Last updated: May 5, 2026
Plain-English summary at the top, full details below. Have a licensed attorney review before commercial scale.
Applied Continuity LLC, an Indiana limited liability company doing business as KnowledgeBricks (“we”, “us”), operates knowledgebricks.com, logistics.knowledgebricks.com, and related services (collectively, the “Service”). This Policy covers all KnowledgeBricks properties unless a property posts its own policy that says otherwise. For purposes of GDPR, we are the data controller. For CCPA/CPRA purposes, we are a business.
For privacy questions, contact support@kbaas.ai with “Privacy Request” in the subject line.
When you create an account, Clerk processes your email address, password (hashed), name (if provided), and any third-party identity tokens (e.g., Google OAuth). Clerk acts as our authentication processor; we receive a Clerk user ID and limited profile information. See Clerk’s Privacy Policy.
When you subscribe, Stripe, Inc. collects and processes your payment instrument, billing address, and transaction history. We receive a Stripe customer ID, subscription status, and metadata about your plan, but never your full card number. See Stripe’s Privacy Policy.
We store your tier (free, standard, pro), entitlement timestamps, and any complimentary access flags in our database (Supabase). This is necessary to deliver the paid Service.
When you submit a question through Ask a SME, we log:
Like most web services, our hosting (Vercel) and database (Supabase) generate operational logs that include IP address, user-agent, request path, response status, and latency. These logs are retained for up to 30 days and are used to operate, secure, and debug the Service.
We use a small number of strictly necessary cookies and tokens — primarily to keep you signed in (Clerk session), to remember your dark/light mode choice, and to enforce rate limits. We do not use third-party advertising cookies.
We do not knowingly collect data from anyone under 18. We do not request government IDs, financial account numbers, biometric data, or precise geolocation.
Before any question is written to our database, the question text is processed by an automated redaction routine. The routine detects and replaces the following patterns with neutral placeholders such as [EMAIL], [PHONE], [SSN], [CARD], [KEY], [SECRET], [TOKEN], [NAME], and [IP]:
sk_, pk_, AWS, GitHub tokens, and similar)Alongside the redacted text we store a non-reversible summary of what categories were detected (e.g., {"type":"email","count":1}) so we can monitor redaction effectiveness. We do not store the original raw text.
Automated redaction is a best-effort system. It will not catch every form of personal data. Please do not paste sensitive personal information, customer-confidential data, or trade secrets into Ask a SME. If you accidentally submit such data, email support@kbaas.ai and we will purge the affected row from our database and from any subsequent export.
Each day, a scheduled job exports the prior day’s redacted questions log into a markdown file inside a private repository we control (kbaas-ai/logistics-vault, path _questions/YYYY-MM-DD.md). This export contains the same redacted question text and answer summary that we already store in our database. The repository is private and access is limited to KnowledgeBricks personnel. Exports are retained indefinitely as part of our internal product-improvement corpus and are not shared with third parties or used to train external AI models.
We use the information described above to:
| Purpose | Lawful basis |
|---|---|
| Account creation, authentication, access | Performance of a contract |
| Payment processing | Performance of a contract |
| Operational logs, abuse prevention | Legitimate interests (security and Service integrity) |
| Question logging and aggregate analysis | Legitimate interests (product improvement) with PII redaction |
| Transactional emails | Performance of a contract |
| Marketing communications (if any) | Consent |
We do not sell, license, or otherwise make subscriber data, the questions log, or our Content available for training, fine-tuning, or evaluation of any third-party AI model. Our processors (Clerk, Stripe, Supabase, Vercel, OpenAI, Anthropic) are contractually limited to processing data for the purpose of delivering their service to us; we have selected processors that contractually do not use customer API content to train their general models. Specifically:
The reciprocal restriction — that you may not use our Content to train any AI system — is in our Terms Section 8.
We share information only with:
We do not sell personal information for monetary consideration, and we do not “share” personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
| Sub-processor | Purpose | Region |
|---|---|---|
| Clerk, Inc. | Authentication, session management | United States |
| Stripe, Inc. | Payment processing, billing, tax | United States |
| Supabase, Inc. | Application database, file storage | United States |
| Vercel, Inc. | Hosting, serverless compute, edge cache | United States |
| OpenAI, L.L.C. | Embeddings for retrieval | United States |
| Anthropic, PBC | LLM for Ask a SME answer generation | United States |
| GitHub, Inc. | Private storage of nightly question export | United States |
| Resend | Transactional email delivery | United States |
We will update this list when we add or change sub-processors. For changes that materially affect the categories of personal data processed, we will provide notice via the Service or email.
Our Service is hosted in the United States. If you access it from outside the US — including the EU/EEA, UK, Canada, or Brazil — your information will be transferred to and processed in the United States. Where applicable, we rely on Standard Contractual Clauses (2021 EU SCCs, with the UK Addendum where relevant) with our sub-processors to safeguard transfers.
| Data category | Retention |
|---|---|
| Account record | While your account is active, plus 30 days after deletion request |
| Billing records | 7 years (US tax retention) |
| Operational logs (Vercel, Supabase) | Up to 30 days |
| Ask a SME questions log (redacted) | Indefinite, in aggregate; individual rows deleted on verified DSR request |
| Nightly question export (private repository) | Indefinite; individual entries scrubbed on verified DSR request |
| Anonymous rate-limit counters | 24 hours |
Depending on where you live, you may have the right to:
To exercise any right, email support@kbaas.ai with “Privacy Request” in the subject line. We will verify your identity through your registered email and respond within 45 days (CCPA) or 30 days (GDPR), and may extend by an additional period as permitted by law if your request is complex.
We will not discriminate against you for exercising your privacy rights.
We use commercially reasonable technical and organizational measures, including TLS in transit, encryption at rest at our sub-processors, scoped access tokens, principle-of-least-privilege database roles, and automated PII redaction in the questions log. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify you and applicable regulators within the timeframes required by law.
The Service is not directed to children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact support@kbaas.ai and we will delete it.
In the past 12 months we have collected the categories of personal information described in Sections 2 and 2.4 (identifiers, commercial information, internet/network activity, and the contents of questions submitted to Ask a SME after redaction). We collect this information directly from you and from our sub-processors. We use it for the purposes described in Section 5. We have not sold personal information for monetary consideration and we have not “shared” personal information for cross-context behavioral advertising.
California residents may exercise the rights to know, delete, correct, and limit the use of sensitive personal information, and may designate an authorized agent to act on their behalf, by contacting support@kbaas.ai.
We may update this Policy from time to time. The “Last updated” date at the top reflects the latest version. For material changes, we will notify you via the Service or by email at least fifteen (15) days before they take effect.
Applied Continuity LLC dba KnowledgeBricks 6101 North Keystone, Suite 100 #1326 Indianapolis, IN 46220 United States support@kbaas.ai