Knocky Chat Privacy Policy

Last updated: 2026.9.18

1. About this Policy

Knocky Chat is operated by Ethereal Connect Limited ("Knocky Chat," "we," "us," or "our"). Contact us about privacy at support@knocky.ai.

This Policy explains how we handle personal information through the Knocky Chat app, and our support services (together, the "Services"). Knocky Chat offers interactive stories in Doors and individual conversations with AI characters in House.

This Policy describes our practices; it is not a request for unlimited consent. When a particular activity requires a separate notice, permission, or consent, we provide or obtain it before that activity.

2. Information We Collect

We collect information you provide, information generated when you use the Services, and information received from the providers described below. The information involved depends on the features and sign-in methods you use.

CategoryInformation and sourceWhy we need it
Account and guest informationAccount or guest identifiers, account settings, and sign-in and session records. For email sign-in, your email address and authentication records; for Google sign-in, the account identifier, email address, verification status, and basic profile information shared through the authorized sign-in flow.Sign you in, protect your account, link your activity, and preserve access to saved experiences.
Age eligibilityThe age-eligibility declaration you provide and the resulting eligibility status.Apply the adult-only access restriction.
Your content and preferencesMessages, prompts, selected replies, player personas, story preferences, and other text you enter.Generate AI conversations and stories and tailor the fictional experience.
Generated content and progressAI replies, chapter summaries, story choices and progress, character-relationship scores, and associated story state generated through your use.Continue conversations, operate chapters and game mechanics, and display your progress.
Device, usage, and diagnosticsIP address, app or installation identifiers, device and operating-system information, app version, language settings, timestamps, feature interactions, and error, crash, and performance records.Deliver and secure the Services, understand feature use, and diagnose reliability problems.
Feedback and supportFeedback, community-board submissions and participation, content reports, contact details you choose to provide, and correspondence or material you send to support.Respond to you, manage feedback, investigate reports, and resolve problems.

Google sign-in. We use the account information shared through the sign-in process to authenticate and operate your account. Signing in does not give us access to your Gmail messages, Google Drive files, or Google Calendar.

Guest access. A guest identifier can connect conversations and progress to an app installation without an email address. This does not make the associated information anonymous.

Text-based launch version. The current in-app interaction features accept text, not voice recordings, photos, or video uploads. They do not offer AI image or video generation, voice generation, text-to-speech, or speech-to-text, and do not require camera, microphone, contact-list, photo-library, or precise-location access. Material you independently send to support, such as a screenshot in an email, is treated as support information.

Sensitive information. Messages may reveal health information, beliefs, sexual orientation, or other sensitive personal circumstances. We do not need government identification numbers, payment credentials, or medical records for ordinary storytelling. Avoid entering these details or another person's private information without permission. Fictional framing does not make identifiable content anonymous or remove applicable privacy protections.

3. How We Use Information

We use the information described in Section 2 to provide accounts and guest access; generate dialogue, suggested replies, chapters, and summaries; maintain personas and story progress; and operate fictional relationship mechanics.

We also use relevant information to respond to feedback and privacy requests, investigate reported content, prevent abuse and security incidents, diagnose errors, measure service performance, and improve feature design. We may send necessary account, security, or service notices and use limited records to meet legal obligations or handle legal claims.

The model-training and human-review limits in Section 4 also apply when we improve the Services. A general reference to improvement does not authorize a different use of private conversations.

Relationship scores and story preferences are used for fictional gameplay. They are not assessments of your health, real-world worth, creditworthiness, or eligibility for employment, housing, or other essential services.

4. AI Processing, Conversation Context, and Human Review

AI service providers

When you use an AI feature, we send relevant input and context to the AI service providers identified in Annex A. Depending on the feature, this can include your current message, relevant conversation history, player persona, chapter summaries, and story or relationship state. Providers use this information to return the requested text, summary, suggested reply, score, or other AI result, and for the disclosed safety and operational purposes.

A model gateway or intermediary is included in Annex A when it receives your information. A provider listed there does not necessarily receive every category or every conversation; the feature you use determines the relevant input.

Context is different from training

We store conversations, summaries, and related state to let you revisit and continue your experience. The portion included in an individual AI request can be smaller than the history stored in your account. Excluding an older message from a model request does not delete it from our systems.

We do not use your private conversations, player personas, chapter summaries, or associated personal information to train or fine-tune AI models. We require AI providers processing that information for us not to use it for model training or fine-tuning. Generating a reply from existing context is not model training.

A no-training restriction is not a promise of zero retention. Provider-specific operational logging, retention, and deletion arrangements are described in Annex A.

Human access

Authorized personnel and service providers may review relevant content when necessary to handle a report or support request, investigate abuse or a security incident, or troubleshoot a specific service problem. Access is limited to the task and subject to access controls and confidentiality obligations.

We may also evaluate conversation excerpts that you deliberately include in feedback to understand the issue and improve prompts or feature design. We do not routinely review other private conversations for quality evaluation. Any additional use requiring a separate choice or consent will be presented separately.

5. Who Can See or Receive Information

Your private experiences. Door and House conversations, personas, and saved story progress are not made visible to other users in ordinary use. "Private" does not mean that processing stays on your device or that authorized personnel can never access the information; Section 4 explains those activities.

Public feedback. Content you choose to submit to a clearly identified public community feature may be visible to other users with the display information shown in that feature. Private support submissions are not automatically published. We do not publish your private chats for promotion merely because you use the Services.

Operational providers. In addition to the AI providers in Annex A, we use these categories of providers as needed for the Services:

Provider categoryInformation involved and purpose
Hosting, storage, and infrastructureAccount records, content, generated story data, and relevant technical records to host, store, deliver, and protect the Services.
Authentication and email deliveryAccount identifiers, email addresses, and authentication or delivery records to sign you in and deliver service communications.
Analytics and diagnosticsApp or guest identifiers, device information, feature events, and diagnostic records to measure usage and investigate reliability. Routine analytics is not intended to contain the text of private chats.
Support and security servicesRelevant reports, correspondence, contact information, and necessary content or technical records to handle requests and investigate incidents.

Providers acting on our behalf are subject to appropriate contractual restrictions on use, access, protection, and retention. We remain responsible for our own disclosure decisions; a provider's separate policy does not remove that responsibility.

Other disclosures. We may disclose limited relevant information to professional advisers under confidentiality duties; as required by law; or where lawful and reasonably necessary to address fraud, security, legal claims, or a serious safety threat. In a genuine business transfer, relevant information may pass to transaction participants or a successor subject to applicable protections. We may also disclose information at your specific direction or with any consent required for the disclosure.

6. Advertising, Tracking, and Data Sales

The launch version does not display advertising, collect advertising identifiers for advertising or attribution, or use personal information for targeted or cross-context behavioral advertising. We do not sell personal information or "share" it for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws.

Operational analytics is used for the service purposes described above, not to allow providers to build independent advertising profiles. Our informational websites do not use advertising pixels or cross-site tracking. Hosting services can still receive connection information necessary to deliver and secure a webpage.

Local storage and similar technologies used by the app maintain sessions, settings, and saved access. Removing local data can affect guest access without deleting server-side records.

We do not separately change our practices in response to a browser's Do Not Track setting. Because we do not engage in sale, advertising sharing, or targeted advertising, a Global Privacy Control signal does not need to stop those activities. Any future change involving such practices will require updated disclosures and applicable consent or opt-out controls before it begins.

7. How Long We Keep Information

We keep information only for the purposes described in this Policy and for the periods or criteria below. A valid deletion request can require earlier deletion, subject to applicable exceptions.

InformationRetention period or criterion
Account and guest records, chats, personas, summaries, and associated story stateUntil you delete the account, request deletion of the relevant information, or the information is no longer needed to provide your saved experience, whichever occurs first, subject to the limited exceptions below.
Routine usage, crash, and performance recordsUp to 90 days after collection. Records needed for a specific security investigation follow the security-record rule below.
Support, feedback excerpts, and routine safety or security investigation recordsUp to 12 months after the matter is resolved. Public feedback may remain visible until removed or you request its removal; any necessary support copy follows this rule.
Privacy-request and legally required recordsFor the period reasonably necessary to document the request, demonstrate compliance, or meet the relevant legal obligation.
BackupsRestricted backup copies expire within 90 days after the corresponding information is deleted from active systems.
AI-provider recordsThe specific retention and handling arrangements in Annex A.

We may keep limited records longer where legally required or reasonably necessary for an unresolved security issue or legal claim. We restrict those records to that purpose and delete them when the basis for retention ends.

Information that has been genuinely deidentified may be retained for statistics where lawful, with safeguards against reidentification. Removing a name or hashing an account identifier is not, by itself, enough to treat information as anonymous.

8. Deleting Your Account and Data

You can request account deletion from the account controls under Me by selecting Delete account, or email support@knocky.ai with the subject "Delete Account." You do not need to reinstall the app to use the web or email option.

The request covers the account and associated personal information, including conversations, personas, chapter summaries, story progress, relationship state, and linked identifiers. We instruct relevant providers to delete information they process for us, subject to lawful and disclosed retention exceptions.

We complete verified deletion requests from active systems without undue delay and ordinarily within 30 calendar days after receiving the request, unless applicable law requires a shorter period. Where a lawful extension is necessary, we explain it within the initial response period. We may request information reasonably needed to verify the request or locate records, and we explain any inability to complete it.

Backups follow Section 7 and may remain for up to 90 further days after active-system deletion. Pending expiry, they are restricted from ordinary use. When a backup is restored, applicable deletion requests are reapplied. We explain relevant retention exceptions unless prohibited by law.

Guest users may use the same contact routes and provide an available guest or app identifier. You do not have to create a registered account just to submit a privacy request. If a lost guest identifier prevents us from locating the records, we explain the available verification options.

Uninstalling, signing out, or unlinking Google is not a request to delete server-side information. Deleting your Knocky Chat account does not delete your separate Google account. Once deletion is completed, signing in again does not restore deleted conversations or progress.

9. Your Privacy Rights and Choices

Depending on your residence and the law that applies, you may have rights to confirm processing; access or obtain a portable copy of information; correct inaccuracies; request deletion; withdraw consent; or opt out of certain sales, sharing, targeted advertising, sensitive-information uses, or legally significant profiling. These rights are subject to applicable conditions and exceptions.

To submit a request, contact support@knocky.ai. We respond within the period required by applicable law, explain any permitted extension, and use proportionate verification where required. We do not require identity verification for an opt-out request when the law prohibits it. An authorized agent may act for you subject to lawful verification of their authority.

Where a right to appeal applies, reply to our decision at the same email address with the subject "Privacy Appeal." We review the decision and explain any available route to a regulator. We do not unlawfully discriminate against you for exercising privacy rights.

California residents. Where the California Consumer Privacy Act applies, the information described in this Policy includes identifiers, internet or electronic activity, user-submitted and generated content, inferences such as story preferences, and sensitive information in authentication records or content you provide. Sections 2–7 describe the sources, purposes, recipient categories, retention, and sale or sharing practices. These descriptions cover our practices since launch and, once we have operated for longer than a year, the preceding 12 months. Applicable rights include access, deletion, correction, non-discrimination, and relevant sale/sharing opt-outs and sensitive-information limits. We do not knowingly sell or share information about anyone under 16.

You may edit available persona or account settings in the app. Removing a device permission or changing a local setting does not necessarily delete information already collected; use the request routes above for that purpose.

10. Security and International Processing

We use reasonable safeguards appropriate to the information and risk, including encrypted transmission and restricted access. No system is completely secure. We do not promise that unauthorized access can never occur or describe server-processed conversations as inaccessible to all authorized personnel.

The AI-provider data storage regions are listed in Annex A.

Processing outside your country can involve different privacy and government-access rules. We use safeguards required by applicable law. Accepting this Policy does not waive your rights or replace a legally required transfer mechanism.

11. Adults-Only Service

Knocky Chat is for people aged 18 or older who meet the eligibility requirements in our Terms of Use. We do not knowingly permit under-18 use or knowingly collect information from children under 13.

If we learn that an ineligible minor is using the Services, we restrict access and take appropriate steps to delete the associated personal information, subject to lawful safety or recordkeeping requirements. A parent, guardian, or other person with a concern may contact support@knocky.ai. Parental permission is not an exception to the adult-only rule.

12. External Services and Changes

External services, including an optional Discord community, have their own policies for your interactions on those services. Our disclosures of information to third parties remain subject to this Policy and applicable law.

We update this Policy and Annex A when our relevant practices change. We revise the update date, provide notice of material changes, and obtain additional consent where required. Publishing a revised policy does not authorize otherwise unlawful processing or retroactively remove your rights.

For privacy questions or complaints, contact Ethereal Connect Limited at support@knocky.ai.


Annex A — Third-Party AI Service Providers

The following table identifies the third-party AI service providers used for Knocky Chat’s text-based features. Text and context may include your messages, relevant conversation history, player personas, chapter summaries, and story or relationship state. Only the information relevant to the feature is sent; each provider does not necessarily receive every category or every conversation. Text generation includes dialogue, chapters, summaries, suggested replies, and relationship scoring, as applicable to the requested feature.

Third-party AI providerAI service providedCategories of your data we sendPurpose of useData storage regionProvider’s privacy policy
Google LLCGenerative AI and large language model (LLM) servicesText information you provide and relevant conversation or story contextText generation; content-safety reviewUnited Stateshttps://policies.google.com/privacy
Amazon Web Services, Inc.Generative AI and large language model (LLM) servicesText information you provide and relevant conversation or story contextText generationUnited Stateshttps://aws.amazon.com/privacy/
xAI Corp.Generative AI and large language model (LLM) servicesText information you provide and relevant conversation or story contextText generationUnited Stateshttps://x.ai/legal/privacy-policy
OpenAI, L.L.C.Generative AI and content-safety servicesText information you provide and relevant conversation or story contextContent-safety reviewUnited Stateshttps://openai.com/policies/privacy-policy/

The no-training restriction in Section 4 applies to the providers processing private conversation information for us. Any permitted operational retention must be consistent with the handling disclosed here. We update this appendix when the actual recipients or relevant practices change; a new provider does not automatically authorize a new purpose for your information.