Privacy policy
What we collect, why, and where it lives.
This policy covers the Knowledge Commons hosted service at knowledgecommons.ai and the Knowledge Commons companion apps for iOS, Android and macOS. It is written to be read, not scrolled past. Effective 21 September 2026.
Who we are
Goal17, Inc. is the operator of the hosted service.
Knowledge Commons is built and operated by Goal17, Inc., Toronto, Canada. For the hosted service at knowledgecommons.ai, Goal17 is the organisation responsible for your personal information under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and comparable laws elsewhere.
Questions, access requests and complaints go to aaron@goal17.co. We answer within 30 days.
Self-hosted deployments are different. When an organisation runs Knowledge Commons on its own infrastructure — air-gapped or otherwise — that organisation controls every byte and is the responsible party. Goal17 receives nothing from a self-hosted deployment. This policy governs only the hosted service and the apps when they are pointed at it.
What we collect
Only what the product needs to work.
Everything below is collected because a feature depends on it. There is no advertising, no profiling, no third-party analytics SDK and no sale of data — in the apps or on this site.
- Account information — Your name, email address and a user identifier, created when your organisation invites you or when you sign up. Used to sign you in, to show who contributed what, and to send the emails that operate the service — invitations, verification, billing notices.
- Audio recordings — Recordings you make with a companion app, a Knowledge Commons hardware recorder or the desktop recorder are uploaded to your organisation’s project and transcribed. Recordings may include the voices of other people in the room. You are responsible for obtaining any consent the law requires before recording. The platform’s Anonymous mode strips speaker identity from the transcript; Speaker-ID mode keeps it. Your project’s administrator chooses which.
- Documents, notes, photos and other content — Files you upload, notes you write, pages you scan with the app’s camera, comments, votes and survey answers. All of it belongs to your organisation’s project and is visible only to the people that project’s administrators have given access to.
- Device identifier — The companion apps generate a random per-install identifier (something like
iphone482913) and put it in the name of every audio chunk they upload, so the pipeline can tell one recorder from another. It is not the advertising identifier, it is not shared with anyone, and it is reset if you reinstall the app. - Billing information — If you pay for a plan, payment is handled by Stripe (on the web) or Apple (in-app purchase on iOS). We never see or store card numbers. We keep the subscription status, the plan, and a customer or transaction reference so we can tell what your account is entitled to.
- Technical logs — Standard server logs — IP address, request path, timestamp, user agent — kept for security and to diagnose faults, and deleted on a rolling basis. We do not use them to build profiles.
How we use it
To run the service you signed up for. That’s the list.
- Providing the platform — Transcribing recordings, extracting entities and themes, building the knowledge graph, answering questions against it, and showing all of that to the people in your project.
- Operating your account — Authentication, access control, invitations, plan entitlements and the transactional email that goes with them.
- Security and reliability — Detecting abuse, investigating faults, keeping backups so a failure does not lose your organisation’s record.
- Legal obligations — Responding to lawful requests from authorities. We will tell you when we are permitted to.
There is no secondary use of customer data. We do not use your recordings, transcripts or documents to train models, we do not share them with any model provider, and we do not sell them. All inference — transcription, speaker separation, extraction, question answering — runs on GPUs Goal17 operates in Canada, and that processing is stateless: nothing is retained on the inference hardware once a job completes.
Where it lives
In Canada, on infrastructure we operate.
The hosted service runs on servers Goal17 owns and operates in Canada — not a public cloud. Your data is encrypted in transit (TLS) and at rest. Backups are encrypted at rest and kept on Goal17’s own servers in Canada.
A small number of service providers handle specific jobs on our behalf, and each sees only what its job requires:
- Stripe — Card payments for web subscriptions. Sees your name, email and payment details — which we never receive.
- Apple — In-app purchases on iOS, handled entirely by Apple under Apple’s privacy policy.
- Transactional email service — Delivers invitations, verification and billing emails. Sees your email address and the message.
We do not sell personal information, and we do not share it with anyone else except as required by law.
Your organisation’s role
Your project’s administrators decide who sees what.
Knowledge Commons is a tool organisations use to keep a record of their own conversations. The organisation that owns a project controls its membership, its speaker-identity mode, its retention, and what happens to the content. If you were recorded in a workshop run by an organisation using Knowledge Commons, that organisation is your first point of contact for questions about the recording; we will help them respond.
Your rights
Access, correction, export and deletion.
- Access and correction — You can see and edit your account details in the app. For anything else, email us and we will send you what we hold about you.
- Export — A project’s owner can export its recordings, transcripts and documents at any time. There is nothing to be trapped by.
- Deletion — Delete your account and we delete your account information. Content you contributed to a project stays with that project — it is the organisation’s record — unless the project’s owner deletes it. Deleting a project removes its recordings, transcripts, documents and the graph derived from them. Backups roll off within 30 days.
- Complaint — If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, or to your local data-protection authority.
Retention
As long as your organisation keeps the project.
Project content is kept for as long as the project exists, because a permanent record is the point. Account information is kept while your account is active. Billing records are kept for seven years, as Canadian tax law requires. Technical logs are kept for 90 days.
Children
Not for people under 16.
Knowledge Commons is a tool for organisations. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe we have, email us and we will delete it.
Changes to this policy
We’ll say what changed and when.
When this policy changes we update the effective date at the top and, for anything material, email account holders before it takes effect. Previous versions are available on request.
Questions: aaron@goal17.co