Privacy
Privacy policy
Crowdbook is zero-knowledge by design, so this policy has an unusually short list of data we can actually access. The summary below is accurate; the full legal text still needs review before launch.
Last updated: July 2026
The short version
- • Your contact details are encrypted on your device before upload; we store only ciphertext we cannot read.
- • Each connection only ever receivea the attributes you explicitly choose to share.
- • Your password never reaches us; login is a signed challenge.
- • Delete your account and your keys, blobs, and shared attributes are purged and tombstoned for peers.
1. Information we collect
Account information. Your email address, a one-way authentication hash derived from your password, and the public halves of your device keys. We do not receive or store your password.
Encrypted content. The attributes you share into groups, received only as ciphertext produced on your device, plus wrapped group keys we cannot unwrap. We cannot read any of this.
Operational metadata. Group membership, version counters, and audit records needed to route updates, along with standard server logs.
2. What we do not collect
Crowdbook never reads your device's private address book for any purpose other than synchronizing data. What is read does not leave the application. Your plaintext contacts, your password, or your private keys never leave your device and are never seen by our servers. We do not sell personal data. Our application does not show ads or participate in any advertising networks.
3. How we use information
To operate the sync service, authenticate you, route encrypted updates between members, and maintain the security and integrity of the service.
4. Sharing and disclosure
Because we hold only ciphertext, a lawful request can compel only encrypted blobs we cannot decrypt.
5. Data retention and deletion
You can delete your account at any time. On deletion, your device key material and encrypted blobs are purged, your key wrapping is revoked, and your shared attributes are tombstoned so other members' devices drop them. All information is removed from our servers. We are not responsible for any data that you share with other users. You understand that, while the Crowdbook application can and will remove all records that it controls, including those in other user's address books, other users can backup or otherwise copy your information that you have voluntarily shared with them.
6. Your rights (GDPR / CCPA)
Data minimization is built into the product: only explicitly shared attributes are ever synced. You have complete control of your data, what is shared, and to whom it is shared.
7. Children's privacy
Our Services are not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. The only personal information that we collect in a form that we can actually access for ANY user is an e-mail address.
If we learn that we have collected personal information from a child under 13 without verified parental consent, we will take reasonable steps to delete that information as soon as practicable. If you believe that a child has provided personal information to us, please contact us at support@crowdbook.net. or through the contact page
Users who upload, import, synchronize, or otherwise provide contact information are responsible for ensuring that they have the authority and any necessary permissions to do so. We do not knowingly use contact information supplied through the Service to market directly to children or any users.
8. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other operational reasons. When we do, we will post the updated Privacy Policy in the Service and revise the “Last Updated” date at the top of the policy.
If we make a material change to how we collect, use, disclose, store, or otherwise process personal information, we will provide additional notice before the change takes effect, such as through the app, on our website, by email, or by another reasonable method.
Where required by applicable law, we will obtain your consent before applying a material change to your personal information. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after an updated Privacy Policy takes effect means that you acknowledge the updated policy, to the extent permitted by applicable law.
9. Contact
Questions about privacy? Reach us through the contact page.