Legal

Privacy Policy

Last updated: 3 September 2026

Knowledge Gaps reads your support tickets, finds the questions your help center can’t answer, and drafts the fix. Doing that means handling your data — and some of it belongs to your customers. This policy explains exactly what we collect, why, who we share it with, and the control you keep over it.

1. Who we are

Knowledge Gaps is a product of ScreamX Inc., a Delaware corporation (“ScreamX”, “Knowledge Gaps”, “we”, “us”, “our”). We operate the website at knowledgegaps.co and the Knowledge Gaps service (the “Service”). ScreamX Inc. is the data controller for the personal information described in this policy, except where we act as a processor on your behalf as described in section 2.

Our registered address is ScreamX Inc., 1007 Orange Street, 4 FL 1975, Wilmington, DE 19801, United States.

For any privacy question, request, or complaint, email pooja@knowledgegaps.co. We answer every privacy request from a real person.

2. Controller and processor roles

There are two distinct kinds of data in the Service, and we treat them differently:

  • Account Data — information about you as our customer: your name, work email, company, billing details, and how you use the Service. We are the controller of this data and decide how it is used, within the limits of this policy.
  • Customer Data — the support tickets, conversations, help center articles, and related content that you connect to the Service. This belongs to you, and may include personal information about your end users. We are a processor of this data. We act on your documented instructions, we do not use it for our own purposes, and you remain responsible for having a lawful basis to send it to us.

In plain terms: your tickets are yours. We process them to find gaps and draft articles for you, and for nothing else. We do not sell data, and we do not build advertising profiles.

3. Information we collect

3.1 Information you give us

  • Account and contact details — name, work email address, company name, role, and anything you write to us in an email or support request.
  • Billing information — your billing name, address, and subscription status. Card numbers are collected and stored by our payment processor, not by us; we receive only a token and the last four digits.
  • Integration credentials — the OAuth tokens or API keys you authorise so we can read your helpdesk and write to your help center. These are encrypted at rest and are revocable by you at any time from the connected tool.

3.2 Customer Data we process for you

  • Support tickets and conversation threads, including message bodies, subjects, timestamps, tags, and status.
  • Existing help center articles, categories, and their metadata.
  • Any personal information your end users happen to include in a ticket — names, email addresses, order numbers, or free-text detail they chose to write.

We ask for the narrowest access scope each integration allows. Where a connected tool supports it, we read tickets rather than customer profiles.

3.3 Information we collect automatically

  • Usage data — which features you use, gaps reviewed, drafts approved or rejected, and timestamps. This tells us what to improve.
  • Device and log data — IP address, browser type, operating system, referring page, and error logs. We use this for security, abuse prevention, and debugging.
  • Cookies — see section 12.

4. How we use information

PurposeWhat we use
Provide the Service — detect gaps, draft articles, publish on your approvalCustomer Data, integration credentials
Create and manage your account, authenticate youAccount Data
Take payment and send invoicesBilling information
Support you when you write inAccount Data, limited Customer Data where you ask us to look
Keep the Service secure, prevent abuse, and investigate incidentsLog data, usage data
Improve the Service and fix bugsAggregated and de-identified usage data
Send service notices, and product updates you can unsubscribe fromAccount Data
Meet legal, tax, and accounting obligationsAccount Data, billing information

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under United States state privacy laws.

5. AI processing and model training

The Service uses large language models to read tickets, cluster them into gaps, and draft candidate articles. This means the content of your tickets is transmitted to our AI model providers for processing.

  • We use enterprise or business API tiers whose terms prohibit the provider from using submitted content to train their models.
  • We do not use your Customer Data to train our own models, and we do not use it to improve the Service for other customers, unless you have separately and explicitly agreed in writing.
  • Model providers may retain content briefly for abuse monitoring in line with their own policies. Current providers are listed in section 7.
  • Every drafted article requires a human on your team to approve it before it is published. The Service never publishes to your help center on its own.

Accuracy: AI-generated drafts can be wrong, incomplete, or out of date. The approval step exists precisely so a person on your team is accountable for what goes live. Please treat every draft as a draft.

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:

  • Performance of a contract — to provide the Service you signed up for, manage your account, and take payment.
  • Legitimate interests — to secure the Service, prevent fraud and abuse, improve our product, and send relevant product communications to business contacts. We balance these against your rights and you may object at any time.
  • Legal obligation — to comply with tax, accounting, and law enforcement requirements.
  • Consent — where we ask for it, such as certain marketing emails or non-essential cookies. You may withdraw consent at any time.

7. Sharing and subprocessors

We share information only with the categories of recipient below, and only as far as each needs it to do its job:

CategoryWhat they doData involved
Cloud hosting and infrastructureRun and store the ServiceAccount Data, Customer Data
AI model providersGap detection and article draftingTicket and article content
Payment processorTake subscription paymentsBilling information
Email and support toolingSend service email, answer your questionsAccount Data
Product analytics and error monitoringUnderstand usage, catch crashesUsage and log data

Every subprocessor is bound by a written agreement that requires confidentiality, appropriate security, and processing limited to our instructions. A current list of named subprocessors is available on request from pooja@knowledgegaps.co, and we will give you reasonable notice before adding a new one that materially affects Customer Data.

We may also disclose information where we are legally required to, to enforce our agreements, to protect the rights and safety of people, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you and the acquirer remains bound by this policy.

8. International transfers

We and our subprocessors may process data in countries other than your own, including the United States. Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on appropriate safeguards — typically the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum — together with supplementary technical measures such as encryption in transit and at rest. Copies of the relevant safeguards are available on request.

9. Data retention

  • Customer Data — retained while your subscription is active. On termination, we delete or de-identify it within 30 days, except where you ask us to delete it sooner or the law requires us to keep it longer. You can request deletion at any time.
  • Account and billing data — retained for as long as your account is open, then for up to 7 years where tax and accounting law requires it.
  • Log data — typically retained for 90 days, longer only where an active security investigation requires it.
  • Backups are cycled out on a rolling basis; data deleted from the live Service falls out of backups within 90 days.

10. Security

We take security seriously and apply measures appropriate to the sensitivity of what we hold, including:

  • Encryption in transit (TLS 1.2 or higher) and encryption at rest.
  • Integration credentials stored encrypted, with least-privilege access scopes.
  • Role-based access control, with staff access to Customer Data limited to those who need it and logged.
  • Regular dependency patching, monitoring, and alerting.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you without undue delay and, where required, within 72 hours of becoming aware, along with what we know and what we are doing about it.

11. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you, and receive a copy.
  • Correct information that is inaccurate or incomplete.
  • Delete your personal information.
  • Port your data to another provider in a machine-readable format.
  • Object to or restrict certain processing, including direct marketing.
  • Withdraw consent where processing is based on consent.
  • Opt out of sale or sharing of personal information — we do neither, but the right stands.
  • Not be discriminated against for exercising any of these rights.

To exercise any right, email pooja@knowledgegaps.co. We will respond within 30 days, or tell you if we need longer. We may need to verify your identity first. You may use an authorised agent where the law permits it.

If the request concerns Customer Data — for example, an end user of one of our customers asking about a ticket — please contact that customer directly, as they are the controller. If you reach us instead, we will forward your request to them promptly.

If you are in the EEA or UK and believe we have not handled your data properly, you may lodge a complaint with your local supervisory authority. We would appreciate the chance to put it right first.

12. Cookies and analytics

Our website and Service use a small number of cookies and similar technologies:

  • Strictly necessary — to keep you signed in, remember your session, and protect against cross-site request forgery. These cannot be switched off.
  • Analytics — to understand which pages and features are used, in aggregate.

We do not use advertising or cross-site tracking cookies. You can block or delete cookies through your browser settings, though the Service may not work correctly without the strictly necessary ones. We honour Global Privacy Control signals where your browser sends them.

13. Children

The Service is a business tool and is not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal information, email pooja@knowledgegaps.co and we will delete it.

14. Changes to this policy

We may update this policy as the Service evolves or the law changes. We will update the “Last updated” date at the top, and for material changes we will email account holders or show a notice in the Service at least 14 days before the change takes effect. Continuing to use the Service after that means you accept the updated policy.

15. Contact us

Privacy contact

Questions, access requests, deletion requests, subprocessor lists, or a copy of our Data Processing Addendum — all go to the same address, and a person will answer.

ScreamX Inc.
1007 Orange Street, 4 FL 1975
Wilmington, DE 19801
United States


See also our Terms & Conditions and Refund Policy.

ScreamX Inc. · 1007 Orange Street, 4 FL 1975, Wilmington, DE 19801, United States