Privacy Policy

Last updated: 14 June 2026

This Privacy Policy explains how bernard, a service operated by KnowCode ("bernard", "we", "us" or "our"), collects, uses, shares and protects your personal data when you use the bernard websites, applications and services (the "Service"). It also explains your rights and how to exercise them.

For personal data about your own audience that you upload or collect through bernard (your contacts, buyers and students), you are the data controller and we act as your processor — see "Data you manage about other people" below.

Who we are

bernard is operated by KnowCode. We are the data controller for the personal data described in this policy (except the contact data you manage about your own audience). You can reach us about privacy at [email protected].

What data we collect

  • Account data — your name, email address, password (stored only as a secure hash) and account settings.
  • Sign-in data from Google — if you choose "Continue with Google", we receive your name, email address, language/locale and profile picture from your Google account. See "Signing in with Google" below.
  • Your content — the website we Move for you and everything you create or store in bernard (pages, images, products, courses).
  • Data you manage about other people — the contact records of your own audience that you upload or collect.
  • Billing data — if you subscribe, our payment processor (Stripe) handles your card details; we receive limited information such as your subscription status and the last four digits of your card. We do not store full card numbers.
  • Usage and device data — log data such as IP address, browser type, pages viewed and actions taken, used to operate and secure the Service.
  • Cookies — see "Cookies and similar technologies" below.

How we use your data, and our lawful bases

We use personal data to:

  • provide the Service — create and run your account, Move your site, host your content and deliver bernard's features (lawful basis: performance of our contract with you);
  • communicate with you — send sign-in codes, service and security notices, and respond to support requests (contract / legitimate interests);
  • bill you — process subscriptions and prevent payment fraud (contract / legal obligation);
  • keep the Service safe — monitor for abuse, secure accounts and enforce our Terms (legitimate interests);
  • improve the Service — understand how it's used and develop new features (legitimate interests); and
  • meet legal obligations — such as accounting and responding to lawful requests (legal obligation).

Where we rely on legitimate interests, we balance them against your rights. Where we rely on consent (for example certain marketing), you can withdraw it at any time.

Signing in with Google

When you sign in with Google, Google shares a limited set of profile information with us — your name, email address, locale and profile picture — so we can create or recognise your bernard account.

  • We use this information only to authenticate you, create and manage your account, and contact you about the Service.
  • We do not use it for advertising, and we do not sell it.
  • bernard's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
  • You can revoke bernard's access at any time from your Google Account permissions.

Data you manage about other people

When you upload or collect personal data about your own contacts, fans, buyers or students, you are the controller of that data and we process it on your behalf under our agreement with you. You are responsible for having a lawful basis to hold and use that data and for honouring those individuals' rights. We will process it only to provide the Service to you and in line with your instructions.

Cookies and similar technologies

We use a small number of essential cookies that are necessary to run the Service — for example to keep you signed in, to keep your session secure, and to remember your cookie choices. With your consent we also use Google Analytics 4 to understand aggregate usage so we can improve the product; you choose whether to allow this via our cookie banner, and you can change your mind at any time. Google Analytics is loaded in Consent Mode with advertising signals disabled — we do not use advertising cookies and do not use it to target ads.

Who we share data with

We share personal data only as needed to run the Service, with service providers ("sub-processors") who act on our instructions, including:

ProviderPurpose
SupabaseDatabase, authentication and storage
Amazon Web ServicesCloud hosting and infrastructure
CloudflareContent delivery, DNS and security
PostmarkTransactional email delivery
StripeSubscription payments
Google"Continue with Google" sign-in; Google Analytics 4 (with your consent)
OpenRouter / LLM providersAI-assisted features you choose to use

We may also disclose data if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition or sale of assets (with notice where required). We do not sell your personal data.

International transfers

Some of our providers process data outside the UK/EEA. Where they do, we rely on appropriate safeguards (such as adequacy decisions or Standard Contractual Clauses) to protect your data.

How long we keep data

We keep personal data for as long as your account is active and for a reasonable period afterwards to meet legal, accounting and security obligations, after which we delete or anonymise it. You can ask us to delete your account and data at any time (see "Your rights").

How we protect your data

We use technical and organisational measures appropriate to the risk — including encryption in transit, access controls, row-level security and secure authentication. No system is perfectly secure, so we cannot guarantee absolute security, and you are responsible for keeping your credentials safe.

Your rights

Subject to applicable law, you have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent where we rely on it. To exercise any of these, email [email protected]. You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

Children

The Service is not directed at children under 18, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will take reasonable steps to notify you (for example by email or an in-product notice). The "Last updated" date above shows when this version took effect.

Contact us

Questions about your privacy or this policy? Email [email protected].