Last updated: August 11, 2026
The key privacy guarantees and data-handling points for CNTC.
CNTC shares only the contact fields you select. Contact Notes are excluded by default.
Shared list contents are stored and synchronized through Apple Core Data and CloudKit, not the CNTC website database.
Feedback is sent only when you submit it, and you can exclude limited device diagnostics.
CNTC does not use advertising SDKs or cross-app tracking.
CNTC helps people create and collaborate on contact lists while controlling which contact details are visible to participants. This policy explains how the app and website handle information.
CNTC requests access to Apple Contacts so you can select people, connect a shared entry to its source contact, import shared details, and keep selected fields current. Depending on your iOS version and choice, access may cover all contacts or only contacts you select.
The app stores operational data locally, including lists, selected fields, local contact mappings, synchronization state, preferences, and purchase entitlement state. Deleting the app removes local app data, subject to data that Apple retains in iCloud or in backups under your Apple Account settings.
CNTC uses Apple Core Data, CloudKit, and CKShare to store and synchronize shared lists. Altai’s CNTC web servers do not receive or store the contents of your lists or address book.
When an owner chooses a CNTC invitation link, the website stores the list title, the owner's short or customized invitation name, the invitation type and permission, and an encrypted Apple CloudKit invitation target. This minimal preview information is visible to anyone who has the unguessable invitation URL. It does not include contacts, list members, photos, phone numbers, email addresses, or other list contents.
Participants may see only the fields included in a shared entry. Names are required for a usable entry. Other fields, including photos, phone numbers, email addresses, dates, relationships, online profiles, and notes, depend on the owner’s selections. Contact Notes are excluded by default because they may contain private information.
When you share someone else’s contact details, you are responsible for having an appropriate reason or permission to do so. Participants can copy or import information they are allowed to view.
Apple processes iCloud and CloudKit data under Apple’s terms and privacy policy. CNTC cannot access another person’s private iCloud account.
When you submit a bug report, feature request, or other feedback, CNTC sends:
You can turn diagnostics off before submitting. CNTC does not attach contacts, list names, CloudKit record identifiers, invitation links, purchase identifiers, or shared-list content.
Do not include passwords, payment information, private contact details, invitation links, or other sensitive information in free-text reports.
The public website uses essential technical storage needed for security and normal Laravel operation. The private administration area uses authentication and session cookies. CNTC does not use advertising cookies or third-party analytics SDKs.
Operational logs may record request times, routes, error details, and security events. App Attest public keys, counters, and report records are kept as needed to prevent replay, investigate reports, maintain security, and meet legal obligations.
CNTC suppresses invitation tokens and encrypted CloudKit targets from application and web-server logs. Invitation pages do not use third-party analytics and instruct browsers and search engines not to retain or index them. Services that create link previews, such as messaging apps, may independently cache a preview after receiving a link.
Reports and their review history are retained only while useful for product support, abuse prevention, security, and legal obligations. To request access to or deletion of a report you submitted, email privacy@cntc.app. Include the report ID if available. We may need enough information to locate the report and verify the request without exposing another person’s data.
Shared-list deletion and participant access are controlled in CNTC and through Apple iCloud. Removing a participant or stopping sharing affects future CloudKit access but cannot erase copies someone already imported or saved.
Individual invitation records are deleted after revocation or reconciliation. Stable anyone-with-link and access-request records may be retained while disabled so the same URL can be restored; deleting the list removes its invitation records. Encrypted backups may retain deleted records temporarily under normal backup rotation.
CNTC is not directed to children under the minimum age required to manage an Apple Account in their region. The app may be used internationally, and Apple may process iCloud data in locations described by Apple.
We may update this policy as CNTC changes. The current version and effective date are published on this page.
Privacy questions: privacy@cntc.app Support: support@cntc.app