Know / Privacy
Privacy,
plainly.
Know Wallet helps you manage an identity, devices, organization access, and approval requests. This policy explains the information the app and this website handle and the choices available to you.
Who is responsible
Know is a product of Nerdstradamus Solutions Private Limited. In this policy, “we” means that company. An organization using Know may also provide and control its employee directory and access information. Questions about that organization's records may need to be handled with its administrator.
For privacy requests, email contact@knowlayer.com.
What we collect and why
- Account and identity: email address, email verification and account identifiers, public keys, device registration details, and authentication records. We use these to create and recover your identity, verify requests, and protect your account.
- Organization information: information supplied by your organization, such as your name, role, team, group, and access assignments. We use it to show the right organization context and make access decisions.
- Activity: approval requests and decisions, sign-in and device activity, organization events, security and audit records. We use these to deliver the service, enforce access, investigate problems, and maintain accountability.
- Notifications: a device push token and platform type for push registration. We use them to send request and event alerts; device notification permission controls whether alerts are displayed.
- Support: the email address and details you include when you contact us. We use them to answer you and resolve the issue.
QR scanning uses your camera to read a code for sign-in or pairing. Biometric checks use your device's operating system; the app does not receive your fingerprint or face template. Recovery material and private keys are kept in device storage, including secure storage where used. Do not send a recovery phrase to support.
Where it is stored
Some information remains on your device, including wallet keys, recovery material, and app preferences. Account, organization, device, access, event, and audit records are processed by Know's backend and stored in cloud databases, object storage, and backups. The backend uses PostgreSQL and S3-compatible object storage. A copy of organization information may also be held by the organization that supplied it. Push tokens and delivery data are processed through Firebase Cloud Messaging; Apple Push Notification service participates in delivery on iOS. Support messages stay in our email system.
The recovery phrase is not sent to Know's backend as a phrase. Losing access to the device or phrase can affect recovery.
Who receives it
We share data with the organization whose account you use, according to its administrator permissions and the access workflow you participate in. We use infrastructure and service providers to run the backend, store data and backups, deliver email, and send push notifications. These include Google Firebase for push delivery and Apple's push service on iOS. We disclose information when required by law or to protect the service and its users. We do not sell personal data.
Information you choose to approve or share with a connected organization or application may be received by that party under its own privacy practices.
How long it is kept
We keep account and organization records while the account or organization needs the service. Temporary verification data expires after its purpose is complete. When a valid deletion request is fulfilled, we remove or de-identify data from active systems where possible. Copies in backups remain until those backups rotate out. Security and audit records, including cryptographic commitments to past access decisions, may be retained after account closure where required for security, legal obligations, or dispute resolution. Support correspondence is kept while needed to resolve the request and for any applicable recordkeeping obligation.
There is no single retention period for every record. If you ask us to delete your data, we will tell you what can be removed, what must remain, and the applicable retention basis.
Access or delete your data
Email contact@knowlayer.com with the subject “Know data access request” or “Know data deletion request.” Include the email address associated with your Know account and the organization name, if applicable. We may verify your identity before acting. You can also ask to correct information or revoke a device. Your organization administrator may need to approve changes to organization-managed records.
Uninstalling the app does not by itself delete server records, and device secure storage may persist according to operating-system behavior. To request account and server-data deletion, use the email process above. We will explain any records we cannot erase and why.
Website analytics
knowlayer.com uses Umami to measure page visits and site performance. The website does not use analytics cookies. Umami processes visit information such as pages viewed, referral and device/browser details to produce aggregate reports. This website does not use Umami data to make wallet access decisions.
Questions?
Write to contact@knowlayer.com or visit our contact page. We may update this policy as the product changes. The date above shows when this version took effect.
