Privacy Policy
Archived version. This version applied from October 2, 2026 until it was replaced on October 3, 2026. The current version is at gnok.com/legal/privacy.
Version la-2026-10-01 · Effective October 2, 2026 · Replaced October 3, 2026
This policy explains how Gnok, Inc. ("Gnok", "we") collects and uses personal information when you use the Gnok data platform: Gnok Studio, the Gnok sign-in, catalog and SQL services, and the websites gnok.com and docs.gnok.com (the earlier gnok.io addresses redirect there). Gnok Mail (gnokmail.com) is covered by its own privacy policy.
Gnok is in Limited Availability. Please don't store personal, confidential or regulated data in it.
What we collect
- Account information: your name, email address, username, password (stored only as a one-way hash), and second-factor settings such as passkeys or an authenticator app.
- Organization information: your organization's name, its members and their roles, and its settings.
- Sign-up and sign-in information: when you sign up or sign in, the time, the result, your IP address and your browser's user agent. If your organization uses single sign-on, we receive the name and email your identity provider sends.
- Usage information: the queries you run and their metadata (time, duration, rows, errors), resource usage against your plan, and AI and embedding token usage.
- Your content: the tables, files, models, notebooks, worksheets and dashboards you create. We process it only to provide the Service to you.
- Messages: what you send to support@gnok.com or security@gnok.com.
Why we use it
- To provide the Service: sign you in, run your queries, store your data, and apply your organization's access rules and plan limits.
- To keep the Service secure: detect abuse, throttle and lock repeated failed sign-ins, check new sign-ups, and investigate incidents.
- To run the preview: review new organizations, contact you about your account, planned maintenance or deletion, and answer your messages.
- To understand how the preview is used so we can improve Gnok. We do this from our own service records; we don't use third-party analytics or advertising trackers.
We do not sell your personal information, and we don't share it for advertising.
Who processes it for us
| Provider | What for | What they receive |
|---|---|---|
| Amazon Web Services | Hosting (compute, databases, storage) in the US (us-east-1), content delivery for gnok.com and docs.gnok.com, email delivery (SES), web firewall | All data described in this policy |
| Anthropic | Language models for AI features, when your organization uses them | Prompts and the data they reference |
| OpenAI | Embeddings for search and AI features, when your organization uses them | Text sent for embedding |
AI features are off until your organization is granted an AI budget and an administrator enables them. When they run, the prompt and the data it references are sent to the provider above under its API terms. Under their current API terms, neither provider uses data sent through its API to train its models, and each may keep it for up to 30 days to monitor for abuse before deleting it.
We may also disclose information if the law requires it, to protect the rights, safety or security of users or the Service, or as part of a merger or acquisition, in which case this policy continues to apply.
Cookies and browser storage
We use only cookies that the Service needs to work: there are no advertising or analytics cookies. Gnok Studio also keeps your sign-in state and interface preferences in your browser's local storage. The gnok.com and docs.gnok.com websites set no cookies.
| Cookie | Where | Purpose |
|---|---|---|
__gnok_session | Gnok Studio | Keeps you signed in to Studio. |
__gnok_csrf | Gnok Studio | Protects your Studio session against cross-site request forgery. |
__gnok_oidc | Gnok Studio | Carries the sign-in request while you sign in. |
gnok_catalog_auth | Sign-in page | Keeps a sign-in in progress across its steps. |
gnok_catalog_org | Sign-in page | Remembers which organization you sign in to. |
gnok_catalog_sso, __Host-gnok_catalog_saml | Sign-in page | Single sign-on with your organization’s identity provider. |
__Host-gnok_signup | Sign-up page | Lets the email verification link work in the browser you signed up in. |
gnok_admin_session | Organization administration | Keeps an administrator signed in. |
aws-waf-token | Sign-up and sign-in | Records that your browser passed our bot check (set by our web firewall). |
How long we keep it
- During the preview, data may be deleted at any time, and is deleted when the preview ends unless we tell you otherwise.
- Account, organization and content: while your organization exists. When an organization is deleted, sign-in stops at once and its data is deleted after 7 days; copies in backups and earlier file versions expire within 30 days.
- Sign-ups that are never verified are removed 7 days after the verification link expires.
- IP address and browser recorded at sign-up: up to 30 days.
- Sign-in records and query history:while your organization exists, and deleted with it.
- Service logs (which can include email addresses and the text of queries): 30 days.
- Messages to support: as long as needed to answer them and keep a record of the request.
Where it is stored
The Service runs in the United States (AWS us-east-1). If you use it from elsewhere, your information is transferred to and processed in the US. During Limited Availability the Service is intended for organizations based in the United States.
Your choices and rights
You can see and change most of your account information in Gnok Studio. To ask for a copy of your personal information, a correction, or deletion, or to object to how we use it, email support@gnok.com. We will confirm your identity and respond within 30 days. Depending on where you live, you may have further rights under local law, including the right to complain to a data-protection authority.
Security
We protect the Service with encryption in transit and at rest, per-organization isolation, a second factor for administrators, and monitoring. No system is perfectly secure. Report security issues to security@gnok.com (see our disclosure policy). If a breach affects your personal information, we will tell you as the law requires.
Children
The Service is for organizations and is not directed to children under 18. We don't knowingly collect their information.
Changes
We will post changes here with a new version number and, for significant changes, tell you by email or in the Service.
Contact
Gnok, Inc.. Email support@gnok.com.