Knowledge Gaps reads your support tickets, finds the questions your help center can’t answer, and drafts the fix. Doing that means handling your data — and some of it belongs to your customers. This policy explains exactly what we collect, why, who we share it with, and the control you keep over it.
1. Who we are
Knowledge Gaps is a product of ScreamX Inc., a Delaware corporation (“ScreamX”, “Knowledge Gaps”, “we”, “us”, “our”). We operate the website at knowledgegaps.co and the Knowledge Gaps service (the “Service”). ScreamX Inc. is the data controller for the personal information described in this policy, except where we act as a processor on your behalf as described in section 2.
Our registered address is ScreamX Inc., 1007 Orange Street, 4 FL 1975, Wilmington, DE 19801, United States.
For any privacy question, request, or complaint, email pooja@knowledgegaps.co. We answer every privacy request from a real person.
2. Controller and processor roles
There are two distinct kinds of data in the Service, and we treat them differently:
- Account Data — information about you as our customer: your name, work email, company, billing details, and how you use the Service. We are the controller of this data and decide how it is used, within the limits of this policy.
- Customer Data — the support tickets, conversations, help center articles, and related content that you connect to the Service. This belongs to you, and may include personal information about your end users. We are a processor of this data. We act on your documented instructions, we do not use it for our own purposes, and you remain responsible for having a lawful basis to send it to us.
In plain terms: your tickets are yours. We process them to find gaps and draft articles for you, and for nothing else. We do not sell data, and we do not build advertising profiles.
3. Information we collect
3.1 Information you give us
- Account and contact details — name, work email address, company name, role, and anything you write to us in an email or support request.
- Billing information — your billing name, address, and subscription status. Card numbers are collected and stored by our payment processor, not by us; we receive only a token and the last four digits.
- Integration credentials — the OAuth tokens or API keys you authorise so we can read your helpdesk and write to your help center. These are encrypted at rest and are revocable by you at any time from the connected tool.
3.2 Customer Data we process for you
- Support tickets and conversation threads, including message bodies, subjects, timestamps, tags, and status.
- Existing help center articles, categories, and their metadata.
- Any personal information your end users happen to include in a ticket — names, email addresses, order numbers, or free-text detail they chose to write.
We ask for the narrowest access scope each integration allows. Where a connected tool supports it, we read tickets rather than customer profiles.
3.3 Information we collect automatically
- Usage data — which features you use, gaps reviewed, drafts approved or rejected, and timestamps. This tells us what to improve.
- Device and log data — IP address, browser type, operating system, referring page, and error logs. We use this for security, abuse prevention, and debugging.
- Cookies — see section 12.
4. How we use information
| Purpose | What we use |
|---|---|
| Provide the Service — detect gaps, draft articles, publish on your approval | Customer Data, integration credentials |
| Create and manage your account, authenticate you | Account Data |
| Take payment and send invoices | Billing information |
| Support you when you write in | Account Data, limited Customer Data where you ask us to look |
| Keep the Service secure, prevent abuse, and investigate incidents | Log data, usage data |
| Improve the Service and fix bugs | Aggregated and de-identified usage data |
| Send service notices, and product updates you can unsubscribe from | Account Data |
| Meet legal, tax, and accounting obligations | Account Data, billing information |
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under United States state privacy laws.
5. AI processing and model training
The Service uses large language models to read tickets, cluster them into gaps, and draft candidate articles. This means the content of your tickets is transmitted to our AI model providers for processing.
- We use enterprise or business API tiers whose terms prohibit the provider from using submitted content to train their models.
- We do not use your Customer Data to train our own models, and we do not use it to improve the Service for other customers, unless you have separately and explicitly agreed in writing.
- Model providers may retain content briefly for abuse monitoring in line with their own policies. Current providers are listed in section 7.
- Every drafted article requires a human on your team to approve it before it is published. The Service never publishes to your help center on its own.
Accuracy: AI-generated drafts can be wrong, incomplete, or out of date. The approval step exists precisely so a person on your team is accountable for what goes live. Please treat every draft as a draft.
6. Legal bases for processing (EEA and UK)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:
- Performance of a contract — to provide the Service you signed up for, manage your account, and take payment.
- Legitimate interests — to secure the Service, prevent fraud and abuse, improve our product, and send relevant product communications to business contacts. We balance these against your rights and you may object at any time.
- Legal obligation — to comply with tax, accounting, and law enforcement requirements.
- Consent — where we ask for it, such as certain marketing emails or non-essential cookies. You may withdraw consent at any time.
7. Sharing and subprocessors
We share information only with the categories of recipient below, and only as far as each needs it to do its job:
| Category | What they do | Data involved |
|---|---|---|
| Cloud hosting and infrastructure | Run and store the Service | Account Data, Customer Data |
| AI model providers | Gap detection and article drafting | Ticket and article content |
| Payment processor | Take subscription payments | Billing information |
| Email and support tooling | Send service email, answer your questions | Account Data |
| Product analytics and error monitoring | Understand usage, catch crashes | Usage and log data |
Every subprocessor is bound by a written agreement that requires confidentiality, appropriate security, and processing limited to our instructions. A current list of named subprocessors is available on request from pooja@knowledgegaps.co, and we will give you reasonable notice before adding a new one that materially affects Customer Data.
We may also disclose information where we are legally required to, to enforce our agreements, to protect the rights and safety of people, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you and the acquirer remains bound by this policy.
8. International transfers
We and our subprocessors may process data in countries other than your own, including the United States. Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on appropriate safeguards — typically the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum — together with supplementary technical measures such as encryption in transit and at rest. Copies of the relevant safeguards are available on request.
9. Data retention
- Customer Data — retained while your subscription is active. On termination, we delete or de-identify it within 30 days, except where you ask us to delete it sooner or the law requires us to keep it longer. You can request deletion at any time.
- Account and billing data — retained for as long as your account is open, then for up to 7 years where tax and accounting law requires it.
- Log data — typically retained for 90 days, longer only where an active security investigation requires it.
- Backups are cycled out on a rolling basis; data deleted from the live Service falls out of backups within 90 days.
10. Security
We take security seriously and apply measures appropriate to the sensitivity of what we hold, including:
- Encryption in transit (TLS 1.2 or higher) and encryption at rest.
- Integration credentials stored encrypted, with least-privilege access scopes.
- Role-based access control, with staff access to Customer Data limited to those who need it and logged.
- Regular dependency patching, monitoring, and alerting.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you without undue delay and, where required, within 72 hours of becoming aware, along with what we know and what we are doing about it.
11. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you, and receive a copy.
- Correct information that is inaccurate or incomplete.
- Delete your personal information.
- Port your data to another provider in a machine-readable format.
- Object to or restrict certain processing, including direct marketing.
- Withdraw consent where processing is based on consent.
- Opt out of sale or sharing of personal information — we do neither, but the right stands.
- Not be discriminated against for exercising any of these rights.
To exercise any right, email pooja@knowledgegaps.co. We will respond within 30 days, or tell you if we need longer. We may need to verify your identity first. You may use an authorised agent where the law permits it.
If the request concerns Customer Data — for example, an end user of one of our customers asking about a ticket — please contact that customer directly, as they are the controller. If you reach us instead, we will forward your request to them promptly.
If you are in the EEA or UK and believe we have not handled your data properly, you may lodge a complaint with your local supervisory authority. We would appreciate the chance to put it right first.
12. Cookies and analytics
Our website and Service use a small number of cookies and similar technologies:
- Strictly necessary — to keep you signed in, remember your session, and protect against cross-site request forgery. These cannot be switched off.
- Analytics — to understand which pages and features are used, in aggregate.
We do not use advertising or cross-site tracking cookies. You can block or delete cookies through your browser settings, though the Service may not work correctly without the strictly necessary ones. We honour Global Privacy Control signals where your browser sends them.
13. Children
The Service is a business tool and is not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal information, email pooja@knowledgegaps.co and we will delete it.
14. Changes to this policy
We may update this policy as the Service evolves or the law changes. We will update the “Last updated” date at the top, and for material changes we will email account holders or show a notice in the Service at least 14 days before the change takes effect. Continuing to use the Service after that means you accept the updated policy.
15. Contact us
Questions, access requests, deletion requests, subprocessor lists, or a copy of our Data Processing Addendum — all go to the same address, and a person will answer.
ScreamX Inc.
1007 Orange Street, 4 FL 1975
Wilmington, DE 19801
United States
See also our Terms & Conditions and Refund Policy.