Legal
Privacy Policy
1. Who we are
Knownbase is operated by ZSTECHLABS, trading as “ZS Tech Labs”. This policy explains what we collect, why, and your choices. Contact us at hello@knownbase.dev.
2. Information we collect
- Account data: email address and hashed password.
- Workspace content: the notes, projects, and tags you or your agents store.
- Usage and security data: session metadata, IP address, and user agent, used for authentication, rate limiting, and audit logging.
- Billing data: our order process is conducted by Paddle.com, our online reseller and Merchant of Record for all orders; we never see or store your card details.
3. Cookies
We use one strictly-necessary cookie, knownbase_session, to keep you signed in; it carries no advertising or tracking data and is never shared with third parties. Your light/dark theme choice is stored in your browser’s local storage, not a cookie. The login, signup, and contact forms load Cloudflare Turnstile, a bot-protection widget that may set its own cookie for that purpose (see Subprocessors). We do not use advertising or cross-site tracking cookies, so no cookie-consent banner is shown.
4. How we use it
To provide and secure the Service, process payments, send transactional email (verification, password reset, invitations), and respond to support requests. We do not sell your personal data.
5. Subprocessors
We rely on infrastructure and service providers including MongoDB Atlas (database and search), Paddle (payments), Cloudflare (Turnstile bot/abuse protection on login, signup, and the contact form), and an email delivery provider. Each processes data only to provide their part of the Service.
6. Retention
We keep your data for as long as your account is active. When you delete a workspace or account, associated data is removed from our systems, subject to routine backup rotation.
7. Your rights
You can access, export, correct, or delete your data at any time from within the app. Depending on your jurisdiction you may have additional rights under laws such as the GDPR or CCPA; contact us to exercise them.
8. Security
Passwords are hashed with PBKDF2, sessions and API keys are stored hashed, transport is encrypted in production, and each workspace is strictly isolated.
9. Governing law
This policy is governed by the laws of Pakistan. If you are located in the EEA, UK, or California, the rights described above (GDPR/CCPA) apply to you regardless of this governing-law clause.
10. Changes
We may update this policy; material changes will be posted here with a new date.