Privacy policy
This policy explains what information the Knock app handles and how. Knock is published by Spikewave Pty Ltd (spikewave.tech).
Summary
Your data is used only to run the app’s features. It is never sold, never used for advertising and the app contains no analytics or trackers.
Information the app collects
| Data | What exactly | Why | Required |
|---|---|---|---|
| Handle and password | Your account identity and sign-in. The password is stored only as a salted hash. No phone number is requested or collected. | To create your account and sign you in. | Required |
| Email address | Used for sign-up verification, password reset, and optionally the business badge. For a verified business email only the domain is ever shown publicly — the address itself is never visible to other users. | Account verification and recovery. | Required |
| Display name and profile photo | Shown to the people you talk to. Both are optional and can be removed at any time. | So people recognise you. | Optional |
| Messages and attachments | Photos, videos, voice notes and files you choose to send. All end-to-end encrypted — the server holds them only in a form we cannot read. Message metadata (who you message, when, and from which devices) is visible to the server, as is inherent to how any messaging system delivers a message. | To deliver your conversations. | Required |
| Device keys | The cryptography behind end-to-end encryption and device verification. Private keys stay on your device; only the public halves reach our server — except for the encrypted recovery backup described below. | To make encryption and device verification work. | Required |
| Encrypted key backup | If you set up recovery, the keys to your messages are backed up to our server, encrypted with a recovery key that is created on your phone and shown only to you. The server holds the backup but not that key, so we cannot open it — and cannot recover it for you if the key is lost. | So you can read your message history on a new phone. | Optional |
| Push token | A device identifier issued by Firebase Cloud Messaging and registered with our server, so it can wake your phone when a message arrives. It is removed when you sign out or delete your account, and carries no message content. | Push notifications. | Required |
| Connection logs | IP address and timestamps, kept short-term. | Running the server, rate limiting and abuse prevention. | Required |
| Crash reports | Stack traces and your device model and OS version. Off by default — collected only if you switch on Settings → Send crash reports. | Diagnosing crashes. | Optional |
Using Knock requires an account so your data can sync to your devices.
Where it is stored
Your account lives on our own Matrix server, which runs on Hetzner Online GmbH infrastructure in the EU (Falkenstein and Helsinki). Messages are held there only as ciphertext that we cannot decrypt.
Device permissions
Knock requests the following permissions, and only for the reasons given:
- Camera — Scanning QR codes to connect with someone, and taking photos to send. Used only while you are using those features.
- Microphone — Recording voice notes. Used only while recording.
- Photos and media — Choosing images or files to send, through the system picker.
- Notifications — Message and scheduled-send notifications.
- Biometrics — The optional App Lock. This uses the standard Android prompt — your biometric data never leaves your device and we never see it.
Service providers
These third parties process data on our behalf, only to make the app work:
- Hetzner Online GmbH — Hosts our Matrix server in the EU. It holds ciphertext and metadata, never readable message content. Privacy policy
- Brevo (Sendinblue SAS) — Delivers verification and password-reset email. It processes your email address only to send those messages. Privacy policy
- Firebase Cloud Messaging — Wakes your device when a message arrives. It receives the device push token and the fact that something arrived in a given room — never message content, because the pusher is configured to send the event ID only. Privacy policy
- Firebase Crashlytics — Receives stack traces and device model only if you opt in to crash reporting. Privacy policy
Advertising and analytics
We do not share your data with advertisers and the app contains no advertising SDKs. The app contains no analytics or tracking software.
Security
All data sent between the app and our services is encrypted in transit using HTTPS/TLS.
Deleting your data
Open Settings and tap Delete account at the bottom, confirm with your device biometric or PIN, then enter your password and type DELETE. Deletion happens immediately — there is no grace period and no recovery.
You can also email knock@spikewave.tech and we will delete it for you.
Your rights
Under the Protection of Personal Information Act (POPIA) in South Africa — and under the GDPR if you are in the EU or UK — you may ask us to confirm what personal information we hold about you, correct it, or delete it. Write to knock@spikewave.tech and we will respond within 30 days.
Children
Knock is not directed at children and we do not knowingly collect information from anyone under 13 (or the relevant age of digital consent in your region).
Changes to this policy
We update this page whenever what the app collects changes, and note the revision date at the top.
Contact
Spikewave Pty Ltd
Registration number 2026/658861/07
Johannesburg, Gauteng, 2090
South Africa
knock@spikewave.tech