Legal
Privacy Policy
How we collect, use, and protect your information. Last updated June 23, 2026.
1. Overview
This Privacy Policy explains how Headknot ("we", "us") collects, uses, and shares information when you use our websites, applications, and related services (collectively, the "Service").
By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
2. Information We Collect
Account information you provide, such as your name, email address, and workspace details.
Content and data you connect, upload, or generate through the Service, including data from the third-party sources you choose to connect.
Usage and device information collected automatically, such as log data, IP address, browser type, and how you interact with the Service.
3. How We Use Information
To provide, maintain, and improve the Service, including building and querying your knowledge graph.
To secure the Service, prevent abuse, and troubleshoot issues.
To communicate with you about your account, updates, and support requests.
4. AI Providers & Your Content
Headknot uses a third-party AI provider to make your content answerable. Today that provider is OpenAI. Content from the sources you connect is sent to OpenAI’s API when we generate embeddings for search, extract the people, projects and claims inside your content, resolve different names for the same thing, detect conflicting statements, and answer your questions.
OpenAI states that data sent to its API is not used to train or improve OpenAI models unless the customer explicitly opts in. We have not opted in.
OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring, unless longer retention is required by law. Zero Data Retention, which would exclude your content from those logs, requires prior approval from OpenAI. We do not hold it and we are not currently seeking it, so the 30-day window above applies to your content today. We would rather state that than let you assume a stricter control than we have.
We do not use your content to train any model of our own, and we do not sell it.
Marking a source, document or item sensitive hides it from workspace members without access and excludes it from every answer. It does not retroactively unsend content already processed at ingestion. If material must never reach an AI provider at all, do not connect the source that contains it.
During ingestion we scan documents for credentials and secrets, and a document that trips the scanner is not sent to the AI provider. Treat this as a safety net rather than a guarantee: if the scan fails, ingestion continues rather than stopping.
5. Connected Sources & Integrations
When you connect a third-party source (for example, Google Drive, Notion, or Slack), we access only the data needed to provide the Service, and only with the scopes you authorize.
You can disconnect a source at any time. Disconnecting stops further syncing; previously indexed data is removed according to our retention practices.
7. Data Retention
We retain personal information for as long as your account is active or as needed to provide the Service. When you delete content or your account, we delete or de-identify the associated data after a reasonable retention period, unless we are required to keep it by law.
8. Security
We use technical and organizational measures designed to protect your information, including access controls and role-based permissions. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Your Rights & Choices
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing.
To exercise these rights, contact us at support@headknot.com. You can also manage much of your data directly within the Service.
11. International Transfers
We may process and store information in countries other than where you live. Where required, we use appropriate safeguards to protect information transferred across borders.
12. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us information, please contact us so we can remove it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service or by other reasonable means. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
14. Contact Us
Questions about this Privacy Policy? Reach us at support@headknot.com.