Privacy
Privacy policy
Crowdbook is zero-knowledge by design, so this policy has an unusually short list of data we can actually access. The summary below is accurate; the full legal text still needs review before launch.
Last updated: July 2026
The short version
- • Your contact details are encrypted on your device before upload; we store only ciphertext we cannot read.
- • We only ever receive attributes you explicitly choose to share into a group.
- • Your password never reaches us — login is a signed challenge.
- • Delete your account and your keys, blobs, and shared attributes are purged and tombstoned for peers.
Note: The sections below are a structured draft. The plain-language data summary reflects how Crowdbook actually works, but the formal legal language is placeholder and must be reviewed by counsel before the app is released.
1. Information we collect
Account information. Your email address, a one-way authentication hash derived from your password, and the public halves of your device keys. We do not receive or store your password.
Encrypted content. The attributes you share into groups, received only as ciphertext produced on your device, plus wrapped group keys we cannot unwrap. We cannot read any of this.
Operational metadata. Group membership, version counters, and audit records needed to route updates, along with standard server logs. [Placeholder — enumerate exact log fields and retention.]
2. What we do not collect
Crowdbook never reads your device's private address book. We do not have access to your plaintext contacts, your password, or your private keys in usable form. We do not sell personal data. [Placeholder — confirm final advertising / analytics stance.]
3. How we use information
[Placeholder] To operate the sync service, authenticate you, route encrypted updates between group members, and maintain the security and integrity of the service. Lorem ipsum dolor sit amet, consectetur adipiscing elit.
4. Sharing and disclosure
[Placeholder] Because we hold only ciphertext, a lawful request can compel only encrypted blobs we cannot decrypt. Describe subprocessors (e.g. cloud hosting), legal-process handling, and any transparency reporting here.
5. Data retention and deletion
You can delete your account at any time. On deletion, your device key material and encrypted blobs are purged, your group key wrapping is revoked, and your shared attributes are tombstoned so other members' devices drop them. [Placeholder — state backup/log retention windows.]
6. Your rights (GDPR / CCPA)
[Placeholder] Data minimization is built into the product: only explicitly shared attributes are ever synced. Detail here the rights to access, correct, delete, and port data, and how to exercise them.
7. Children's privacy
[Placeholder — state minimum age and handling.]
8. Changes to this policy
[Placeholder] We'll post changes here and update the date above.
9. Contact
Questions about privacy? Reach us through the contact page.