Skip to content

Agentknock · Full Disclosure

Privacy notice

Last updated ·

This notice explains how we collect, use, disclose and retain personal data in connection with Agentknock, and the rights available to you under applicable data protection law, including the General Data Protection Regulation (GDPR).

1. Controller and contact details

Agentknock is operated by Full Disclosure, Business ID 3639691-6, at Taka-Niipperin tie 12, 02970 Espoo, Finland (“Full Disclosure”, “we”, “us”). We are the controller of personal data processed for our own service administration, subscription management, security, website and correspondence purposes.

For enquiries about this notice or to exercise your data protection rights, contact privacy@fulldisclosure.fi.

2. Scope of this notice

This notice covers the Agentknock website and documentation, applications, relay service, optional cloud AI review, subscriptions and communications with us. It applies to users and to other individuals whose personal data is included in information submitted to these services.

Agentknock does not require a name-and-email account for device pairing and relay access. Device identifiers, subscription records and other information associated with a user may nevertheless constitute personal data.

Where we process personal data on behalf of an organisation using Agentknock, that organisation is responsible for determining the purposes of that processing. We act on its instructions under the data-processing agreement in section 13 of the service terms. Enquiries concerning such processing should be directed to the organisation; we assist it in responding where required. This notice does not replace an organisation’s own privacy information.

Information held only on your devices is described where relevant to explain the service. Saving it locally does not, by itself, make it available to us.

3. Personal data and its sources

We process the following categories of information, depending on the features you use. Information is provided by you and your devices, generated through use of the service, or received from the service providers identified below.

Credentials and information held on your devices
Your devices hold credentials, cryptographic keys, access rules, paired-device information, settings and local request history. Authorised programs may receive credentials or other information through the service. We do not receive your device PIN or biometric templates.
Registration and connection information
Device and client identifiers, authentication information, pairing addresses, connection times, activity records and delivery status are used to provide the connected service. We also process push notification identifiers where applicable. Messages between paired clients and the phone are relayed in encrypted form.
Device security information
We process information about the application and device security environment, including software versions, integrity checks and verification results, to assess whether a device meets the service’s security requirements.
AI review information
When cloud AI review is used, we process the review instructions, descriptions of the relevant credentials and clients, the requested operation and its context. This may include commands, file paths, signing content and repository information. Submitted content may contain names, email addresses or other personal data about you or others. Section 5 explains how this information is handled.
Subscription and transaction information
We receive purchase and subscription information from your device and Google Play, including transaction references, subscription status, entitlement and expiry information, and associated devices. Google Play also makes individual order records and transaction reports available to us. These may include transaction dates, amounts, refunds, chargebacks, device models and buyer location information. We retain reports needed as supporting evidence for our accounts. Google handles payment processing; we do not receive your payment-card number through the billing integration.
Website and operational information
Our infrastructure processes IP addresses, connection and request information, device or browser information, errors, security events and service usage. These records support delivery, troubleshooting, security, usage limits and billing for the service.
Correspondence
We process your contact details, messages and attachments when you contact us. Support and data protection requests may include device identifiers, Google Play order IDs and receipt information. Please provide only information relevant to your enquiry.

4. Purposes and legal bases

We use personal data for the purposes set out below. Where we act as a controller, the applicable legal basis depends on the purpose and our relationship with the individual. Processing on an organisation’s behalf is governed by its instructions and the arrangements described in section 2.

PurposeLegal basis
Provide the services you request, including device registration, authentication, message delivery and selected AI review features.Performance of a contract under Article 6(1)(b) GDPR, where the processing is necessary to provide the service to you.
Verify subscriptions, administer access, handle refunds and respond to enquiries about your service or a prospective purchase.Performance of a contract, or steps taken at your request before entering a contract, under Article 6(1)(b).
Deliver the website and documentation and respond to general enquiries.Legitimate interests under Article 6(1)(f): making information about our services available and responding to communications.
Keep correspondence to document business relationships, agreements, instructions and responses.Legitimate interests under Article 6(1)(f): maintaining a reliable history of our business communications and resolving later questions or disputes.
Maintain service reliability, investigate faults, prevent misuse and enforce security and usage limits.Legitimate interests under Article 6(1)(f): protecting users, securing the service and operating it reliably.
Respond to data protection requests and comply with applicable legal, accounting and regulatory obligations.Compliance with a legal obligation under Article 6(1)(c).
Establish, exercise or defend legal claims using information relevant to the matter.Legitimate interests under Article 6(1)(f): protecting and exercising our legal rights.

Where we rely on legitimate interests, we consider the necessity of the processing and its effect on your rights and interests. Where a use requires consent, we obtain that consent separately and you may withdraw it at any time. This notice does not itself constitute consent.

We do not sell personal data or use it for targeted advertising. We do not use AI review content to train models or for general product improvement.

5. AI review and data use

Cloud AI review is optional. When you use it, review information is processed by our service, Cloudflare and the model provider, currently OpenAI. These parties receive readable review context to produce a decision and explanation. This processing is separate from the encrypted exchange between your paired devices.

We do not retain AI review requests or responses after processing. We do not keep review content in application logs or review databases, and we do not authorise its use for model training. We use the model provider under zero data retention arrangements. The provider’s obligations are governed by those arrangements and their stated limitations, including any temporary infrastructure caching they expressly permit. Further information is available in OpenAI’s data controls.

Sensitive credential fields and private keys are excluded from review context. However, information entered into instructions, commands, descriptions or other submitted content may itself contain sensitive or personal data. That information forms part of the review.

The zero-retention arrangements concern cloud review content. Separate device, subscription, security and usage records remain subject to this notice. Your devices may also retain local review history and backups.

6. Recipients and service providers

We disclose personal data where necessary to provide the service, carry out the purposes described in this notice, or comply with a legal obligation. The principal recipients are:

  • Cloudflare, which provides hosting, storage, network services and the AI gateway.
  • OpenAI, which provides the cloud AI review model through Cloudflare.
  • Google, which provides Google Play billing and order administration and supported push notification services through Firebase. Push notifications contain a generic wake-up signal rather than credential-request content.
  • GitHub, which provides public issue reporting and private security reporting. Public issue reports you submit are visible to others.
  • Email and cloud storage providers, which host our business correspondence and accounting records, including transaction reports retained as vouchers.
  • Services you choose to use, including your device backup provider, and programs or devices you authorise to receive information.

Service providers processing personal data on our behalf are subject to applicable data protection agreements and instructions. Providers may separately act as controllers for their own account, payment, security or other activities. We may also disclose relevant information to competent authorities or professional advisers where required by law or necessary to establish, exercise or defend legal claims.

7. International transfers

We operate from Finland and use providers with international operations. Personal data may be processed outside the European Economic Area, including in the United States.

For transfers subject to the GDPR, we rely on an applicable adequacy decision or appropriate safeguards, such as the European Commission’s standard contractual clauses.

Cloudflare relies on its EU–US Data Privacy Framework certification for covered transfers to the United States. Its Data Processing Addendum incorporates the standard contractual clauses for other restricted transfers and as an alternative where that certification no longer applies.

You may contact us for further information about the safeguards relevant to your data or to obtain a copy, subject to any necessary redactions to protect confidential information.

8. Data retention

Retention depends on the purpose and type of information. The following periods and criteria apply, subject to earlier deletion where appropriate and any specific legal obligation requiring retention.

AI review content
We do not retain cloud review requests or responses after processing, as explained in section 5.
Device and connection records
We initiate deletion of inactive device records after 180 days without authenticated device activity. Associated registration records and identifiers held by our relay generally follow that device’s lifecycle.
Push notification registrations
When a registered notification identifier is replaced or removed, or when we delete the device registration, we request deletion of the corresponding Firebase installation. According to Google’s Firebase documentation, data tied to the installation is removed from Firebase’s live and backup systems within 180 days of the deletion request.
Encrypted messages
Relay messages are held temporarily while a request is active or delivery and recovery remain pending. They are removed following confirmed delivery, cancellation or expiry of the relevant exchange.
Pairing addresses
Address records may be retained for up to 90 days to manage reassignment. Deleting a device removes its association with current addresses; historical address records may remain until their existing retention period ends.
Recovery copies
Deleted or expired backend records may remain in backup or recovery storage for up to 30 additional days after removal from live storage. These copies are excluded from normal service processing and expire under the recovery-storage schedule.
Backend subscription records
We schedule deletion of Google Play subscription records for 60 days after the expiry date, once Google confirms that the subscription has expired. When a purchase is replaced, we retain a limited record for 60 days after recording its replacement. Records supporting ongoing or resumable subscriptions remain while that relationship continues. Other subscription records no longer associated with a device may be deleted earlier. Earlier deletion may be requested under section 9. These periods concern our service’s backend records. Google maintains separate billing and transaction records under the rules applicable to its services.
Accounting records
We retain required vouchers, transaction-related correspondence and other supporting accounting material for six years from the end of the calendar year in which the financial year ended. Where particular records remain necessary for another legal obligation or the establishment, exercise or defence of legal claims, we keep only the relevant records for as long as necessary. Once this period and any justified extension end, we delete or anonymise personal data in those records and the copies we control. This period is separate from the backend and correspondence retention periods.
Deletion-request correspondence
We retain the request conversation, including any order IDs, receipts, attachments and separately saved copies, for 90 days after completing the request and sending our final response to address immediate follow-up questions or corrections. We then delete the whole conversation and those copies. We honour requests for earlier deletion unless particular records remain necessary for a legal obligation or the establishment, exercise or defence of legal claims. Where these needs require longer retention, we keep only the relevant records for as long as necessary.
Other correspondence
Our default retention period for correspondence is six years after the last message sent or received in the conversation. We honour requests for earlier deletion unless particular records remain necessary for an ongoing contractual matter, a legal obligation or the establishment, exercise or defence of legal claims. Where these needs require longer retention, we keep only the relevant records for as long as necessary. Correspondence about deletion requests follows the shorter retention rule above.
Email recovery copies
Deleted email may remain in trash for up to 30 additional days, then be recoverable by our administrator for up to 25 further days. These recovery periods follow the correspondence retention periods above. Longer preservation is limited to the legal obligations or legal claims described above.
Operational records
Ordinary application and error logs are retained for up to seven days. Service providers may separately retain limited usage, billing and security records under the terms applicable to their services.
Information on your devices
Credentials and settings remain until you remove them. The app prunes local audit history after 365 days when it runs. A separate recent-request history can remain longer, without an age-based expiry, until replaced or cleared. Existing backups and copies held by other programs follow their own settings and retention arrangements.

Records held by providers for their own purposes are subject to their respective retention policies. Information about Google’s processing is available in its privacy policy and Firebase privacy information.

9. Deletion of personal data

You can request deletion of device records through the app’s factory reset function while connected, or by contacting us. Removing the app or clearing its local data while offline does not by itself confirm removal of backend records. See our device deletion instructions for practical guidance.

For subscription-related deletion, contact us with the relevant Google Play order ID. We delete the live subscription and associated device records that we can identify within the request’s scope. Additional identifiers may be needed to locate separate or older records. We will explain any records we cannot locate or delete, and any further action needed. We do not introduce additional identity tracking solely to make unidentified records searchable.

Cancellation and data deletion are separate. Subscription renewal must be cancelled through Google Play. Resetting the app or requesting deletion from us does not cancel renewal, and cancellation does not automatically erase our records.

Once relay deletion begins, the device registration is disabled. If cleanup is delayed, its records remain pending automatic retries.

We retain accounting records that remain necessary to meet our legal obligations, and particular records needed to establish, exercise or defend legal claims, even where other data is deleted following your request. We explain which records remain, the reason and the applicable retention period. We limit their use to the purposes that justify retaining them.

Deletion from the live service ends normal processing of the relevant records. The retention periods for address reservations, recovery copies and other separately held records still apply. Deletion does not remove copies held independently by you or other recipients.

10. Security

We use technical and organisational measures appropriate to the nature of the information and the risks of processing, including encryption, authentication and access controls. Messages between paired clients and the phone are end-to-end encrypted. The relay does not have the keys required to read their protected contents.

Sensitive credentials stored by the app are protected by encryption and device security controls. Other local records, including metadata and history, do not necessarily have the same protection. The security of your devices, authorised programs and backups also affects the confidentiality of your information.

Further information is available on our security page. Security concerns can be reported using our reporting instructions.

11. Required information and your choices

Registration, authentication and connection information are necessary to provide the connected service. Purchase verification is necessary for paid entitlements. If this information is not provided, the relevant functions cannot be supplied. There is no general legal requirement to use Agentknock or provide this information.

Cloud AI review is optional. You may use manual approval or change your settings to stop future cloud reviews. Doing so does not erase existing local history or the administrative records described in this notice.

We do not use advertising or behavioural analytics integrations in the website or applications. The documentation may store a display preference in your browser. Necessary connection and operational information is still processed when you use the service.

12. Automated decisions

Agentknock uses automated checks to administer access, security and usage limits. Where you enable AI approval, requests may be approved, declined or referred to you under your selected rules. Approval may permit a credential to be released or a signing operation to proceed.

You can review the request and explanation, change the rules or use manual approval. These functions govern technical access requests; we do not use them to make decisions about you with legal or similarly significant effects within the meaning of Article 22 GDPR.

13. Your data protection rights

Subject to the conditions and exceptions in applicable law, you may:

  • Request access to your personal data and a copy of it.
  • Request correction of inaccurate data and completion of incomplete data.
  • Request erasure or restriction of processing.
  • Receive data you provided in a structured, commonly used and machine-readable format, and request its transfer to another controller, where processing is automated and based on consent or contract.
  • Object to processing based on legitimate interests on grounds relating to your particular situation. We will stop that processing unless we demonstrate overriding legitimate grounds or the processing is needed for legal claims.
  • Withdraw consent where processing relies on it, without affecting the lawfulness of processing before withdrawal.
  • Exercise the protections relating to qualifying automated decisions where Article 22 GDPR applies.

To exercise your rights, contact privacy@fulldisclosure.fi. We may need information to locate the relevant records and verify your identity or authority. Where we cannot identify the data concerned, we will explain this and facilitate your request if you provide information that makes identification possible.

We respond without undue delay and normally within one month of receiving a request. Where permitted because of the complexity or number of requests, this may be extended by up to two further months; we will notify you of the extension and its reasons within the first month. Requests are normally free. A reasonable fee or refusal is permitted only in the circumstances allowed by law, such as manifestly unfounded or excessive requests. If we decline to act, we will explain the reasons and the remedies available.

You may complain to the Office of the Data Protection Ombudsman in Finland, or a competent supervisory authority in the EEA country where you habitually live or work, or where the alleged infringement occurred. You do not have to contact us first. You may also seek a judicial remedy.

14. Changes to this notice

We may update this notice to reflect changes in the service, our processing or applicable requirements. The revision date identifies the current version. Where appropriate or required by law, we will provide additional notice of material changes.

Before processing personal data for a new purpose, we will provide the required information and establish the applicable legal basis. Publishing an updated notice does not itself constitute consent.