Skip to content

Privacy

What we keep, and what we cannot.

This is the plain-language account of the hosted spool service: the site, the dashboard and the spools we run for you. The formal policy is linked at the end.

What this covers

The service at hosted.getknit.app: this website, the dashboard behind sign-in, and every spool we run under spool.getknit.app. Knit, the app on your phone, has its own notice at getknit.app.

What we keep about you

Three things identify you to us: the email address you sign in with, a billing reference from our payment provider, and an id for each spool you own. A workspace also has the name you gave it and the people you invited.

Beside those sit the settings you chose for each spool — its plan, whether it has a token, its proof-of-work level, whether it has a commons — and a history of the changes you made to them, so the dashboard can show you what happened and when.

  • No conversation ids reach our control plane. It never learns which conversations a spool holds.
  • No connection logs. It never learns which devices connected, or when.
  • No client addresses. Reports from the fleet carry the state of the container and nothing about who used it.

What your spool can see

Knit seals every message on the device. What arrives at a spool is a sealed frame filed under a conversation id, and that is what the spool stores and forwards: the frame, its size, when it arrived, and the ids of any attachments.

It never sees who you are, who is in a conversation, what a message says, who read it, or which other spools your devices also use. This is how knit-spool is built, and the hosted one runs the same released daemon you can read on GitHub.

Your token

The token is yours. You can read it whenever you ask, set one of your own, rotate it, or remove it and run an open spool. We store it sealed, so a copy of our database cannot reveal it, and it is never written into an email, a log line, an error message or a link.

Your commons

When you start a commons, the dashboard mints an invite and shows it once. We keep only a hash of it — enough to tell the spool which room to relay, not enough for anyone, us included, to join it. Lose the invite and you mint another; the room's name is the one thing about it we hold in the clear, because the spool shows it to devices.

Your hostname and certificate

A spool's hostname is sixteen random characters under spool.getknit.app, chosen by us and never derived from you, so it carries nothing through browser history, a referrer or a support ticket. One wildcard certificate covers the whole fleet, which means your hostname is never written into a public certificate log.

Usage figures

Every five minutes we read counters from your spool: devices connected, bytes stored, bytes sent. They draw the meters and charts on your dashboard and are kept for ninety days. They are numbers about the container, not records of anyone's use of it.

Who we work with

Running this takes a handful of providers, each holding only what its job needs.

  • Clerk — sign-in and workspaces. Holds your email address and who is in your workspace.
  • Polar — payments, as merchant of record. Holds your card and invoices; we hold a reference.
  • Resend — the emails we send you.
  • Hetzner — the servers your spool runs on, in the EU.
  • Vercel and Neon — this website, the dashboard and their database, in Frankfurt.
  • Cloudflare — DNS for getknit.app. It answers name lookups and does not sit in front of your spool.

What this website records

We count page views and measure page speed with Vercel Web Analytics and Speed Insights. Neither sets a cookie. Vercel tells one visitor from another by a hash of the request, which it discards after 24 hours, and ties nothing to an IP address. A page view is recorded with the page, the site you came from, a coarse location — country, region, city — and the browser, system and kind of device.

Before anything is sent, we strip the query string from the address, so your spool's id never travels with a page view, and the dashboard's addresses are recorded as patterns rather than the pages you actually opened. There are no tracking events and no advertising. Nothing here follows you off this site.

The email we send

We write when your spool comes up, when a payment fails, and before a cancelled spool is removed. Every message is about your account; none carries your token.

When you leave

Cancel a spool and it runs to the end of the month you paid for, then the container and its data are removed; delete it now and they are removed on the next pass. Delete your workspace and every spool in it does the same. The billing record stays for as long as invoices need it.

Questions

Write to support@getknit.app. A person reads it.

The formal documents: Terms of service · Privacy policy