KnoMe

Privacy

Effective date: 27 April 2026  ·  Last updated: 27 July 2026

What we collect, where it lives, and what we do with it. Operated by M1 Factory, Inc.

Short version

Your knowledge lives in our database under your account. We don’t read it for product purposes, we don’t train AI on it, and we don’t share it outside the subprocessors listed below. When you connect an AI assistant via MCP, it reads only what you’ve granted it access to — your credentials are never shared with the AI provider. We have operator-level access to the infrastructure we run.

Do not store Social Security numbers, government-issued ID numbers, passwords, financial account credentials, medical records, or any data governed by HIPAA, GLBA, FERPA, or equivalent laws. KnoMe is not certified or designed for regulated data.

1. Scope and definitions

Account data — your email address, optional display name, and authentication records.

Customer data — everything you add to KnoMe: rooms, categories, entries, notes, links, and files. Also includes anything an AI assistant writes on your behalf via MCP.

Personal data — information about identifiable individuals processed in connection with providing the service. M1 Factory, Inc. acts as the data controller for personal data it collects directly (account data, analytics). Where you store third-party personal data inside KnoMe, you are the controller of that data.

2. Data we collect

Account data
Your email address and optionally your first and last name. Passwords are never stored — authentication is handled by Supabase Auth (magic link or OAuth via Google or GitHub).
Customer data
Rooms, categories, entries, notes, and any files you attach or import. This data lives in our database under your user ID. We do not read, analyse, or share it.
Usage analytics and session replay
We use PostHog(PostHog Cloud, US region) to understand how features are used. This includes page views, explicitly instrumented feature interactions, and error events. We also use PostHog’s session replay feature to diagnose interface and reliability problems. Replay masks all text and inputs before data leaves your device. We identify analytics using an internal account ID and do not send your email address, name, rooms, entries, notes, or shared context to PostHog. You can opt out at any time by emailing meet@m1factory.com or by blocking us.i.posthog.com in your browser.
Request logs
Our backend logs HTTP method, path, status code, duration, and anonymised user ID. Request and response bodies are never logged. IP addresses are used only for in-process rate limiting and are not persisted to any database or log store.
Cookies and local storage
We store a Supabase session token in your browser’s local storage to keep you signed in. No advertising or tracking cookies are set. PostHog may set a session cookie scoped to our domain only for analytics continuity.

3. How we use data

  • To provide and operate the KnoMe service
  • To authenticate you and keep your session secure
  • To understand how features are used and diagnose issues (aggregate and session-level)
  • To detect and prevent abuse and rate-limit excessive API usage
  • To contact you about significant service changes (email only)
  • To meet legal obligations (tax records, court orders)

We do not sell, rent, or syndicate your data. We do not use your content to train or fine-tune any AI model.

4. Legal basis for processing (GDPR)

For users in the European Economic Area or United Kingdom, we process personal data under the following legal bases:

Processing activityLegal basis
Providing the service, authentication, account managementPerformance of contract (Article 6(1)(b))
Usage analytics and session replayLegitimate interests — improving and securing the service (Article 6(1)(f))
Responding to legal obligations, tax recordsLegal obligation (Article 6(1)(c))
Sending service communicationsPerformance of contract / legitimate interests (Article 6(1)(b)(f))

Where we rely on legitimate interests, you have the right to object (see Section 10). We have assessed that our interests do not override your fundamental rights and freedoms.

5. AI assistant access (MCP)

When you connect an AI assistant (such as Claude) to KnoMe via our MCP server, the assistant reads and writes data on your behalf using only the permissions you have granted via OAuth 2.0. Your KnoMe credentials are never shared with or seen by the AI provider.

Data returned to the AI assistant travels to that provider under their published data-handling policy. We don’t control what happens to data once it leaves our servers and enters a prompt.

6. Where data lives

DataLocation
Customer data (rooms, entries, files)Supabase (PostgreSQL) — US region, encrypted at rest
Account dataSupabase — US region, encrypted at rest
OAuth tokens (MCP)Supabase — US region, SHA-256 hashed before storage
Request logsRailway (ephemeral — not persisted beyond process lifetime)
Analytics and session replaysPostHog Cloud — US region

All primary processing occurs in the United States.

7. Subprocessors

SubprocessorPurposeWhere
SupabaseDatabase, authentication, and storageUS
RailwayBackend API and frontend hostingUS
PostHogProduct analytics and session replayUS
GoogleOAuth sign-inUS

No other third parties receive your data.

8. Data retention and deletion

DataRetention
Customer data (rooms, entries, files)Deleted immediately when you remove an item. All remaining data deleted when you delete your account.
Account dataUntil you delete your account, plus 30 days for backup rotation
Maximum-masked session replaysUp to 3 months via PostHog Cloud (depends on plan)
Request logsEphemeral — not persisted
Billing records7 years (tax law)

Account deletion is a one-way door. When you request deletion, your account, rooms, entries, and files are removed. Email meet@m1factory.com to delete your account.

9. Security (excerpt)

  • Encrypted at rest. All customer data is stored in Supabase (PostgreSQL) and encrypted at rest by the platform. OAuth tokens are SHA-256 hashed before storage — the raw token is never persisted.
  • Encrypted in transit. TLS 1.2+ is enforced on all public endpoints. HTTP connections are rejected at the edge.
  • Not end-to-end encrypted. KnoMe reads your content in cleartext so that AI assistants can retrieve it. This is intrinsic to how the product works — encryption at rest protects your data at the storage layer, but does not prevent server-side access.
  • No third-party certifications. We do not hold SOC 2, ISO 27001, or comparable certifications. See the Security page for what is in place today.

10. Your rights

Depending on your location, you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct inaccurate information
  • Deletion — ask us to delete your account and all associated personal data
  • Portability — receive your data in a machine-readable format
  • Restrict processing — ask us to limit how we use your data while a dispute is resolved
  • Object — object to processing based on legitimate interests, including session replay analytics
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing

To exercise any of these rights email meet@m1factory.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or your EU Member State’s data protection authority).

11. International data transfers

The service is operated from the United States. If you are located in the European Economic Area, United Kingdom, or Switzerland, your personal data is transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) as the transfer mechanism for EEA/UK data. A copy of the applicable SCCs is available on request at meet@m1factory.com.

12. Breach notification

We will notify affected users by email within 72 hours of confirming a data incident, with details and updates as the investigation proceeds. Where required by law, we will also notify the relevant supervisory authority.

13. Children

KnoMe is not directed at individuals under 16. We do not knowingly collect personal information from anyone under 16. Contact us immediately at meet@m1factory.com if you believe we have done so.

14. Changes to this page

Material changes will be communicated by email at least 14 days before they take effect. The date at the top of this page reflects the most recent version.

15. Contact and DPO

Privacy questions: meet@m1factory.com

No Data Protection Officer has been designated at this time. This page will be updated if one is appointed. For data protection enquiries, contact us at the email above.