details (handled by Stripe — we never see your full card number), team member list.
- Product data: the content, keywords, social posts, brand information, and other marketing data you or your team enter to use the Service.
- Usage & security logs: login events, API/webhook activity, AI usage/cost per request — retained as an audit trail even after other data is deleted (see §6).
- Cookies: a single session cookie for authentication, and (if you accept) an analytics cookie — see §7.
2. How We Use It
- To provide the Service — render your dashboard, run AI generation, track rankings, send scheduled reports.
- To process payments via Stripe.
- To send transactional email (invitations, password resets, usage alerts) — currently via Mailtrap in development, a production email provider in production.
- To investigate security incidents, using the security audit log.
3. AI Processing
Content you generate is sent to third-party AI providers (Anthropic, Google Gemini) to produce drafts, suggestions, and analysis. If you bring your own API key ("BYOK"), it is encrypted at rest and used only for your organization's requests — we never send your BYOK key anywhere but that provider's API. On managed-AI plans, requests are routed through our own platform key instead; either way, request content is subject to the relevant provider's own data-use policy for API traffic (as opposed to their consumer chat products).
4. Sub-Processors
| Provider | Purpose |
|---|---|
| Anthropic | AI content generation (Claude models) |
| Google (Gemini) | AI content generation, PageSpeed Insights |
| Stripe | Payment processing, subscription billing |
| SerpApi | Search rank tracking |
| Pollinations.ai | AI image generation (optional) |
| Email provider (Mailtrap in dev) | Transactional email delivery |
5. Data Security
- Passwords are hashed, never stored or logged in plain text.
- BYOK API keys and 2FA secrets/recovery codes are encrypted at rest.
- Every organization's data is isolated at the database query level — cross-tenant access is blocked by default, not opt-in.
- Optional two-factor authentication (TOTP) is available on every account, free of plan tier.
- See our Data Processing Agreement for the full technical/organizational measures list.
6. Data Retention & Your Rights
You can, at any time, from Settings → Data & Privacy:
- Export a complete copy of your organization's data as a JSON file (excluding encrypted secrets, which aren't portable data).
- Permanently delete your organization and everything in it.
A small number of records are deliberately retained after a deletion request, as audit/compliance trails rather than active product data: AI usage/cost logs, security event logs, and shared content tags. These are orphaned (disconnected from your account) rather than deleted outright — see our public engineering notes for the exact reasoning if you'd like the technical detail. Billing records (subscriptions, credit transactions) are also retained, consistent with standard financial record-keeping practice.
To request deletion of your individual user account specifically (rather than an entire organization), contact hello@getknockly.com.
7. Cookies
- Essential: a session cookie, required to keep you logged in. Cannot be disabled without breaking the Service.
- Analytics: optional, only set if you accept the cookie banner — used to understand aggregate product usage, never sold to third parties.
8. Children
The Service is not directed at anyone under 16. We do not knowingly collect data from children.
9. Changes to This Policy
Material changes will be communicated via email or an in-app notice before they take effect.
10. Contact
Privacy questions or data requests: hello@getknockly.com