What this covers
This policy explains what KnownIn collects, why, and what rights you have over it. KnownIn is a portable professional profile — your skills, experience, projects, and context — that you update by chatting with it or by connecting AI tools (like Claude, ChatGPT, or Cursor) over the Model Context Protocol (MCP), and that generates AI-tailored resumes and an optional public profile card.
What we collect
Directly from you, or from an AI tool you've connected:
- Account info: email address, and authentication data if you sign in with Google.
- Profile content: name, headline, bio, contact details, skills, work experience, projects, education, certifications, and any custom sections you or a connected AI tool add.
- Generated content: AI-tailored resume versions, and the PDF resumes rendered from your profile.
- Job application records you choose to track (company, role, status, notes).
- Billing data if you subscribe to a paid plan — payments are processed by Razorpay; we store your plan and subscription status, not your card details, which never reach our servers.
- Your country, inferred from your IP address by our hosting provider (Vercel) — used only to decide which currency to show pricing in (USD or INR) and, at checkout, which currency you're actually billed in. We don't store this beyond the request, and it's not used for anything else.
- A hashed version of any API key you generate to connect an external AI tool — never the raw key itself.
- An activity log of profile changes (what changed, when, and whether it came from chat or an MCP tool call) — visible to you at any time on the History page.
How we use it
- To parse what you type in chat, or what a connected AI tool sends over MCP, into structured profile updates — this is sent to a third-party AI provider (Google's Gemini or Zhipu AI's GLM, depending on which is active) for processing. We do not use your data to train our own models.
- To generate AI-tailored resume content and PDFs from your real profile data — never invented content.
- To operate your account: authentication, billing, and the MCP server that lets your connected tools read and write your profile.
- To keep an audit trail of changes, so you can see what changed and why.
- If you enable your public card, to serve that page (and its social-media preview image) to anyone with the link.
- To show and bill pricing in the right currency for your region (USD or INR), based on your country as reported by our hosting provider.
We do not sell your data, and we do not share it with third parties except the processors listed below.
Who else sees it (third-party processors)
- Google Firebase — authentication and database hosting.
- Google Gemini and/or Zhipu AI (GLM) — processes chat messages and profile text to generate structured updates and tailored resumes, depending on which provider is active.
- Razorpay — payment processing for paid plans.
- Vercel — application hosting; also the source of the country signal used for regional pricing, derived automatically from your IP address at request time.
- Any AI tool you personally connect via an MCP API key (e.g. Claude, ChatGPT, Cursor) — that tool can read and write your profile data for as long as the key is active. You control this entirely: generate and revoke keys anytime from Settings.
Your public card
The public card (/c/your-link) is off by default. If you turn it on, the profile content you've chosen to include (not your email or phone number, unless you've put them in a field that's shown) is visible to anyone with the link, with no login required. You can disable it anytime from Settings, which takes the page down immediately.
Your rights
These are available directly in the product, not just on request:
- Right to access — download everything we hold about you as JSON from Settings → Account → "Download my data."
- Right to erasure — permanently delete your account and all associated data from Settings → Account → "Delete my account." This is immediate and irreversible.
- Right to correction — just tell the chat, or edit via a connected AI tool; your profile updates instantly.
- Grievance redressal — contact us at support@devstudiolabs.in for any complaint about how your personal data is processed.
How long we keep it
We keep your data for as long as your account exists. If you delete your account, everything — profile data, API keys, billing records tied to your account, and your public card — is deleted immediately and permanently.
Security
API keys are stored as one-way hashes, never in plaintext. All profile data access goes through server-side validation — no direct client access to the database is possible. Firestore Security Rules deny all access by default. Payment webhooks are cryptographically signature-verified.
Children
KnownIn is not directed at children under 18, and we don't knowingly collect data from anyone under that age.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page.
Contact us
For any privacy question or request: support@devstudiolabs.in. KnownIn is operated by DevStudioLabs (sole proprietorship), Mumbai, Maharashtra, India. Governed by the laws of India.
Questions about this document?
Review the related Terms of Service, or manage your profile, connected tools, exports, and account controls directly in KnownIn settings.