Privacy
Last updated July 2026. Plain-language summary of how warm.contact handles data. This is a starting draft, not legal advice.
The short version
The details people submit to you are end-to-end encrypted in their browser before they reach us. We cannot read them. They are decrypted only on your own device and land in your own Apple Contacts — which we never hold a copy of.
What we can see
- Account data: your email and your chosen handle.
- Encrypted submissions: opaque ciphertext we cannot decrypt, held briefly and deleted once your device confirms receipt.
- Metadata: IP addresses, timestamps, destination handle, and volume. We are honest that this is visible to us even though contents are not.
- Your published card: the contact details you choose to put in your own profile are data you are broadcasting, and are stored so we can serve your page.
- Aggregate counts: page views, submissions, signups — numbers only, never tied to a person.
What we do not do
- Read the contents of submissions (we structurally cannot).
- Store, sell, enrich, or profile your address book. The real store is your Mac's Contacts.
- Track you across the web or run advertising.
Third parties
- Resend — sends verification codes and receipts by email.
- Hosting — our relay runs on standard cloud infrastructure.
Your data — export & deletion
From your dashboard you can export everything we hold about your account (as JSON) and delete your account outright. Deletion removes your account record, your handle, your device keys, and any queued ciphertext. Submission contents were never readable to us; contacts already written to your address book live in Apple Contacts and are yours to manage.
Questions or abuse reports: hello@warm.contact · warm.contact