QontaqtBack home

Legal · Qontaqt

Privacy Policyclear, careful, human.

How we collect, use, and protect your data — written for the people who actually use the product.

Your data

Privacy Policy

This Privacy Policy describes how Qontaqt handles personal data in the mobile and web products at qontaqt.me.

01

Who we are

Qontaqt (“we”, “us”, “our”) provides AI-assisted contact capture, networking, and event tools through our mobile application (com.qontaqt.app) and website at qontaqt.me. This Privacy Policy explains what personal data we collect, why we process it, how we share it with service providers, and the rights available to you under applicable law — including the UAE Personal Data Protection Law (PDPL) and, where it applies, the EU/UK GDPR. For privacy questions, contact us at privacy@qontaqt.me. For general support, use hello@qontaqt.me.

02

Scope

This Policy applies when you use: • the Qontaqt iOS or Android app; • the Qontaqt web app at qontaqt.me; and • related features such as public digital cards and event links hosted on qontaqt.me. It does not cover third-party websites or apps that we merely link to (for example WhatsApp, Google Calendar, or your device share sheet), which have their own privacy practices.

03

Data we collect

We collect the categories of data below only as needed to operate Qontaqt. Account & profile • Phone number used to sign in (mobile app uses phone OTP; the interface presents this as WhatsApp verification) • Full name • Profile photo (optional) • Preferred UI language and appearance settings stored on your device • On the web app, email address and password or email magic-link credentials if you choose those sign-in methods • Subscription tier and related account metadata Contacts you create or capture • Names, job title, company, industry, and notes • Phone numbers (including WhatsApp numbers), emails, website, and social links • Address / city / country • Relationship type, temperature, follow-up date and note • Capture method (for example camera, QR, voice, text, or upload) • Contact photo and business-card image • AI-generated structure/tags and confidence signals derived from your capture Events & networking • Events you create or join (name, dates, venue/city, description, cover image, capacity, and related settings) • Registration / attendance records • Check-ins (time, method, and a coarse device label such as ios, android, or web) • Exhibitor details you add (company and contact details) Digital cards • Card profile fields you publish (name, title, company, phone, email, LinkedIn, public slug) • Public card pages at https://qontaqt.me/card/{slug} when you enable a public card Voice & media • Voice recordings you capture for contact extraction • Photos or PDFs of business cards and QR images you scan or upload • Temporary files created on your device when exporting contacts Authentication & security • One-time verification codes associated with your phone number (stored as a secure hash with expiry and attempt limits) Local device data • Theme, language, recent searches, notification read state, and links between Qontaqt contacts and native address-book entries (SharedPreferences) • Locally scheduled follow-up reminder notifications We do not use advertising identifiers, Firebase Analytics, Crashlytics, Sentry, Mixpanel, Amplitude, or similar product-analytics SDKs in the mobile app.

04

How we collect data

• Directly from you when you register, edit your profile, create contacts, manage events, or publish a digital card • Through device permissions you grant (camera, microphone, photo library, contacts, and notifications) • From AI processing of media or text you submit for contact extraction • From other users when they check in to events you host, register for events, or import a public digital card you shared • Automatically from the app/backend for session authentication and operational security (for example OTP attempt tracking)

05

Device permissions

Qontaqt requests the following permissions only when you use the related feature. We explain why in the app before the system dialog on iOS and Android: • Camera — photograph business cards and scan event QR codes so AI can extract contact details and you can check in. The camera is not used in the background. • Photo library / gallery — only when you pick a photo or file (saved business card, QR screenshot, profile or company photo). We do not browse your full library; only items you select are used. • Microphone — only when you tap Voice, to record a short note so AI can turn a spoken introduction into a contact. Recording starts and stops with your action. • Contacts (read/write) — only when you tap Save to phone, to add that contact to your address book and check for duplicates by phone or email. We do not bulk-import your entire address book into Qontaqt. • Notifications — schedule local follow-up reminders on your device • Exact alarms / boot receivers (Android) — restore scheduled local reminders after reboot We do not request location permission or App Tracking Transparency / advertising tracking permission. You can revoke permissions in your device settings; some features will then be unavailable.

06

Why we process your data

We process personal data to: • create and secure your account (phone OTP verification and session management); • provide core product features (contact capture, AI structuring, events, check-in, digital cards, follow-ups); • store and sync your data across devices via our backend; • export contacts on your request (PDF, CSV, or vCard generated on-device and shared through the system share sheet); • open system actions you choose (phone, email, WhatsApp wa.me links, Google Calendar web templates); • send local reminder notifications you configure; • review and act on account-deletion requests; • maintain security, prevent abuse of OTP endpoints, and operate the service; • comply with legal obligations applicable to us. Legal bases (where GDPR applies) include performance of a contract, legitimate interests in operating and securing the service, consent for optional permissions/features, and legal obligation. Under UAE PDPL we process data for the stated purposes above and as otherwise permitted by law.

07

AI processing

When you use AI capture (photo, QR, voice, or text), relevant content is sent to our backend processor, which calls Anthropic Claude APIs (and a speech-to-text provider for voice) to extract structured contact fields. That may include images of business cards, voice audio, and free-text notes. The purpose is solely to populate or suggest contact records for you. Do not submit content you are not entitled to process. AI outputs can be imperfect; you remain responsible for reviewing contact details before relying on them.

08

How we share data

We do not sell your personal information. We share data only with: • Supabase — authentication, database, file storage, and edge functions that power Qontaqt • Anthropic — AI extraction for captures you initiate • Speech-to-text provider — voice capture transcription only • Other Qontaqt users — when you publish a public digital card, host a public/shared event, or otherwise make information available through product features • Device / OS services you invoke — contacts app, share sheet, WhatsApp, phone/email apps, Google Calendar in the browser • Professional advisers or authorities when required by law Service providers process data under instructions and for the purposes described in this Policy.

09

Storage locations

• Cloud: account, contacts, events, digital cards, media URLs, OTP records, and deletion requests are stored in our Supabase project • File storage buckets: profile avatars, contact photos / card images, event covers, and voice audio associated with captures • On your device: session tokens managed by the Supabase client, SharedPreferences settings described above, temporary export files, and local notification schedules Some providers may process data outside the UAE (including in the United States or other regions). Where required, we rely on appropriate transfer safeguards and contractual protections offered by those providers.

10

Retention

• Account and product data are retained while your account is active and as needed to provide the service • OTP records are short-lived (expiry and one-time use controls) • Local preferences remain on your device until you clear app data or uninstall • When an account-deletion request is approved, we mark the account as deleted (users.deleted_at). Residual backups or legal holds may persist for a limited period as required for security, dispute resolution, or law If you need a specific retention question answered for your account, email privacy@qontaqt.me.

11

Your rights

Subject to applicable law (including UAE PDPL and GDPR where applicable), you may have the right to: • access the personal data we hold about you; • correct inaccurate data (you can edit profile and contacts in the app); • export your contacts (PDF, CSV, or vCard from Settings); • withdraw optional permissions on your device; • object to or restrict certain processing where the law allows; • request deletion of your account. Account deletion in Qontaqt is available in Settings → Delete account. Submitting a request notifies our team; deletion is completed after administrative review and approval. You may cancel a pending request from Settings. After approval, the account is marked deleted and you will no longer be able to use it normally. To exercise rights, use in-app controls where available or email privacy@qontaqt.me. We may need to verify your request.

12

Security

We protect personal data using industry-standard measures appropriate to our stack, including: • authenticated API access and row-level controls in Supabase; • hashed OTP codes with expiry and attempt limits; • encrypted transport (HTTPS) between the apps and our backend; • limited access for operational administration. No method of transmission or storage is completely secure. Please protect your device and sign-out on shared devices.

13

Children’s privacy

Qontaqt is designed for professional networking and business use. It is not directed to children under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@qontaqt.me and we will take appropriate steps.

14

International users

Qontaqt is offered with a UAE-oriented experience (including +971 as a default country code and English/Arabic interfaces) and may be used from other countries. By using the service you understand that your information may be processed in the UAE and in other countries where our providers operate.

15

Changes to this Policy

We may update this Privacy Policy to reflect product or legal changes. Material changes may be communicated in the app or by other reasonable means. Continued use after an update means you acknowledge the revised Policy.

16

Contact

Privacy: privacy@qontaqt.me Support: hello@qontaqt.me Website: https://qontaqt.me If you are in the UAE or EEA/UK and have an unresolved concern, you may also have the right to lodge a complaint with your local data-protection authority.

Questions? hello@qontaqt.me · Delete account