Legal

Privacy Policy

Last updated: September 27, 2026

This policy explains what personal information knit.bio collects, how we use and share it, and the choices and rights you have. It covers our website, the creator dashboard, our APIs, and any mobile or desktop app or browser extension we offer now or in the future, plus the published pages we host on your behalf. We've written it to reflect how the product actually works, including the data your page visitors and customers generate.

1. Who we are & our two roles

knit.bio is operated by Akhil Jhunjhunwala, a sole proprietor based in India, trading as “knit.bio” (“we,” “us”). We may in the future assign this policy and the data it covers to an affiliate, a successor company we or a successor incorporates, or an acquirer of our business, as described in our Terms of Service; if that happens we will update this page and notify you as described in Section 20. Because of what the platform does, we handle personal data in two different capacities, and your rights depend on which applies:

  • •As a controller (data fiduciary): for the personal data of our account holders (creators). This includes your signup details, profile, billing information, and how you use the dashboard. This policy governs that data directly.
  • •As a processor (service provider): for the personal data a creator collects from their own page visitors, leads, customers, Instagram contacts, brand contacts, and broadcast recipients through knit.bio. The creator is the controller (data fiduciary) of that data; we process it on their behalf under our Terms, as described further in our Terms of Service (Data processing terms). If you interacted with someone's knit.bio page and have a request about your data, please contact that creator first. We will support them in responding, and will also respond to you directly where the law requires us to.

2. Information you give us

When you create an account or use knit.bio as a creator, you provide:

  • •Account & identity: email address, username, password, and (optionally) display name, user type, category, and phone number. Passwords are hashed by our authentication provider. We never see or store them in plain text.
  • •Profile & page content: your bio, profile photo/avatar, social links, and any text, images, files, or products you add to your page.
  • •Payment & payout details: when you subscribe to a paid plan, our billing processor (Stripe) collects your card directly. We store only limited billing metadata: a Stripe customer reference, your plan, billing period, and subscription status. If you use the store, you connect and manage your own payment accounts (Stripe, PayPal/PayPal.me, Venmo, UPI, Razorpay, or a per-product link); the credentials or handles you enter for those are encrypted at rest. We do not store full card numbers.
  • •Support & communications: the contents of messages you send us and any information you include when contacting support.

3. Information we collect automatically

When you use the dashboard and marketing site, we and our providers automatically collect:

  • •Device & log data: IP address, browser type, operating system, device type, and the actions you take in the app, used to operate, secure, and debug the Service.
  • •Product analytics: we use PostHog to understand how creators activate and use features (e.g., sign-up, page published, block added, upgrade interest) on our dashboard and marketing site only, never on your published pages. These events are tied to your account ID and plan so we can improve the product.
  • •Performance metrics: anonymous speed and performance data (via Vercel Speed Insights) to keep pages fast.
  • •Advertising conversion data: if you arrive from a Google ad, our Google Ads tag records that a signup happened so we can measure ad performance. See Section 11 for what this sets and how to opt out.

4. Information about your visitors & customers

When someone visits a published knit.bio page, interacts with it, or buys a product, we collect data on the creator's behalf so they can see how their page performs. Here, the creator is the controller and we are the processor:

  • •First-party page analytics:a pseudonymous, randomly generated visitor ID and session ID (stored in the visitor's own browser storage, not advertising cookies), the type of event (view, click, impression, submission), the referring URL, any UTM campaign tags in the link, and device type, OS, and browser inferred from the browser's user agent.
  • •Approximate location:a coarse country, region, and city derived from the visitor's IP address. We use the IP to determine this location and to rate-limit and protect the endpoint; we do not store the raw IP address in the analytics record.
  • •Lead & form submissions: if a creator adds an email capture, contact form, phone capture, or poll, we store what the visitor submits (such as email, phone, name, form answers, or poll choice) so the creator can view it in their Submissions dashboard. A creator can export their own leads (Excel/PDF) from that dashboard.
  • •Orders & purchases:when a visitor buys through a creator's page, we may record the order: buyer email, product, amount, currency, payment references, and, for a hosted digital download, a secure download token. Card details are handled directly by the creator's payment provider, not stored by us. Where a creator uses their own UPI/PayPal.me/Razorpay/direct link instead of a checkout we host, we may never see the order at all.
  • •Affiliate & short-link clicks: if a creator runs an affiliate program or short links, we record click events (referrer, approximate location, device) used to attribute a sale or payout.

5. Brand deals, broadcast & other business data

A creator's use of the Money suite, Broadcast, media kit, and claimable pages can bring in personal data about other people. As with Section 4, the creator is the controller of this data and we are the processor:

  • •Brand & deal contacts:Deal Desk stores the names, emails, and deal details of the brand contacts a creator adds, plus any attachment the creator uploads to a deal (kept in private storage). If a creator uses their <handle>@deals.knit.bio inbox, we receive that mail (routed through Cloudflare Email Routing to our systems) and file it against a deal; mail we identify as spam or unrelated marketing is dropped without being stored.
  • •Broadcast recipients: the email addresses and Instagram contacts a creator broadcasts to, and, for each send, delivery and click/open signals and whether a recipient unsubscribed. We keep a suppression list of opted-out addresses/contacts, including after other data about that person is deleted, so we can continue honoring the opt-out.
  • •Media kit & booking requests:when a brand submits a booking or contact request through a creator's media kit, we store the details they submit (name, email, and message) for the creator to review.
  • •Claimable pages: before some creators sign up, we may build a page for them using publicly available information (for example a public username, display name, and category) and store it as a pending, unpublished claim until they claim it. If a page is never claimed, we remove it on request or once we stop pursuing that hand-off; email support@knit.bio to ask us to take one down. Our legal basis for building it is our legitimate interest in offering the person a ready-made page.

6. How we use information

We use personal information to operate and improve knit.bio. Where the GDPR applies, our legal basis is shown in brackets.

  • •Provide, maintain, and secure the platform and your account (performance of a contract).
  • •Process subscriptions and payments (performance of a contract).
  • •Give creators analytics and insights about their pages, audience, and sales (legitimate interests; processing on the creator's behalf).
  • •Detect, prevent, and respond to fraud, abuse, and security incidents (legitimate interests / legal obligation).
  • •Understand usage and improve features and reliability (legitimate interests; consent where required).
  • •Send transactional and service messages (receipts, security alerts, in-app notifications, important updates) (contract); marketing only where you have opted in, with an opt-out in every message (consent).
  • •Measure the effectiveness of our own advertising (consent / legitimate interests, depending on your location), as described in Section 11.
  • •Comply with legal, tax, and accounting obligations (legal obligation).

7. How we share information

We do not sell your personal information for money.We share it with the service providers (“sub-processors”) that run the platform, with integrations you or a creator choose to connect, for advertising measurement as described in Section 11, and where required by law. This list may change as we add or replace providers; we will keep this page updated.

  • •Supabase: managed database, authentication, and file storage that host your account, page content, and uploads.
  • •Vercel: application hosting, performance insights, and IP-based geolocation used to derive approximate visitor location.
  • •Stripe: subscription billing, and checkout/payout infrastructure where you use it to sell.
  • •PostHog: product analytics about how creators use the dashboard and marketing site (US-hosted).
  • •OpenAI: AI processing for the features described in Section 10. Only the text those features need is sent, and only when the feature is on.
  • •Resend: delivery of transactional and broadcast email on a creator's behalf.
  • •Upstash (Redis): short-lived rate-limiting and caching data to keep the Service fast and to stop abuse.
  • •Cloudflare: email routing for a creator's optional @deals.knit.bio inbox.
  • •Meta (Instagram): the platform a creator connects to for the Instagram Suite, described fully in Section 9.
  • •Google (Ads): conversion measurement for our own advertising, described in Section 11.

We may also disclose information to comply with law or valid legal requests, to enforce our Terms or protect rights, property, and safety, and as part of a business transfer, assignment, or novation permitted under our Terms (such as to a successor entity or an acquirer), in which case the recipient will be bound to handle your data under a policy at least as protective as this one, and we will notify you of any material change in control of your data.

8. Integrations you connect

Creators can connect third-party tools to a page or account, for example Google Analytics (GA4), Meta/Facebook Pixel, Google Ads, Mailchimp, ConvertKit, Beehiiv, Resend, SendGrid, PayPal, Zapier, WhatsApp, and Shopify. When you enable an integration:

  • •Relevant data (such as page events, leads, or orders) may be shared with that provider, and the provider's own privacy policy governs what they do with it.
  • •Some integrations (like analytics or advertising pixels) may set their own cookies on your published page once you enable them.
  • •Any API keys, secrets, or tokens you provide are encrypted at rest and are never exposed to your page visitors or returned to the browser.
  • •You control these connections and can disconnect an integration at any time from your dashboard.

9. Instagram & Meta Platform data

Our Instagram Suite lets a creator connect their own Instagram professional account to automate DMs, moderate comments, schedule posts, and build a media kit. We access this data through Meta's Instagram API using the permissions you grant when you connect, and only to provide the features you turn on. Our use of information received from Meta's APIs follows Meta's Platform Terms and Developer Policies.

When you connect an Instagram account, we access and store:

  • •Account & access token: your Instagram-scoped user ID, username, and an access token, so we can act on your behalf. The token is encrypted at rest and never exposed to your page visitors or returned to the browser.
  • •Messages & comments: the content, sender ID, and metadata of comments and direct messages that trigger an automation you created, so we can send the automated reply, comment action, or DM funnel you configured.
  • •Moderation activity:when a comment matches a spam or moderation rule you set up, we keep a record of that comment's text, the commenter's Instagram-scoped ID and username, and which rule matched, so you can review what was actioned and reverse it if it was a mistake.
  • •Contacts: an Instagram-scoped ID for people who interact with your automations, plus any username, email, or phone they choose to share, so you can see and manage your audience.
  • •Content & insights: posts you schedule through us, and aggregate metrics (reach, impressions, engagement) used to power your dashboard, Deep Dive, Trial Bench, Post Report, and media kit.

We use this data only to provide the Instagram Suite features you enable. We do notsell it, use it for advertising, or share it with third parties except the sub-processors that run the platform (see Section 7). Content of Instagram messages sourced from Meta's API is never included in any aggregated or de-identified data we generate under Section 12.

Quoting messages on your page.Messages people send you privately are never published automatically. If you choose to add one to your Testimonials block or media kit, we ask you to confirm you have the sender's permission, and it is credited generically (“Instagram follower”) rather than by their Instagram handle. Public comments are not quoted on your page.

How long we keep it. Raw incoming Instagram events are deleted after 30 days. The text of sent direct messages is removed after 90 days, and the recipient's Instagram-scoped id on that record (and on link-click records) is blanked after 400 days. After 180 days we remove the text and names from moderation records and inbox conversations/transcripts (except a conversation a Deal Desk deal still points at, which stays until you delete the deal). A harvested testimonial or FAQ suggestion loses its quoted text and author name 30 days after you accept or dismiss it (90 days if you never act on it at all). Counts and totals derived from that activity, such as how many messages were sent, are kept. You can delete any one contact, including their email, phone, messages, and engagement history, from the Contacts page at any time.

Revoking access & deleting your data:you can disconnect at any time from Settings, remove knit.bio from your Instagram “Apps and websites” settings, or permanently erase everything we hold for the account. Erasing removes the connected account and everything tied to it, including uploaded scheduling media, raw incoming events, and the Instagram insights and post links cached on Deal Desk records (the deals themselves are yours and stay). When you remove the app, Meta notifies us and we do the same automatically. Full steps, and the status of any request, are on our Instagram data deletion page.

10. AI processing

Several features use OpenAI, the only AI provider we use today, to process text and produce a suggestion, classification, or draft. This includes, where you turn them on: AI comment and DM moderation (spam/scam screening); the Money Inbox assistant that extracts offer details (deliverables, budget, deadline) from a message; Audience Signals, which groups the questions and requests your audience keeps sending into topics; Comment Concierge's intent playbooks and FAQ answers; and similar assistive features we may add over time.

  • •Only the text a feature needs (a message, comment, or question) is sent, and only while that feature is switched on; several of these features can be turned off in Settings, after which no text is sent for that feature.
  • •We do not send usernames, Instagram IDs, or images to the AI provider for these features.
  • •Under OpenAI's API terms, data sent through the API is not used to train its models.
  • •AI output can be wrong. Spam and scam detection, offer extraction, and topic grouping are assistive, not certain, and a creator should review AI suggestions before relying on or acting on them. See Section 18 for more on automated decisions.
  • •The people who message or comment are not individually notified that this processing happens; this policy is that notice.

11. Cookies, local storage & advertising

We keep our use of browser storage and advertising tracking as minimal as we can while still measuring what matters:

  • •Essential cookies set by our authentication provider keep you securely signed in to the dashboard. The Service does not work without them.
  • •Local & session storage on published pages holds the pseudonymous, random analytics identifiers described in Section 4. These are not used for cross-site tracking. Visitors can clear them through their browser settings.
  • •Product-analytics storage (PostHog) on our dashboard and marketing site uses cookies/local storage to recognize you across sessions there; it is never loaded on a published creator page.
  • •Google Ads conversion cookies.Our marketing site, signup flow, and dashboard (but not published creator pages) load the Google Ads tag so we can measure whether an ad led to a signup. This sets Google cookies and, depending on how your regulator defines the term, may count as “sharing” your device/browsing signal with Google for advertising measurement purposes. We do not use it to build ad profiles about your published page's visitors. You can opt out through Google Ad Settings, your browser's cookie or tracking-protection controls, or by emailing support@knit.bio.
  • •Third-party cookies may also be set when a creator has connected their own analytics or advertising pixel to their page (Section 8). Those are governed by the relevant provider and the creator's configuration, not by us.
  • •Do Not Track / Global Privacy Control. Some browsers send a “Do Not Track” or Global Privacy Control (GPC) signal. We do not currently detect or act on these signals; if that changes we will update this section.

12. Aggregated & de-identified data

We may create and use aggregated or de-identified statistics derived from use of the Service (for example, typical conversion rates across templates, or feature adoption trends) for any purpose, including improving the product and our own marketing. This output does not identify you, your business, or any individual, and never includes the content of Instagram messages sourced from Meta's API.

13. International data transfers

We are based in India, and some of our providers (including Stripe, PostHog, OpenAI, Resend, Upstash, and Vercel) operate in the United States and other countries, so your information may be processed outside your home country, including in the United States and India, where data-protection laws may differ from where you live. Where the GDPR or UK GDPR requires it, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, for transfers out of the EU/UK. Where India's Digital Personal Data Protection Act, 2023 restricts a transfer to a particular country, we follow that restriction.

14. Data retention

We keep personal information only as long as we need it for the purposes above. As a general schedule:

  • •Account & profile data: for as long as your account is active. See Section 15 for what happens after you delete it.
  • •Page content & blocks: for as long as your account and page exist, or until you delete them.
  • •Leads & submissions: for as long as your account is active or until you delete them from Submissions.
  • •Page analytics events: for as long as your account is active or until you delete them; we may aggregate or roll up older raw events over time.
  • •Your knit.bio subscription & store-order records: your billing reference with our payment processor and records of orders placed through your store are retained as required by Indian tax and accounting law, currently up to 8 years, even after account deletion (Section 15). This does not include invoices you generate to brands through the Money suite — see the Deal Desk records row below.
  • •Instagram data: raw events 30 days; sent-message text 90 days (recipient id blanked at 400 days); link-click recipient id 400 days; moderation-log text/identity 180 days; inbox conversations/transcripts 180 days (except a conversation attached to an open Deal Desk deal); harvested testimonial/FAQ text 30 days after resolution or 90 days if never resolved. See Section 9 for detail.
  • •Deal Desk records: kept until you delete the deal or your account; attachment files are deleted or anonymized on the same schedule as other account data (Section 15).
  • •Broadcast suppression lists: kept indefinitely, even after other data about that person is deleted, so that we and the creator continue honoring the opt-out.
  • •Security & server logs: kept for a short period (typically weeks, not years) to investigate abuse and incidents, then deleted or aggregated.
  • •Backups: roll off on our normal backup cycle, generally within 90 days of the underlying data being deleted.
  • •Claimable-page snapshots: unclaimed pages are deleted on request, or when we stop pursuing that hand-off.
  • •Inactive accounts: we may treat a free account with no sign-in or material activity for 12 months or more as inactive, and remove it after notice, as described in our Terms.

15. Account deletion

You can permanently delete your account from your account settings at any time. Deleting your account removes your authentication record and, through database-level cascades, your profile, pages, page blocks, and subscription records.

  • •Deleting your account also cancels any Stripe subscription tied to it immediately, and removes files you uploaded to your profile, pages, store, QR codes, and Instagram scheduling from our storage, and any deal attachments in your account, on a best-effort basis at the time of deletion.
  • •We aim to delete or irreversibly anonymize the remaining personal data tied to your account within 90 days of deletion, except where we must keep something for a legal obligation described below.
  • •What we keep, and why: before your account's billing and order records are deleted, we copy them into a separate internal archive kept only for tax/accounting law (Section 14) — it is not part of your live account and is not visible in any dashboard; records we reasonably need to defend against or pursue a legal claim, investigate fraud or abuse, or comply with a legal hold; aggregated or de-identified statistics that no longer identify you (Section 12); and, for anyone your account previously messaged, the opt-out record on a broadcast suppression list so that opt-out keeps being honored.
  • •Backups containing your data roll off on our normal cycle, within about 90 days, as described in Section 14.
  • •Instagram data connected to your account is deleted as part of account deletion, and separately whenever you disconnect and erase it, or Meta notifies us that you removed the app; see Section 9 and our Instagram data deletion page, which this policy is consistent with.
  • •Before deleting your account, use the “Export Data” button in Settings to download a copy of your profile, pages, and content blocks; once deletion completes, we cannot recover it.

16. Security & breach notification

We apply technical and organizational measures designed to protect personal information, including:

  • •Encryption of data in transit (TLS) and at rest.
  • •Row-Level Security that isolates each account's data so creators can only access their own records.
  • •Integration secrets, payment credentials, and Instagram tokens encrypted at rest with dedicated keys.
  • •Private storage for paid digital products and deal attachments, delivered only through short-lived, single-purpose signed links after a verified purchase or to the account that owns them.
  • •Access controls, authentication, rate limiting, and PCI-DSS-compliant payment handling through Stripe.

No system is perfectly secure, so we cannot guarantee absolute security, but we work to protect your information and to respond quickly to any incident. If we become aware of a data breach that affects your personal information, we will notify you and any regulator, without undue delay, to the extent required by applicable law, including notifying the Indian Computer Emergency Response Team (CERT-In) within 6 hours of becoming aware of a reportable cybersecurity incident where that requirement applies to us.

17. Your privacy rights

Your rights depend on where you live. We honor the applicable rights below for account-holder data; for data where a creator is the controller (Section 1), contact that creator first.

India — Digital Personal Data Protection Act, 2023 & Rules, 2025

You have the right to a summary of the personal data we hold about you and how we process it; to correction, completion, and updating of that data; to erasure once it is no longer needed for the purpose it was collected for; to grievance redressal through us first; to nominate another individual to exercise your rights in the event of death or incapacity; and to withdraw consent at any time as easily as you gave it. If you are not satisfied with how we handle your grievance, you may complain to the Data Protection Board of India after exhausting our grievance process.

EU/UK — GDPR & UK GDPR

You have the right to access, correct, delete, restrict, or object to processing of your personal data (including processing based on legitimate interests), to data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority.

California & other US states — CCPA/CPRA and similar laws

You have the right to know the categories and specific pieces of personal information we collect, the sources, and the purposes; to delete it; to correct it; to opt out of “sale” or “sharing”; to limit use of sensitive personal information; and to not be discriminated against for exercising these rights. We do not sell your personal information for money. We do not knowingly share personal information from your published page's visitors for cross-context behavioral advertising. Our own Google Ads conversion tag (Section 11), used on our marketing/dashboard site (not your page), may itself constitute “sharing” under the CPRA's broad definition; you can opt out of it as described in Section 11, and doing so does not affect any other part of the Service. An authorized agent may submit a request on your behalf with proof of authorization; we may need to verify your identity before completing a request, using information you already have on your account.

Other jurisdictions

If your local law gives you a similar right not listed above, we will honor it to the extent it applies to us.

How to exercise these rights. Manage much of your data directly in your account settings, or email support@knit.bio. We may ask you to verify your identity (for example by confirming the email on your account) before acting on a request. We aim to respond within 30 days, or sooner where law requires, and may extend that period where applicable law allows, in which case we will tell you why. We will never discriminate against you for exercising a privacy right.

Grievance Officer (India). Akhil Jhunjhunwala, support@knit.bio.

18. Automated decisions

Some features use automated processing, including the AI features in Section 10 and rule-based spam and moderation filters. These are designed to assist a creator, not to make a decision with a legal or similarly significant effect on you on their own: a creator can review, override, or reverse an automated moderation action, AI reply, or offer extraction. We do not use automated profiling to make decisions about your access to the Service without human review being available.

19. Children

knit.bio is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us information, contact us and we will delete it.

20. Changes & contact

We may update this policy as the product and the law evolve. For a material change, we'll update the “Last updated” date above and notify you by email or an in-app notice with reasonable advance notice where practicable. Your continued use of knit.bio after a change takes effect means you accept the revised policy.

Questions, requests, or concerns about your privacy? Reach our team, or our Grievance Officer, at:

support@knit.bio

Create your page