1. Scope
This policy applies to the Knovox web app, API Worker, compute service, and related transactional emails. Third-party sites, hosted payment pages, and model providers are governed by their own policies.
2. Data we process
To provide the service, the system may process these categories:
- Account data: name, email, authentication methods, and session device information.
- User content: uploaded audio and video, YouTube source URLs, transcripts, summaries, edits, and legacy follow-up records created before that feature was retired.
- Service data: job state, processing duration, usage, error codes, request IDs, pseudonymous rate-limit keys, and allowlisted product events that exclude titles, transcript text, email, and URL query parameters.
- Billing data: local subscription projection, plan, and provider customer identifiers; the payment provider hosts complete card details.
3. Purposes and legal basis
Data is used to create and protect accounts, complete transcription jobs, generate requested AI results, enforce quotas and subscriptions, send transactional email, prevent abuse, diagnose failures, and meet legal obligations. Processing is based on providing the requested service, protecting the service and its users, complying with law, or consent where required.
4. Media and AI processing
Media is written to private object storage and processed by an isolated compute plane and configured model providers. Uploaded source video is converted to a playable audio derivative for transcription. Knovox does not use customer content to train its own models. Provider processing is limited to delivering the requested transcription and AI features.
5. Retention
Different data follows different lifecycles:
- Free-account transcripts, summaries, and associated playable media are deleted 15 days after processing.
- Paid-account transcripts, summaries, and playable media are retained until the user deletes the project or account.
- Sessions, verification records, and rate limits are removed according to their security lifetime or cleanup schedule.
- First-party product events are deleted with the associated account or retained only in aggregate form.
- Payment and provider records are retained as required for tax, dispute handling, and provider policies.
6. Sharing and subprocessors
Data is shared with cloud infrastructure, Cloudflare Web Analytics, email, payment, and model providers only as needed to deliver the service. Knovox does not sell personal data. Providers may process data in other regions subject to their contractual and legal safeguards.
7. Security measures
The system uses HttpOnly session cookies, exact-origin CORS, Turnstile, pseudonymous rate limiting, single-use upload tokens, HMAC job signatures, user-level ownership checks, and secret isolation. No internet service can promise absolute security; suspected risks should be reported promptly.
8. User rights and deletion
Users can access and edit some account data, delete individual transcripts, revoke device sessions, or request account deletion after canceling an active subscription. Final deletion removes Knovox-owned D1 and R2 data; records lawfully retained by third parties remain subject to their processes.
9. Contact and changes
Send privacy requests to [email protected]. Material changes should be announced in the product or by email and reflected in the date above.