Legal
We built Knot to bring people together offline — not to harvest your data. This policy explains plainly what we collect, why, and how you stay in control.
Knot is operated by Meenakshi Sharma (operating as Knot: Tied Together), based in Singapore. When this policy says "Knot", "we", "us", or "our", it refers to Meenakshi Sharma.
Knot is subject to Singapore's Personal Data Protection Act 2012 (PDPA), administered by the Personal Data Protection Commission (PDPC). We have designated a Data Protection Officer (DPO) responsible for our compliance with the PDPA. You can reach the DPO at joinknot.app@gmail.com.
We collect only what we need to make Knot work:
We do not collect advertising IDs or national identification numbers (NRIC/FIN), and we do not build advertising profiles or sell your data. Knot does not process payments — any transactions between users happen directly between them, by their own means, and we don't collect or store payment or card details.
If you give us personal data about another person (for example, when reporting a user or sharing contact information), you confirm you have their consent or are otherwise authorised under the PDPA to share it with us.
Your data is used to:
We never sell your personal data or use it for third-party advertising. We won't use your data for any purpose beyond this policy without telling you and, where the PDPA requires it, getting your consent. We take reasonable steps to keep the data we hold accurate, especially before using it to make a decision that affects you.
Under the PDPA, consent is our main basis for handling your personal data. By creating an account and using Knot, you consent to the collection and use of your data as described in this policy.
In some cases the PDPA lets us handle data without separate consent, including:
You can withdraw consent at any time by emailing joinknot.app@gmail.com. Withdrawing may affect your ability to use parts of Knot — we'll explain the likely consequences when you ask.
We share data only in these limited cases:
Some of these providers store data on servers outside Singapore (for example, Supabase servers located in Japan). When data is transferred overseas, we make sure it stays protected to a standard comparable to the PDPA, through contractual data processing agreements and the providers' own compliance commitments.
You can delete your account at any time directly in the app, under Profile → Settings → Delete Account.
When you delete your account, we delete or anonymise your personal data within 30 days — except where we're required to keep certain records by law (for any investigation, or to meet a legal obligation). We otherwise keep personal data only for as long as needed to provide Knot or to meet a legal obligation.
You have the right to:
To exercise any of these, email joinknot.app@gmail.com from your registered account email with a description of your request. We may verify your identity first, and we'll aim to respond within 5 business days, and in any case within 30 days. If we're legally allowed to decline a request, we'll explain why. Please also keep your own information up to date via Profile → Settings.
Knot uses only minimal, essential cookies — for authentication and security. We do not use advertising cookies or third-party tracking pixels in the app or on our website.
Knot is intended for users aged 17 and above, because it includes in-person meetups and user-generated content. We do not knowingly collect personal data from anyone under 17, and if we learn that we have, we'll delete it promptly.
Users who are 17 (and so under 18) should use Knot only with the consent of a parent or legal guardian, who is responsible for supervising their use and ensuring they understand this policy. We write this policy in plain language so younger users can understand it.
Knot lets users post content, message each other, and meet in person. To keep the community safe, the app includes tools to report content or users, block abusive users, and filter objectionable content. We review reports and act on them, which may include removing content or suspending accounts.
To report a safety concern or abuse, use the in-app report tools or email us at joinknot.app@gmail.com. Always take sensible precautions when meeting people in person.
We use industry-standard security measures, including encryption in transit (TLS) and at rest. No system is ever completely secure, but we work to protect your data. If you find a security vulnerability, please report it to joinknot.app@gmail.com.
If a data breach occurs that is notifiable under the PDPA, we'll notify the PDPC no later than 3 calendar days after assessing that the breach is notifiable, and we'll notify affected users as soon as practicable where required.
Knot may contain links to third-party websites or services (for example, resources shared by users). We don't control these and aren't responsible for their content or privacy practices. Review their privacy policies before sharing personal data with them.
We may update this policy as Knot grows. When we make significant changes, we'll notify you through the app or by email. The "last updated" date at the top reflects the current version.
Questions or concerns about your personal data? Contact our designated Data Protection Officer (DPO):
Data Protection Officer (DPO)
Meenakshi Sharma (operating as Knot: Tied Together)
Singapore
joinknot.app@gmail.com
Monitored during Singapore business hours (SGT, UTC+8).
We aim to respond to all enquiries within 5 business days, and in any case within 30 days. If you're not satisfied with our response, you can lodge a complaint directly with the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.