Privacy policy
This policy covers CoKnow, a Slack app that answers "what would it take to get this approved?" from a company's own past approvals, and this website. It says what we collect, where it is processed, how long we keep it, and how to have it deleted.
What we collect
From people who book an intro. If you book an intro, Calendly collects your name, work email, company, role, and the tools your team uses, along with the time you choose. This website sets no cookies and runs no analytics or third-party scripts; one small script on the home page runs the interactive examples in your browser and sends nothing anywhere. Its fonts are served from this website, so loading a page makes no request to a third-party font service.
From customers. When a company installs CoKnow, it reads only the sources the company adds to its allowlist:
- messages and threads in the Slack channels on the allowlist, including past messages, and basic profile data (name and user id) of the people who wrote them;
- Confluence pages in the allowlisted spaces, read through one read-only Atlassian connection that a person at the company approves; CoKnow checks every page against the allowlist and reads no other space;
- Google Docs, Sheets and Slides in the folders shared with CoKnow, including meeting transcripts the team already records there;
- an ask log: for each question asked, the asker's Slack user id, the question, the ids of the items used and withheld, and the answer returned. The ask log is kept 90 days.
CoKnow does not join meetings or record audio. It shows each person evidence only from sources they can already read.
How we use it
Customer content is used only to answer that customer's own questions. We never train a model on customer data, and we never use one customer's data to benefit another customer. Booking details are used only to contact you about CoKnow.
Where it is processed
Customer data is stored and processed on Railway (region us-east4-eqdc4a, US East), each customer in its own service and its own storage volume, encrypted at rest by the platform. This website is served by Vercel, which hosts this website only and holds no customer data.
| Subprocessor | Purpose | Data |
|---|---|---|
| Railway | Hosting, storage volume, volume backups, service variables holding credentials (region us-east4-eqdc4a, US East) | Customer content, ask log, credentials |
| Vercel | Serves this website only | Visitor request logs; no customer data |
| OpenRouter | Routes model requests to the model hosts below; does not store prompts or responses | Text passed to the model for one request |
| Model hosts (below) | Run the language and embedding models | Text passed to the model for one request |
| Calendly | Intro call scheduling only, under Calendly's own privacy policy | Booking details you enter; no customer data |
Model hosts
Every model request is sent through OpenRouter with zero-data-retention routing: providers that store or train on inputs are excluded, and a request that cannot be served under those rules fails rather than falling back. Language model requests may be served only by these hosts:
| Host | Routing id |
|---|---|
| Google Cloud Vertex AI | google-vertex |
| Amazon Bedrock | amazon-bedrock |
| DeepInfra | deepinfra |
| Together AI | together |
| Fireworks AI | fireworks |
Embeddings (the search index) are computed by OpenAI's embedding model, served by OpenAI or Microsoft Azure under the same zero-data-retention routing.
Retention and deletion
- The ask log is purged after 90 days.
- Content removed from the allowlist is deleted from CoKnow's store; it persists in backups for at most 14 days, after which the backups expire.
- On request, we delete everything held for a customer workspace: its store, ask log, backups and credentials. The deletion is checked by a written test that confirms nothing remains.
- Booking details are deleted on request.
Your rights
You can ask what we hold about you, ask us to correct it, or ask us to delete it. For customer content, the company that installed CoKnow controls what CoKnow reads; we will also act on requests from that company's administrators. Depending on where you live, you may have further rights under laws such as the GDPR or the CCPA, and you may complain to your data protection authority.
Changes
If this policy changes, we will update the effective date above and tell customers before the change applies to their data.
Contact
Email michaelhhuang@gmail.com.