Privacy policy

Version of 1 May 2026

This explains what Knapsack (knapsack.my) collects, why, and what happens to it afterwards. We try to collect as little as the service can run on.

What we collect

Account data

An email address and a password hash. A display name is optional. We do not ask for a phone number.

Object metadata

Object keys, sizes, upload timestamps, checksums and the bucket or project they belong to. This is what makes a listing possible and what your usage is calculated from.

Technical logs

Connection IP address, client type and version, request time and result. Kept for 30 days and used only for debugging and for rate-limiting abuse.

Billing data

Amounts, dates and payment status. Card details are handled by our payment provider and never reach our systems.

What we do not do

Who we share with

Two cases only: our payment provider, to take payment; and competent authorities, in response to a properly issued legal request. In the second case we notify the affected customer unless we are prohibited from doing so.

Retention

Security

All connections use TLS. Data at rest is encrypted on the storage layer. Staff access to production requires hardware-backed two-factor authentication and is logged. Backups are taken daily and stored in a separate facility.

Cookies

Only strictly necessary ones: a session cookie and a preference cookie for the interface theme. No analytics, no advertising, no consent banner needed.

Your rights

You may request a copy of your data, correction of inaccuracies, or deletion of the account. Write to hello@knapsack.my from the address on the account and we will complete the request within 30 days.