Knavigator MCP - Privacy Policy
Effective date: August 26, 2026
Data controller: Avvera Technologies Inc. (registered address available on request via the contact below).
Contact: support@avvera.ca
1. The short version
- Knavigator MCP reads and stores your Knack app's structure metadata only - the definitions of fields, objects, views, scenes, tasks, and emails, and how they connect.
- We cannot and do not read, request, or store the records inside your Knack apps (your customers' data, form submissions, table rows). You never give us a credential that can read records, and the only Knack endpoint we call returns structure metadata - we have no technical access to your records.
- We store only the latest structure snapshot per verified app (no history), and we delete it when you remove the app or delete your account.
- If you buy credits, Stripe handles the payment. We keep the credit ledger behind your balance, never your card details.
- We use trusted sub-processors (hosting, database, payments, email), we do not sell your data, and we do not use it for advertising or to train AI models.
2. What we collect
a. Account data. Your email address, authentication credentials (passwords are handled by our auth layer and stored hashed), and, if you buy credits, billing identifiers held by Stripe (we do not store full card numbers).
b. App registration data. The Knack App IDs you register, the app name returned by Knack, verification tokens and timestamps.
c. App structure snapshots. The latest metadata (structure) of each verified app, fetched from Knack's public API. Structure only - no records. Latest snapshot per app; no history.
d. Usage and audit data. Logs of queries (which tool, which app, timestamps, outcome), API-key metadata, rate/quota counters, and standard server logs. We use these for security, abuse prevention, billing integrity, and support.
e. Credit and billing records. Your credit balance and the ledger behind it: credit purchases, bonus credits, the free monthly credits, per-call consumption, refunds and any manual adjustment, each with a timestamp and, for a purchase, the Stripe payment reference. This is how the balance you see is proven against the money.
f. Payment data. Processed by Stripe. We receive payment confirmations and identifiers, not your card details. See Stripe's privacy policy.
g. Website analytics. Our website uses PostHog to understand page usage (pages visited, referral source, browser type). Visitors are tracked pseudonymously; we do not build identified profiles of anonymous visitors, and analytics data is never joined to your app structure data.
3. What we do NOT collect
We cannot fetch, process, or store the record data inside your Knack apps - and we do not. This is a technical impossibility, not just a policy: you never provide us a credential that can read records, and the endpoint we use returns application structure metadata only. It has no way to return record data.
4. How we use your data
To provide the service (answer structure queries), verify app ownership, keep snapshots fresh, meter and bill credit usage, secure the service and prevent abuse, provide support, and comply with law. We do not use your data to train AI models or for advertising, and we do not sell it.
5. Legal basis (EU/UK users)
Where GDPR or UK GDPR applies, we process your data on these bases: performance of a contract (providing the service you buy credits for), legitimate interests (securing the service, preventing abuse, and supporting customers), and legal obligation (for example, retaining billing records).
6. Service providers
We share data with a small number of service providers only as needed to run Knavigator MCP - hosting and serverless compute, our database, payment processing, transactional email, and website usage analytics. Each receives only the data its function requires. Payments are processed by Stripe (one-time credit-pack purchases); we never see your card details. Primary data residency is the United States. A current list of our service providers is available on request at support@avvera.ca.
7. Data retention and deletion
- Structure snapshots: latest only; deleted when you deregister the app or delete your account.
- Account data: kept while your account is active; deleted or anonymized after account deletion, except records we must keep for legal or accounting reasons.
- Credit ledger and billing records: retained as required by applicable tax and accounting law (commonly up to 7 years), so purchases and refunds stay auditable after an account closes.
- Audit and usage logs: retained up to 12 months, then deleted or anonymized.
You can delete your account from the dashboard; this cascades removal of your apps, keys, snapshots, and your credit balance (any remaining credits are forfeited - see the Terms, Section 12). The credit ledger rows behind past purchases are kept as financial records for the retention period above, so a refund or a payment dispute that arrives after the account is gone can still be settled.
8. Security
Connections are encrypted in transit (HTTPS). Access is gated by OAuth or hashed API keys, your credit balance, and per-app ownership checks, with a full audit trail. Passwords and API keys are stored only in hashed form. No system is perfectly secure; we cannot guarantee absolute security. If a data breach affects your personal data, we will notify you and any authorities as required by applicable law, without undue delay.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise them, contact us at the address above. We do not sell or share your personal data (including within the meaning of the CCPA).
10. International transfers
If we serve users in the EU/UK from US-based infrastructure, such transfers are made under an appropriate safeguard (for example, the Standard Contractual Clauses).
11. Children
Knavigator MCP is not directed to children and is intended for users 18 and older. We do not knowingly collect personal data from anyone under 18.
12. Changes
We may update this policy; we will post the new version with an updated effective date and, for material changes, notify account holders by email.
13. Contact
Privacy questions: support@avvera.ca (and business address if required in your jurisdiction).