Privacy policy

For the Knock app · Last updated 6 August 2026

This policy explains what information the Knock app handles and how. Knock is published by Spikewave Pty Ltd (spikewave.tech).

Summary

Your data is used only to run the app’s features. It is never sold, never used for advertising and the app contains no analytics or trackers.

Information the app collects

Data What exactly Why Required
Handle and password Your account identity and sign-in. The password is stored only as a salted hash. No phone number is requested or collected. To create your account and sign you in. Required
Email address Used for sign-up verification, password reset, and optionally the business badge. For a verified business email only the domain is ever shown publicly — the address itself is never visible to other users. Account verification and recovery. Required
Display name and profile photo Shown to the people you talk to. Both are optional and can be removed at any time. So people recognise you. Optional
Messages and attachments Photos, videos, voice notes and files you choose to send. All end-to-end encrypted — the server holds them only in a form we cannot read. Message metadata (who you message, when, and from which devices) is visible to the server, as is inherent to how any messaging system delivers a message. To deliver your conversations. Required
Device keys The cryptography behind end-to-end encryption and device verification. Private keys stay on your device; only the public halves reach our server — except for the encrypted recovery backup described below. To make encryption and device verification work. Required
Encrypted key backup If you set up recovery, the keys to your messages are backed up to our server, encrypted with a recovery key that is created on your phone and shown only to you. The server holds the backup but not that key, so we cannot open it — and cannot recover it for you if the key is lost. So you can read your message history on a new phone. Optional
Push token A device identifier issued by Firebase Cloud Messaging and registered with our server, so it can wake your phone when a message arrives. It is removed when you sign out or delete your account, and carries no message content. Push notifications. Required
Connection logs IP address and timestamps, kept short-term. Running the server, rate limiting and abuse prevention. Required
Crash reports Stack traces and your device model and OS version. Off by default — collected only if you switch on Settings → Send crash reports. Diagnosing crashes. Optional

Using Knock requires an account so your data can sync to your devices.

Where it is stored

Your account lives on our own Matrix server, which runs on Hetzner Online GmbH infrastructure in the EU (Falkenstein and Helsinki). Messages are held there only as ciphertext that we cannot decrypt.

Device permissions

Knock requests the following permissions, and only for the reasons given:

  • Camera — Scanning QR codes to connect with someone, and taking photos to send. Used only while you are using those features.
  • Microphone — Recording voice notes. Used only while recording.
  • Photos and media — Choosing images or files to send, through the system picker.
  • Notifications — Message and scheduled-send notifications.
  • Biometrics — The optional App Lock. This uses the standard Android prompt — your biometric data never leaves your device and we never see it.

Service providers

These third parties process data on our behalf, only to make the app work:

  • Hetzner Online GmbH — Hosts our Matrix server in the EU. It holds ciphertext and metadata, never readable message content. Privacy policy
  • Brevo (Sendinblue SAS) — Delivers verification and password-reset email. It processes your email address only to send those messages. Privacy policy
  • Firebase Cloud Messaging — Wakes your device when a message arrives. It receives the device push token and the fact that something arrived in a given room — never message content, because the pusher is configured to send the event ID only. Privacy policy
  • Firebase Crashlytics — Receives stack traces and device model only if you opt in to crash reporting. Privacy policy

Advertising and analytics

We do not share your data with advertisers and the app contains no advertising SDKs. The app contains no analytics or tracking software.

Security

All data sent between the app and our services is encrypted in transit using HTTPS/TLS.

Deleting your data

Open Settings and tap Delete account at the bottom, confirm with your device biometric or PIN, then enter your password and type DELETE. Deletion happens immediately — there is no grace period and no recovery.

You can also email knock@spikewave.tech and we will delete it for you.

Your rights

Under the Protection of Personal Information Act (POPIA) in South Africa — and under the GDPR if you are in the EU or UK — you may ask us to confirm what personal information we hold about you, correct it, or delete it. Write to knock@spikewave.tech and we will respond within 30 days.

Children

Knock is not directed at children and we do not knowingly collect information from anyone under 13 (or the relevant age of digital consent in your region).

Changes to this policy

We update this page whenever what the app collects changes, and note the revision date at the top.

Contact

Spikewave Pty Ltd
Registration number 2026/658861/07
Johannesburg, Gauteng, 2090
South Africa
knock@spikewave.tech