Privacy Policy
Effective August 8, 2026
1. The short version
Knocklet is run by Solutas Labs, LLC, an Ohio limited liability company. For everything the service handles, we decide what is kept and why, and we answer for it; the law calls that the controller, or in California the business. We keep as little as we can: an email address for each owner, a hash wherever a secret would otherwise sit, and thirty days of presses. Card numbers never touch us; Stripe holds them. There are no ads and no third-party trackers, and nothing is sold or shared for marketing.
2. If you own rooms
- Account. Your email address and, if you set one, a display name.
- Sign-in. There are no passwords. A six-digit code goes to your email; we store a salted hash of it, briefly, and a hash of each session token. Web sessions last thirty days, iOS sessions ninety.
- Push. If you install the iOS app, a device token, so Apple can carry a ring to your phone.
- Text messages. Only if you add one: your own phone number, so rings can reach you by text.
- Billing. If you subscribe, Stripe takes the payment and keeps the card. What we hold is the plan you’re on, the state of the subscription, and Stripe’s identifiers for it.
- Activity. Your rooms, and thirty days of what happened in them: presses, answers, and the trail the console shows.
3. If you pressed a button
No account, no name, no email. The room page sets one cookie, a random token tying your browser to that room, so your press and its answer can find you again. If you type a message with a press, the room’s owner sees it. If the owner sends a reply, what you see is text they picked from a fixed set. Our host keeps IP addresses in ordinary server logs and rate-limit counters; those logs live at Cloudflare, age out under its own retention schedule, and are never copied into our database.
4. Writing to us
The way to reach us is plain email, hello@knocklet.com. What you send sits in that mailbox, at the provider that carries it, and nothing from it is copied into our database.
5. Who handles it
- Cloudflare hosts the service, its database, and its logs.
- Resend sends the sign-in code email.
- Apple carries push notifications to the owner app.
- Stripe takes subscription payments and holds the card details.
- Twilio carries text messages, only for owners who set them up.
As of the effective date those are all of them, along with whichever mail provider carries the hello@ mailbox. All of them process data in the United States, so using Knocklet from elsewhere sends your data here. We may disclose data if the law requires it, and account data would transfer with the business if the business were ever sold.
6. How long
Presses, the room activity trail, and idle presser sessions are removed after thirty days by a nightly job. Owner accounts stay while they’re in use, and billing records stay as long as tax law makes them. You can delete your account yourself in the console, or write to hello@knocklet.com and we will do it; either way the account’s data goes with it.
7. Cookies
Two of ours: the owner console’s sign-in cookie, which lasts thirty days, and the presser page’s room token, which lasts twelve hours. Cloudflare serves every page, and may set a cookie or run a script of its own from our domain to filter bots and absorb attacks. Nothing on either side is for advertising, and every font, script and image a page asks for comes from knocklet.com.
8. Your rights
Depending on where you live, the law may let you see, correct, take a copy of, or remove personal data, opt out of its sale, of its sharing for targeted advertising, and of profiling, limit what happens to sensitive data, and not be treated worse for asking. Some of those we can answer here for everyone: we sell nothing, we share nothing for cross-context behavioral advertising as the CCPA defines that term, we profile no one, and we keep no sensitive data to limit.
The rest we honor the same way everywhere: email hello@knocklet.com from your account’s address, which is also how we verify it’s you, and the answer comes within forty-five days. An authorized agent may write in your place, and we’ll confirm with you before acting. If we turn a request down, the reply says why, and answering it with the word “appeal” starts one: a fresh look, decided within forty-five days, and if it still goes against you the reply points to your state attorney general. A presser has no account to verify against, and nothing we hold about a press names a person, which is the point.
9. Security
A secret is stored as a salted hash wherever one would otherwise sit: sign-in codes, session tokens, room tokens. Traffic is encrypted in transit everywhere, data rests encrypted at Cloudflare, and production access is limited to the people who run the service. Behind this page sits a written security program aligned to the NIST Cybersecurity Framework, reviewed yearly.
10. Children
Knocklet is not directed to children under thirteen, and we don’t knowingly keep a child’s personal information. Tell us if you believe we have some and we will remove it.
11. Changes and contact
The date at the top moves when this policy changes, and a material change reaches owners by email first. Questions go to hello@knocklet.com, Solutas Labs, LLC.