Legal

Privacy policy

Knode records where people are working. That is genuinely personal information, so this page sets out exactly what we hold, who can see it, and how to get it back or deleted.

Last updated 9 September 2026 Applies to Knode and knode.space

In plain language. This policy describes how Knode actually behaves, not how a template says it might. It has not been reviewed by a lawyer — if Knode grows past a small free tool, that is worth doing.

1. The short version

Knode holds your name, your work email, the workspace you belong to, and the availability you record — the dates you are working, at home, on leave or not scheduled. That is close to all of it.

We do not sell it, we do not use it for advertising, we do not build a profile of you, and we do not track how long you spend working. The people who can see your availability are the other members of your workspace, because that is the entire point of the product.

2. What Knode holds

WhatWhere it comes from
Name and email addressYou, or whoever invited you to the workspace
Workspace membershipCreated when you join a team
Availability recordsYou, when you mark a day as available, working from home, on leave, a half day or not a working day
Account credentialsYou, at sign-up. Passwords are stored hashed, never in readable form
Slack identifiersOnly if someone connects Slack — see section 5
Basic technical logsYour browser, for security and debugging: IP address, browser type, timestamps

Knode does not ask for and has no use for your home address, date of birth, government identifiers, salary, emergency contacts, or the reason behind any leave you record. If you type a reason into a note field, that is your choice — the product does not require it.

3. Why we hold it

  • To run the product. Showing your team who is available is the service you signed up for. Without the availability records there is nothing to show.
  • To keep accounts secure. Credentials and technical logs let us verify it is really you and investigate abuse.
  • To answer you. If you email us, we keep the thread so we can follow up.

Where the law requires a legal basis for processing, we rely on:

  • Performing our agreement with you — there is no way to show your team who is available without storing what you record.
  • Our legitimate interests in keeping the service secure, working, and free of abuse.
  • Your consent, where you give it — for example when someone connects Slack.

In India this sits under the Digital Personal Data Protection Act 2023. If you are in the EEA or the UK, the equivalent bases under the GDPR are Articles 6(1)(b), 6(1)(f) and 6(1)(a).

4. Who can see your availability

Other members of your workspace. That is the design. When you mark Thursday as working from home, everyone in your team can see it, because a shared view that only some people can read would not solve the problem.

Members of one workspace cannot see another workspace’s data. Whoever administers your workspace can manage members and see the same availability everyone else does.

We do not share your data with anyone outside your workspace, except the service providers in section 6 who help us run Knode, and where the law compels us to.

5. If you connect Slack

Connecting Slack is optional and off until someone turns it on. When it is connected, Knode exchanges the minimum needed to keep availability in step across the two:

  • Your Slack workspace and user identifiers, so Knode knows which Slack account maps to which Knode member.
  • Messages in the channels the app has been added to, read for availability such as “wfh tomorrow” so it can offer to record it.
  • Your Slack status, if you have asked Knode to reflect your availability there.

Knode does not read direct messages, does not archive channel history, and does not store message content beyond what is needed to record the availability it found. Disconnecting Slack stops all of it; availability already recorded in Knode stays until you delete it.

6. Where it is stored

Knode runs on third-party infrastructure. These are the only companies that handle your data on our behalf:

ProviderWhat it handles
SupabaseThe database and sign-in — members, workspaces and every availability record. Supabase is a US company; the database runs in the region selected for the project.
NetlifyHosting for this site and the app, and submissions sent through the contact form. Netlify is a US company.
GoogleReceives the email you send us, including contact form notifications, at a Gmail address.

Each processes data only on our instructions under its own published data processing terms. We use no advertising network, no analytics product and no profiling service of any kind.

Where your data physically sits. Because these providers are US companies, your data may be stored or processed outside India, and outside the European Economic Area. Where that happens we rely on the standard contractual clauses and data processing agreements those providers publish. If your organisation needs data to stay in a particular region, write to us before you create a workspace and we will tell you honestly whether we can meet that.

7. How long we keep it

  • Availability records stay for as long as your workspace is active, so the team can look back at patterns.
  • Your account is kept until you or an administrator deletes it.
  • Technical logs are kept for 30 days for security and debugging, then discarded.
  • Deleted workspaces and accounts are removed from live systems straight away, and age out of backups within 30 days.

8. Your rights over your data

Depending on where you live you may have the right to ask for a copy of your data, correct it, delete it, restrict or object to how it is used, or take it elsewhere in a portable format. You can exercise any of these by writing to sudhanshu.ux@gmail.com.

Most of it you can do yourself: edit or clear your availability from the calendar at any time, and correct your name and email in settings. Ask us and we will handle the rest.

If you think we have got this wrong you can complain to a regulator. In India that is the Data Protection Board of India under the Digital Personal Data Protection Act 2023. In the EEA or the UK, complain to your local supervisory authority.

9. Cookies and local storage

This marketing site sets no tracking cookies and runs no analytics or advertising scripts. The only third party it contacts is Google Fonts, to load the typefaces.

The Knode app itself stores what is needed to keep you signed in and to remember small preferences such as light or dark mode. Those are functional, not advertising, and they never leave your browser except as part of signing in.

10. Age

Knode is a workplace tool and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has an account, write to us and we will remove it.

11. Changes to this policy

If this policy changes we will update the date at the top of the page. If a change materially affects what we do with your data we will tell workspace administrators before it takes effect, rather than quietly editing the page.

12. Contact

Knode is built and operated by Sudhanshu Kadu, an individual based in Mumbai, India. There is no company behind it and no team — one person reads what you send.

For anything on this page, write to sudhanshu.ux@gmail.com or use the contact form.