Privacy Policy
This policy explains what personal information the Knack app collects, how we hold and use it, and the choices and rights you have. It is written to align with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
The kinds of personal information we collect and hold
To help you discover apprenticeships, traineeships and cadetships and to show you an honest fit for each role, we collect and hold:
- Identity and contact details — your name and email address, used to create and secure your account (sign-in is passwordless, by a one-time code sent to your email).
- Your profile and preferences — the interests, motivations, preferences, work environments, deal-breakers, readiness (your stage, licence, transport, tickets and checks), location and relocation answers you provide, so we can match you to roles.
- Optional background information — if you choose to provide it, your age group, gender, and Aboriginal or Torres Strait Islander status. This is optional, is never required to use the app, and never affects your ability to apply to roles.
- Activity on the app — the roles you save, the employers you express interest in, and the connections that result.
- Privacy-friendly analytics — only if you accept analytics (see “Analytics and cookies” below).
How we collect and hold it
We collect personal information directly from you as you sign in, build your profile and use the app. We hold it in secured databases hosted in Australia (Sydney region), protected by access controls, encryption in transit, and owner-only data-access rules. We do not sell your personal information.
The purposes we use it for
- To create and secure your account and sign you in.
- To rank roles and produce an explainable fit verdict for you. This matching is an automated process — see How matching works (automated decision-making) for exactly which signals it uses.
- To let you express interest in a role and to progress a connection with an employer.
- To improve the app and, only with your consent, to understand how it is used.
Analytics, advertising, and cookies
We use analytics (Google Analytics 4), session-recording analytics (Microsoft Clarity), and the Meta pixel (Facebook and Instagram advertising) — all of them only if you accept, with one exception we explain below. The first time you open the app, a consent banner asks whether to enable them; it defaults to off and stays off unless you choose to accept. We remember your answer on the device you gave it on and, if you have an account, against your profile — so that we ask you once rather than again on every device or browser. Google Analytics data is limited to app-usage codes and counts — never your name, email, or other personal details. Clarity records session replays (clicks, scrolling, on-screen content) to help us spot usability issues, but every recording is masked so your name, email, date of birth, and any other personal detail is never visible in it. If you accept, the Meta pixel also receives app-usage codes and counts — for example that a role was viewed or an application was submitted — so we can measure and target our advertising. It never receives your name, email, date of birth, or anything you type into the app, including what you type into search.
If you accept, we also tell Meta from our own servers when an account is created, so we can measure how our advertising performs. That includes your IP address and basic browser information, and never your name, email, date of birth, or anything you type into the app. If you decline, we send nothing.
The one exception: if you arrive from one of our ads, the Meta pixel records that a page was opened before you have made a choice, and we record that the visit came from an ad. This is how we tell how much traffic our advertising brings, which we cannot otherwise measure. It is limited to the fact of a page being opened — no profile details, nothing you type, and nothing about what you do in the app. Everything else described above waits for your consent, and if you decline, nothing further is sent.
When we disclose your information
When you express interest in a role, we share the profile details needed for that connection with the relevant employer. What we collect for a connection and why is set out in What we collect and why. We use trusted service providers (for hosting, email delivery, and error monitoring) that process data on our behalf under contract.
Overseas disclosure
Your personal information is stored in Australia. Some service providers we rely on (for example, error-monitoring or email delivery) may process limited data overseas. The analytics and advertising services described above — Google, Microsoft, and Meta — are based in the United States, and the app-usage information they receive is processed there. Where that happens, we take reasonable steps to ensure it is handled consistently with the APPs.
Accessing, correcting, and complaining
You can view and update most of your details in the app’s Settings at any time. You may request access to, or correction of, the personal information we hold about you, and you may make a privacy complaint. We will respond within a reasonable time. If you are not satisfied, you may contact the Office of the Australian Information Commissioner (OAIC).
Deleting your profile
You can delete your profile yourself, at any time, from the bottom of your profile screen. Deletion happens straight away — there is no waiting period and no undo. Once you confirm, we cannot bring your profile back.
If you haven’t connected with any employers
Everything goes: your profile and your answers, your saved roles, your photo, your match results, any invitations you hadn’t accepted, and your sign-in account are all permanently deleted, and nothing about you remains. You can sign up again later with the same email address; you would start with a fresh profile.
If you have connected with employers
Each employer you connected with keeps their record of that application. We do not delete it — but it is no longer connected to you.
They keep: the status of your application and the dates it moved through their process; their own notes and events about it; the messages exchanged between you; and the application and screening content you provided — your interests, motivations, preferences, deal-breakers, the work environments you chose, and your licence and transport answers.
Your identity is destroyed: your name and contact details, your location, your age group, your school level, your stage, your photo, the optional background information you gave us, and your sign-in account are all removed, and the record can no longer be linked back to you. Employers see it marked as withdrawn, with no name attached.
Removed either way
Whichever applies to you, we always delete the optional background information you gave us, your stored photo, anything you wrote about yourself, your saved roles, your sign-in account, and every analytics event we recorded about you.
Backups
Your data is removed from our systems straight away. Backup copies age out on our backup cycle — we can't delete individual records from a backup.
Why we keep an anonymised record
Australian privacy law (Australian Privacy Principle 11.2) allows us to de-identify personal information as an alternative to destroying it. When you have applied to a role, that employer genuinely received your application, and their record of it is a business record. De-identifying it means the record survives without you being identifiable in it. Other Australian job platforms take the same approach.