Privacy Policy

Last updated: May 9, 2026

This policy describes what data ContactHoney ("we", "the app", "the service") collects from you, how it is used, where it is stored, and the choices you have. It applies to the ContactHoney mobile apps (Android and iOS), the ContactHoney web app at app.contacthoney.com, and the ContactHoney desktop installer for Windows.

1. What ContactHoney is

ContactHoney is a personal contact-management and CRM application. You use it to keep track of people you know, your email correspondence with them, scheduled events, sales-pipeline deals, and phone-call history. All of this data is yours; ContactHoney is the tool you use to organize it.

2. Data we collect

We collect only the data you give us, plus the minimum needed to operate your account. Specifically:

  • Account information — first and last name, login (a username you choose), email address, phone number, and a password (stored as a salted, bcrypt-hashed value, never in plain text).
  • Contact records you create or import — names, email addresses, phone numbers, postal addresses, notes, dates (birthdays, anniversaries), and any custom fields you add.
  • Email-account credentials, if you connect a mailbox — IMAP/SMTP server settings, username, and password. Mailbox passwords are encrypted at rest in our database. If you connect a Google account via OAuth, we store only the OAuth refresh token; we never see your Google password.
  • Email message data, if you connect a mailbox — ContactHoney fetches and caches message headers and bodies on our server so you can search and read them inside the app. Attachment metadata (filename, type, size) is cached; attachment binaries are fetched on demand from your mail server. This cache lives in your private database and is not shared with other ContactHoney users.
  • Calendar events you create inside ContactHoney, or that flow back and forth from a connected Google Calendar.
  • Deals / sales-pipeline data you enter (deal name, value, stage, associated contacts, notes).
  • Activities, tasks, and phone-call notes you log inside ContactHoney. The app does not access your device's call log or contacts list.
  • Preferences — UI settings such as font size and theme, so the app remembers them.
  • Session and security data — IP address (recorded at login), session timestamps, and an approximate geographic region derived from the IP (city / country) for the operator's security monitoring of active sessions. Used to detect suspicious access and to expire idle sessions; not used for analytics, advertising, or personalization.
  • Cookies and similar tokens — a session cookie keeps you signed in. If you enable multi-factor authentication and check "trust this device," we set a separate 30-day cookie (ch_trust) so you don't re-prompt for the second factor on that device. No analytics, advertising, or third-party tracking cookies are used.
  • Subscription and billing records, if you have a paid plan — we store the Stripe customer ID, subscription status, and a record of past invoices (amount, currency, date). We do not store credit-card numbers, CVV, or expiration dates; those are handled directly by Stripe. See "Sharing with third parties" below.

The mobile app requests only the INTERNET permission. It does not access your device's contacts, SMS, call log, GPS, microphone, camera, or photo library. It does not collect device identifiers (Advertising ID, IMEI, MAC address, or similar). It does not include any third-party analytics or crash-reporting SDK; the only diagnostic data Apple and Google receive is what those platforms automatically collect from any app on a user's device.

3. How we use your data

We use the data above solely to provide ContactHoney's features to you: storing your records, syncing your email, displaying your calendar, processing your subscription, securing your account, and responding to support requests. We do not use your data to train AI or machine-learning models. We do not sell your data. We do not share your data with advertisers, data brokers, or any third party for marketing purposes.

4. Where your data is stored

Your data is stored in MySQL on our server in the United States. Each ContactHoney user has an isolated per-user database; other users cannot read your records. All traffic between your device and our server is encrypted in transit using HTTPS (TLS). Specific high-sensitivity fields — connected-mailbox passwords, OAuth tokens, MFA secrets, and trusted-device tokens — are encrypted or hashed at rest in addition to disk-level server protections.

5. Sharing with third parties (sub-processors)

We share data with a small set of service providers necessary to operate ContactHoney. We do not share your data for any other purpose unless you direct us to or we are legally compelled to.

  • Stripe — payment processing and subscription management. Stripe receives your name, email, and payment-method details directly when you check out. We receive only an opaque customer ID and subscription status from Stripe.
  • Vultr — server hosting (United States). Vultr stores the database and runs the application servers under standard data-handling commitments and does not access your data in the ordinary course of business.
  • freeipapi.com — IP-to-region lookup. When you log in, we send your IP address to freeipapi.com to obtain a coarse geographic region (country / city) used for operator security monitoring. freeipapi.com receives only the IP address; no other data.
  • Email providers you choose to connect — if you connect a Gmail, Outlook, or other IMAP/SMTP account, ContactHoney communicates with that provider on your behalf, governed by the provider's own privacy policy.
  • Apple and Google — for app distribution. The platforms automatically collect their own diagnostic and crash data when a user opts in to "share with developers" at the OS level; ContactHoney does not initiate or expand that collection.
  • Legal compliance — if we are compelled by valid legal process (subpoena, court order) we will comply, and we will notify you unless legally prohibited.

6. Your choices and rights

  • Access and export. You can view and export your contact, email, calendar, and deal data from inside the app at any time.
  • Correction. You can edit or delete any individual record from inside the app.
  • Account deletion. You can permanently delete your entire account from inside the app: Account → Advanced → Delete data or account. The flow re-confirms your password, cancels any active subscription with Stripe, removes your user record, your contact database, cached email content, mailbox credentials, MFA credentials, and trusted-device tokens. If you cannot reach the in-app option (for example, a forgotten password), email us at the address below and we will delete your data on confirmation. Backup copies are purged on the normal backup-rotation cycle (no longer than 90 days). Stripe billing records are retained per Stripe's own policy as required for tax and accounting compliance.
  • Disconnecting a mailbox. You can disconnect a connected email account from inside the app, which removes the stored credentials immediately. Cached message data from that account is removed within 24 hours.
  • EEA / UK / California rights. If you are in the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR / UK GDPR / CCPA-CPRA, including the right to object to processing, the right to data portability, and the right to lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at the address below.

7. Data retention

We retain your account information and customer data for as long as your account is active. After you delete your account (in-app or by request), your data is removed within 30 days across all live systems and within 90 days from backup-rotation cycles. Stripe billing records are retained per Stripe's own policy as required for tax and accounting compliance (typically up to 7 years).

8. Children's privacy

ContactHoney is intended for adults. The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

9. Changes to this policy

If we materially change how we handle your data, we will update this page and the "Last updated" date at the top. For substantial changes (for example, sharing with a new category of third party) we will notify you by email or via the app before the change takes effect.

10. Contact

Questions, deletion requests, or privacy concerns: [email protected].

ContactHoney is operated by Norm Strassner.