1. Who we are
Knuud (“Knuud,” “we,” “us,” or “our”) is a product-operations tool that turns a product requirement document (PRD) into editable team packs (for example Support, Marketing, QA, and Engineering) and can post approved packs to connected tools.
- Legal / brand name
- Knuud
- Privacy point of contact
- Sakar Baxi
- duskiflake@gmail.com
- Phone
- +91-7878190445
- Location
- Gurugram, India
Knuud may be offered as a hosted Service and/or as open-source software you self-host. This policy primarily covers the hosted Service we operate. If you self-host Knuud, you (the organization running the instance) are typically the controller of personal data processed in that instance; see Section 15.
2. Scope
This policy applies to:
- Accounts and organizations on the hosted Service
- The Compile Console and related product pages (including landing, auth, onboarding, settings, integrations, and shared brief pages)
- Content you submit or connect (briefs/PRDs, comments, feedback, share links)
- OAuth and API connections to third-party tools
- Communications we send (invites, password reset, digests, transactional email)
- Limited operational and product analytics within your organization
It does not apply to third-party websites or services you connect (for example Notion, Google, Atlassian/Confluence/Jira, Linear, Slack, Zendesk, GitHub, HubSpot, AI providers, email delivery providers, or hosting/database providers). Those services have their own privacy policies.
3. Roles: controller vs. processor
Depending on how you use Knuud:
- Account and contact data about you as a customer (name, email, organization name) — we typically act as an independent controller.
- Customer Content you put into Knuud (PRDs, briefs, team packs, comments, integration payloads, share-link content) — we typically act as a processor on behalf of your organization (the controller), and process that content only to provide the Service under your instructions.
If you are an individual using a personal workspace with no separate company, we may act as controller for both account data and content you create.
4. Information we collect
4.1 Information you provide
Account and profile. Name; email address; password (stored only as a secure password hash — we do not store plaintext passwords); optional avatar URL; role within an organization (for example admin, PM, engineering, QA, marketing, CSM); and notification preferences (including email digest toggles).
Organization. Organization name and slug; membership and invite records (invitee email, role, invite token metadata, expiry/acceptance); and workflow configuration or custom workflow templates you save.
Customer Content. Briefs/documents and source PRD text or markdown you paste, fetch, or sync; generated team packs and related artifacts; comments, review decisions, pack feedback, activity history, and in-app notifications; shareable brief links you create (token, permission such as view/comment, optional expiry); and exception or upstream suggestions you confirm into a brief.
Support and communications. Messages you send us and content needed to respond to security, privacy, or account requests.
4.2 Information from connected third-party services
If you (or your admin) connect integrations, we may receive and store credentials and content needed to operate those connections, for example:
| Integration area | Examples of data involved |
|---|---|
| Source editors | Notion, Google Docs, Confluence — OAuth tokens, document identifiers, titles, and document content you authorize us to read or sync |
| Delivery / work trackers | Linear, Jira, Zendesk — tokens/API credentials, project/team identifiers, and issue/article content we create or update on your behalf |
| Messaging | Slack — bot tokens, channel identifiers, and messages needed for approval/notification flows |
| Engineering drift (when enabled) | GitHub — installation/app tokens, repository metadata, and pull-request/check-run related data |
| Other connectors as offered | For example HubSpot or similar, when connected by your organization |
Integration credentials for organizations and workspaces are stored encrypted at rest. You can disconnect integrations; residual copies may remain in backups for a limited period (see Section 9).
4.3 Information collected automatically
When you use the Service, we may collect:
- Session identifiers via an HttpOnly cookie (for example
knuud_session) - Approximate technical logs: IP address, user agent, timestamps, request paths, and error diagnostics
- Security signals used for rate limiting and abuse prevention (for example auth attempt throttling by IP)
- Product usage events needed to operate organization-level features (for example brief counts, generate/compile activity, pack feedback aggregates)
We do not currently rely on third-party advertising trackers or cross-site ad profiling for the core product UI. If that changes, we will update this policy and, where required, obtain consent.
4.4 Information from AI / model providers
When AI-assisted pack generation or related features are enabled, we may send relevant Customer Content (for example brief text and generation instructions) to model providers such as OpenAI and/or Google Gemini to produce or polish team packs. Those providers process data under their terms and privacy policies. Do not submit content you are not allowed to process with subprocessors.
4.5 Information we do not intentionally collect
We do not intentionally collect special-category data (for example health, biometric, or precise geolocation for tracking). Please do not upload sensitive personal data into briefs unless necessary and lawful for your use case. You are responsible for ensuring your Customer Content complies with your internal policies and applicable law.
5. How we use information
We use information to:
- Provide the Service — create accounts, authenticate sessions, manage organizations, compile briefs into team packs, post to destinations you approve, and show draft refreshes when sources change.
- Operate integrations — exchange OAuth/API credentials and content with tools you connect.
- Enable collaboration — invites, comments, reviews, notifications, share links, and organization membership.
- Improve reliability and security — debugging, monitoring, rate limiting, fraud/abuse prevention, and integrity of merge/drift checks when enabled.
- Communicate with you — transactional email (invites, password reset, digests you enable), product notices, and responses to support/privacy requests.
- Meet legal obligations — comply with law, enforce terms, and respond to lawful requests.
- Analyze product usage within your organization — aggregate metrics such as brief volume and pack feedback to help admins understand usage (not for selling personal data).
We do not sell personal information.
6. Legal bases (EEA/UK and similar)
Where GDPR/UK GDPR applies, we rely on:
- Contract — to provide the Service you request (account, compilation, posting, integrations).
- Legitimate interests — security, service improvement, limited operational analytics, and preventing abuse (balanced against your rights).
- Consent — where required (for example optional marketing email if we offer it; certain cookies if introduced; optional future style-profile training on prior work with explicit opt-in).
- Legal obligation — when we must retain or disclose information to comply with law.
9. Retention
We retain information for as long as needed to provide the Service and for legitimate business or legal purposes:
| Category | Typical retention |
|---|---|
| Account profile | While the account remains active |
| Organization content (briefs, packs, comments, activity) | While the organization/account remains active, or until deleted by an authorized user |
| Sessions | Until expiry, logout, or deletion |
| Password reset / invite tokens | Until used, expired, or invalidated |
| Encrypted integration credentials | While the integration remains connected |
| Server / security logs | A limited operational window, unless needed for incidents or legal holds |
| Backups | Rolling backups for disaster recovery, then automatically overwritten |
When you delete content or an account (or when we delete upon a verified request), we remove or de-identify data from active systems within a reasonable period, subject to backup cycles and legal retention needs.
10. Security
We implement technical and organizational measures appropriate to the risk, including password hashing; encryption of integration credentials at rest; HTTPS for hosted traffic in production; session cookies with HttpOnly / SameSite attributes; access controls scoped to organizations and roles; and rate limiting on authentication endpoints.
No method of transmission or storage is 100% secure. You are responsible for protecting account credentials, reviewing member access, and configuring integrations with least privilege.
If you believe there has been a security incident involving your Knuud account or data, contact duskiflake@gmail.com promptly.
11. International transfers
We may process and store information in India, the United States, and other countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses) for transfers from the EEA/UK/Switzerland to countries without an adequacy decision.
12. Your rights and choices
Depending on your location, you may have rights to access personal data we hold about you; correct inaccurate data; delete personal data (subject to legal exceptions); export or port certain data; restrict or object to certain processing; withdraw consent where processing is consent-based; opt out of sale/sharing for cross-context behavioral advertising (we do not sell personal information; if our practices change, we will update this policy); and lodge a complaint with your local supervisory authority.
How to exercise rights
- Use in-product settings where available (profile, notification preferences, disconnect integrations, revoke share links, delete briefs).
- Ask an organization admin to remove membership or organization-owned content where they control it.
- Email duskiflake@gmail.com from the email associated with your account, addressed to Sakar Baxi. We may need to verify identity before fulfilling requests.
California (CCPA/CPRA) summary. We collect identifiers, commercial/account information, internet activity (limited logs/usage), and Customer Content you submit. We use them for the business purposes in Section 5. We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are commonly defined. Authorized agents may submit requests subject to verification.
13. Children’s privacy
Knuud is built for workplace and product teams and is not directed to children under 16 (or the higher age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
14. Automated processing and AI
Knuud uses automated processing (including heuristics and, when configured, large language models) to classify requirement content and generate or polish team packs. These outputs are intended as drafts for human review before you post or rely on them. Important decisions about what is published to your tools remain under your control via review and approval flows.
We do not use Customer Content to train public foundation models unless a provider’s terms say otherwise for API usage, or unless we clearly disclose a separate opt-in program (for example, future organization-scoped style/voice profiles trained on chosen prior work).
15. Self-hosted and open-source deployments
Knuud is available as open-source software. If you deploy and operate your own instance:
- You determine the privacy policy presented to your users.
- You are responsible for lawful basis, retention, subprocessors you choose (database, AI keys, OAuth apps), and responding to data-subject requests.
- This hosted Privacy Policy does not automatically govern your self-hosted deployment, except to the extent you visit our public project sites or interact with us as a project maintainer or vendor.
16. Third-party links and services
The Service may link to or interoperate with third-party products. We are not responsible for their privacy practices. Review their policies before connecting accounts or sharing content.
17. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised “Last updated” date and, for material changes, provide additional notice (for example in-product or email) where required. Continued use after the effective date constitutes acceptance where permitted by law.
18. Contact us
For privacy questions, requests, or complaints:
- Company
- Knuud
- Point of contact
- Sakar Baxi
- duskiflake@gmail.com
- Phone
- +91-7878190445
- Location
- Gurugram, India
For EEA/UK users, you may also contact your local data protection authority.
Appendix A — Categories of personal data (summary)
| Category | Examples | Primary purposes |
|---|---|---|
| Identifiers | Name, email, user ID, organization ID | Account, auth, collaboration |
| Credentials | Password hash; encrypted OAuth/API secrets | Security, integrations |
| Commercial / account | Organization membership, roles, invites | Multi-user workspace |
| Customer Content | PRDs, packs, comments, feedback | Core product functionality |
| Internet / technical | IP, user agent, logs, session cookie | Security, reliability |
| Inferences / derived | Classification labels, generated packs | Draft generation (reviewable) |