Last updated: September 20, 2026
Key facts about where data lives and the limited information CNTC’s web services process.
CNTC uses the Apple Account already signed in to iCloud. You do not create a separate CNTC username, password, or account.
Shared contact entries and selected fields are stored on your devices and synchronized through Apple iCloud. CNTC’s website does not receive them.
Select fields contact by contact. CNTC does not request access to Contact Notes, so they are never read or shared.
CNTC stores limited data for invitations, security, and optional notifications. Optional report threads are normally scheduled for deletion 90 days after their latest message.
CNTC helps people create and collaborate on contact lists while controlling which contact details are visible to participants. This policy explains how the app and website handle information.
CNTC uses the Apple Account already signed in to iCloud on your compatible device. You do not create a separate CNTC username, password, or account.
CNTC requests access to Apple Contacts so you can select people, connect a shared entry to its source contact, import shared details, and keep selected fields current. Depending on your iOS version and choice, access may cover all contacts or only contacts you select.
The app stores operational data locally, including lists, selected fields, local contact mappings, synchronization state, preferences, and purchase entitlement state. Deleting the app removes local app data, subject to data that Apple retains in iCloud or in backups under your Apple Account settings.
CNTC uses Apple iCloud to store and synchronize shared lists. CNTC’s web services do not receive or store your address book, shared contact entries, or the contact fields selected for sharing.
When an owner creates a CNTC invitation link, the website stores the list title, the owner’s optional customized display name (or a generic CNTC label), the invitation type and permission, and an encrypted reference to the Apple iCloud invitation. This minimal preview information is visible to anyone who has the invitation URL. It does not include contacts, list members, photos, phone numbers, email addresses, or other list contents. CNTC may use an iCloud short name temporarily inside Apple’s invitation sheet, but does not send or store that iCloud name on the CNTC website.
To authenticate invitation changes and identify participant activity across a person’s devices, CNTC creates a random sharing-profile identifier and secret. The credential is stored in the person’s private iCloud storage. CNTC’s web service stores the random identifier, a one-way hash of the secret, a generic or optional customized display name, and internal associations between the profile, shared list, and participant. This information does not reveal the person’s Apple Account or the contents of the shared list.
Participants may see only the fields included in a shared entry. Names are required for a usable entry. Other fields, including photos, phone numbers, email addresses, dates, relationships, and online profiles, depend on the owner’s selections.
CNTC does not request permission to access Contact Notes. The app cannot read them and does not store, index, synchronize, or share them.
You choose the recipients and fields included in a shared list. Use reasonable care when sharing another person’s information, especially when a field is sensitive or private. Participants can copy or import information they are allowed to view.
Apple processes iCloud data under Apple’s iCloud terms and privacy policy. CNTC cannot access another person’s private iCloud account.
CNTC adds lists and shared contacts to the iOS system search index. The index may include list names and contact details visible in CNTC, such as names, selected phone numbers and email addresses, photos, and other selected searchable values. The index stays on the device; CNTC’s web services do not receive it, and CNTC does not synchronize it to the person’s other devices. You can control whether CNTC content appears in system search from iOS Settings.
If you allow sharing notifications, CNTC stores information needed to route them, including an encrypted Apple notification token, the app locale, and internal identifiers that associate the app installation with a shared list and participant. These identifiers do not contain the underlying iCloud record identifier or invitation URL.
A sharing notification may identify the type of event, the list title, and an optional customized display name. CNTC does not put contacts, list contents, email addresses, phone numbers, photos, internal iCloud identifiers, or invitation URLs in notification payloads. Apple processes and delivers these notifications. You can disable notifications in iOS Settings.
When you submit a bug report, feature request, or other feedback, CNTC sends:
Images are resized, converted to JPEG, and stripped of location and other embedded metadata before sending. This does not remove private information visible in the image itself, so review and crop images before submitting them. You can omit contact email and images and turn diagnostics off before submitting. CNTC does not automatically attach contacts, list names, internal iCloud identifiers, invitation links, purchase identifiers, or shared-list content.
Reports are delivered to CNTC support through Google Workspace. CNTC’s website does not keep a report-content database or persist image uploads. Google processes the resulting support email and conversation under its applicable terms and privacy commitments.
Do not include passwords, payment information, private contact details, invitation links, or other sensitive information in report text or images.
The public website uses essential technical storage needed for security and normal operation. The private administration area uses authentication and session cookies. CNTC does not use advertising cookies or third-party analytics SDKs.
Operational logs may record request times, requested pages or API routes, delivery status, error details, and security events, but CNTC suppresses report text, contact email, diagnostics, and image data from application monitoring. App-verification credentials, counters, installation records, and related security information are kept as needed to authenticate app requests, prevent duplicate or forged requests, maintain sharing services, and meet legal obligations.
On Apple-silicon Macs, where Apple's standard device-integrity service is unavailable to an iPad app, CNTC uses an Apple-signed app transaction and device-verification value to enroll a device-only Secure Enclave installation key. CNTC validates those values but retains only one-way hashes of their identifiers, the public installation key, counters, and related security status. Raw signed transactions and device-verification identifiers are not retained or included in application monitoring.
CNTC suppresses invitation tokens and encrypted iCloud invitation references from application and web-server logs. Invitation pages do not use third-party analytics and instruct browsers and search engines not to retain or index them. Services that create link previews, such as messaging apps, may independently cache a preview after receiving a link.
Support report threads are scheduled for permanent deletion 90 days after their latest message. A report may be retained longer when it remains unresolved or is useful for support, product improvement, abuse prevention, security, or legal obligations. Once that reason ends, it returns to the normal deletion schedule. Google Workspace backup, legal-hold, or compliance systems may retain limited copies where required by their configuration or law.
Pseudonymous sharing profiles and their list or participant associations are retained while needed to authenticate invitations, display a chosen name, deliver enabled notifications, maintain service integrity, and prevent abuse.
To request access to or deletion of information stored by CNTC’s web services, email privacy@cntc.app. Because CNTC does not require an account, we may need enough information to locate and verify the relevant records without exposing another person’s data.
Shared-list deletion and participant access are controlled in CNTC and through Apple iCloud. Removing a participant or stopping sharing affects future access through iCloud but cannot erase copies someone already imported or saved.
Individual invitation records are deleted after revocation or reconciliation. Stable anyone-with-link and access-request records may be retained while disabled so the same URL can be restored; deleting the list removes its invitation records. Encrypted backups may retain deleted records temporarily under normal backup rotation.
Notification subscriptions are removed when the related access or sharing state ends. A device registration may remain while notifications are enabled and is disabled when Apple reports that its notification token is no longer valid. You can also disable notification delivery in iOS Settings.
The app may be used internationally, and Apple may process iCloud data in locations described by Apple.
We may update this policy as CNTC changes. The current version and effective date are published on this page.
Privacy questions: privacy@cntc.app Support: support@cntc.app