Privacy approach
Private project data, handled with explicit boundaries.
Knoy works with environmental project material that can carry commercial, personal, cultural and regulatory sensitivity. This page explains the product and operating approach reflected in the current codebase, together with the arrangements that still need to be confirmed before sensitive use.
This is a public working draft, not a final privacy policy. Before uploading restricted, government-sensitive or confidential personal information, confirm the agreed hosting, model route, retention and processor arrangements with Knoy.
Information Knoy may handle
The application may handle:
- Account details, project membership and named reviewer roles.
- Project documents, submissions, correspondence and field material.
- Extracted text, evidence excerpts, citations, requirements and findings.
- Draft reports, review decisions, commitments and exported outputs.
- Project activity records, support requests and service diagnostics.
Customers and users must only upload material they are authorised to process.
Project access and boundaries
The current application implements project membership roles—owner, editor and reviewer—and database row-level policies for project records. Application actions also perform project-role checks. These controls do not, by themselves, establish a universal hosting or tenant-isolation promise: the deployed environment and agreed customer arrangement still need to be confirmed.
AI processing and model routes
AI-assisted tasks can be configured to use a Vercel AI Gateway route or direct OpenAI or Anthropic routes. The selected provider, model, processing location, retention position and training terms depend on deployment configuration and the provider agreement in effect at that time. A fixed Australian processing route is not guaranteed by the public codebase.
Structured-generation requests limit the number and length of evidence excerpts supplied to a model. Knoy is working toward clearer user-visible disclosure of the material prepared for a task and the route used to process it.
Human-controlled outputs
AI-assisted material remains draft material. Environmental obligations, citations, conclusions and exported outputs require professional interpretation, verification and approval before use or submission. Knoy is not intended to make final planning, legal, cultural heritage, ecological or regulatory decisions.
Activity, retention and deletion
The codebase records project audit events and preserves source identifiers used by several workflows. This should not yet be interpreted as a complete, customer-facing audit log or guaranteed export history.
Project deletion is supported. A complete public account-level retention schedule, backup-deletion commitment and set of self-service controls has not yet been finalised. Confirm deletion scope and timing with Knoy for production or procurement use.
Cross-border processing and service providers
Project data may be processed outside Australia when the selected hosting, model or support route uses an overseas provider or region. Knoy will need to document the applicable subprocessors, regions and contractual safeguards for each agreed deployment.
Questions and requests
Contact support@knoy.app for privacy questions or to request access, correction or deletion. The scope of rights, response periods and data ownership position must be confirmed in counsel-approved privacy and customer terms.