Security
Data privacy
What each part of Knwlge collects, what it never does, how long it keeps things, and what you can change. For the legal terms, see the Privacy Policy.
In short
- Knwlge Global knows who you are and how your servers are doing — accounts, memberships, health and counts. It never sees your code or your conversations with your agents.
- Your content stays on your Enterprise Server, in your database and your storage, in your cloud.
- Your organization decides what sessions are captured — everything redacted, metadata only, or nothing — and every developer can opt out.
- We do not sell personal data or use it for advertising.
What Knwlge Global collects
| What | Why | Kept |
|---|---|---|
| Your account: email, name, the organization name you typed, your plan, when you accepted the terms, your approval status; your password as a salted hash, or the Microsoft or GitHub account you sign in with and the address it verified | To sign you in and decide on access | While the account exists, and a limited time after for security and legal purposes |
| Sign-ins: times, session ids, your browser's user agent; the devices holding a developer token, and how each signed in | To keep your account secure, and so you can revoke a device | Sessions expire after 12 hours of inactivity; tokens when they expire or are revoked |
| Organizations, teams, projects and who belongs to them, with roles; pending invites (as a hash) | To decide who may use which server | Until changed or removed |
| Each enrolled server's status reports: version, uptime, readiness checks, database and storage health and size, the storage bucket's name, allowed clients and sign-in methods, how many people were active, and counts of prompts, briefs and tokens | The project's health view, update notices and usage charts | 30 days |
| Daily usage totals per organization, from each server | Licences, seats and usage charts | Kept — counts only, no content |
| The CLI's usage reports: install id, CLI version, OS, device name, the counts of requests, briefs and memory writes per project and AI client — and the network address the report came from | Your own Dashboard at knwlge.com, shown only to you | 30 days |
| What you send on the contact form: name, email, phone if you give it, the topic and your message | To answer you | Until we delete it; ask and we will |
| An audit log of control-plane actions: projects created, keys issued, approvals, releases | Security and accountability | Kept as evidence |
What your Enterprise Server keeps
All of this is in your database and your storage; Knwlge the company cannot read it.
| What | Notes |
|---|---|
| The index of the repositories you select | Chunks of source, pull requests, issues and wiki pages; embeddings; the knowledge catalog. Removed with the repository. |
| Knowledge and memories | With who wrote each and its versions. Personal memories are private to their owner. |
| Captured sessions | As the capture policy allows: in full, prompts and what happened in each session, redacted; in metadata_only, paths, tool names and exit statuses; in off, nothing. For Claude Code, tokens used per turn and model — counts only. |
| Briefs and their receipts | What was served and withheld, for explaining a brief; visible for 24 hours. |
| Connected CLIs | Per sign-in: the device name, OS, CLI version, a random install id, AI client and last seen; tool-call counts per day. Never content. |
| The audit log | Admin actions and prompt views — never the prompt text or an admin's search terms. |
| Credentials | Provider keys and integration secrets, encrypted; only the last four characters in the clear. |
What stays on the developer's machine
- Your sessions for each project, in the operating system's keychain.
- The activity log behind the control panel, in
~/.team-context-gateway/activity/: 30 days, readable by you only. It keeps what each call was about — a brief's first titles, a memory's title, a search's words — and only its counts are ever sent, to Knwlge Global, for your Dashboard. - The upkeep log and the last brief's summary — counts, repository names, times and outcomes, never content.
- Backups of the files
installchanged, souninstallcan restore them.
What is never collected
By Knwlge Global, from any part of the product:
- Source code, or the names of repositories, branches or files.
- Prompts, answers, transcripts, context cards, knowledge, memories, documents or guardrails.
- Provider API keys, integration credentials, database connection strings or passwords.
- The names of the people using your server — only how many there are.
And a developer who opts out, or an organization whose policy is off, has no sessions on the server at all: the server refuses to store them, whatever a sidecar sends.
knwlge.com
The site and the Knwlge app use Google Analytics to understand how they are used: the pages you open, how you arrived, your browser and device, and the approximate location Google derives from your network address. It sets cookies to tell one visit from another. Pages whose address carries an invitation, or a sign-in request for your own server, are never measured. The documentation, including this page, is a public site like the rest.
Retention and deletion
| Data | How long | How it goes |
|---|---|---|
| Developer tokens | An hour; renewed for up to 30 days | Log out, revoke a device in the Knwlge app, or an admin disconnects it |
| Status reports and CLI usage reports | 30 days | Deleted automatically |
| The control panel's activity log | 30 days | Deleted automatically, on the machine |
| Captured sessions on your server | Your server's retention | The retention purge removes old session digests; offboarding someone removes all of theirs |
| Personal memories on your server | 365 days by default | The retention purge, when turned on; offboarding removes them at once |
| Your server's audit log | 365 days by default | The audit retention job, when turned on |
| Your Knwlge account | Until you ask us to delete it | Write to privacy@replient.com |
Retention on your server is set with KNWLGE_MEMORY_RETENTION_DAYS_PERSONAL, KNWLGE_AUDIT_RETENTION_DAYS and the purge schedules (Configuration reference).
Your controls
| Who | Can |
|---|---|
| An organization | Set the capture policy and how personal data in it is handled; choose which repositories are indexed, which AI clients may be used and which sign-in methods and email domains are accepted; keep LLM assistance off (the default) or pick the provider; set retention; export the audit log (Settings). |
| A developer | Opt out of capture on My memory; read, edit and archive their own memories; see and revoke their devices under Account → Devices in the Knwlge app; turn off the learning nudge and upkeep for a sidecar; uninstall at any time (Turning it off). |
| Anyone | Ask what we hold about them, or ask us to delete it, at privacy@replient.com. |
