Privacy
Written to be accurate about what the software actually does, by the person who wrote the software. It has not yet been checked by a solicitor, and it will be before the service takes anybody who is not a friend of ours.
Who we are
contact4me is run by Ian Pearl, in the United Kingdom. We are the data controller: we decide what is held and why, and we are the people to complain to.
Write to admin@contact4.me. It is a real mailbox and a person reads it.
While this is a trial
contact4me is being tested with a small group. Two things follow from that, and it is fairer to say them here than to let you find out:
- Data may be deleted without warning. If we have to rebuild something during testing, accounts may go with it. Do not treat this as the only record of anything.
- Do not rely on it in a real emergency. It is not yet proved, and parts of it still run on ordinary equipment rather than anything built for the job.
What we hold about you
- Your email address, mobile number and the name you chose to appear on your messages.
- Your password and PIN, stored as one-way hashes. Neither can be recovered, including by us.
- The people on your list: the label you gave them, their mobile number, and their code word.
- The messages you wrote.
Everything in that list except the hashes is encrypted where it is stored. Mobile numbers are never held in a searchable index — lookups go through a keyed hash, so possessing our database does not reveal who has an account.
We hold it to give you the account you asked for. In legal terms that is performance of a contract with you, and you can end it at any time by asking us to delete the account.
If you only joined the waiting list
We hold your email address, encrypted, and whatever you wrote in the note. Nothing else — there is no account and no phone number. We email you once to say you are on the list, and once more when it opens. Ask us at admin@contact4.me and you are off it the same day.
If somebody added you to their list
You never came here, never agreed to anything, and got a text from a service you had not heard of. This section is for you, and it is the part the law is most particular about.
How we got your number. Somebody who knows you typed it in. They chose you as a person they would want reached if they lost their phone and needed help. We did not buy your number, find it, or get it from anywhere else.
What we hold about you, and it is deliberately almost nothing:
- Your mobile number, encrypted.
- A label — usually a first name, and whatever they call you.
- A code word, so that if a message does come you can tell it is really from them and not a scam.
- Whether you have asked us to stop.
No surname, no address, no email, no date of birth, nothing about you beyond those. We never sell or share any of it, there is no advertising anywhere on this site, and there is no tracking of any kind.
Why we are allowed to. Our lawful basis is legitimate interests. We cannot ask your permission first, because the only way to reach you is the number we would be asking about, and the person who added you cannot give us your permission on your behalf. So we have weighed it up instead: the interest is that somebody who cares about you can reach you when they are in trouble, we hold the least we can, we tell you at the point of being added, and you can be gone in one word. If we ever do send you an emergency message, we also rely on protecting someone’s vital interests, which is what that moment actually is.
When we would text you. Twice at most, and never otherwise: once when you are added, so you are not surprised later, and again only if the person who added you asks us to. No marketing, ever.
Getting off the list. Reply UNSUBSCRIBE to any text from us. It takes effect immediately and permanently, and we tell the person who added you so they can find somebody else rather than quietly relying on a contact who has gone. You do not have to give a reason, and you do not have to email anybody.
Finding out what we hold. Email admin@contact4.me with the mobile number and, if you have one, the reference from the bottom of the text. We will text that number a short code first, because handing somebody’s details to whoever asks for them would be a worse failure than not answering. Once you have sent the code back we will tell you what is held and who added you, within a month and without charging you.
Your rights, whichever of the two you are
You can ask us to show you what we hold, correct it, delete it, restrict what we do with it, or hand it over in a portable form. Where we rely on legitimate interests — which is everybody in the section above — you can also object, and for a contact list the practical form of that is UNSUBSCRIBE, which we act on immediately and without asking why.
We answer within one month and we do not charge. If we get it wrong, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you told us first, but you do not have to.
How long we keep things
| What | How long |
|---|---|
| Your account, your list, your messages | Until you ask us to delete it |
| A contact’s number and label | Until they unsubscribe or the account goes |
| The reference that proves a text was genuine | With the account, so an old message stays checkable |
| Our event log — times and kinds, no names or numbers | 13 months |
| Server logs, which include the address you connected from | 30 days |
| Where you were when you sent a message | Not kept at all — it goes into the message and nowhere else |
Where you are
A location is only ever collected at the moment you send a message that asks for one, and only if your browser asks you and you agree. It goes into that message and is not stored afterwards.
The scam check
When someone checks a message on contact4.me/scamcheck we compare the number they type against a keyed hash of the number we sent to. We do not store the number they typed.
Deleting your account
Ask us and we will delete it. That removes your details, your list, their numbers, your messages and your history. The event log survives, but by then it refers to nobody, and it expires on its own in any case.
How it is kept safe
Plainly, so you can judge it rather than take our word for it:
- Passwords and PINs are hashed with argon2id. They cannot be recovered, by us or by anyone who takes the database.
- Everything else identifying is encrypted where it is stored — your email, your number, your contacts' names and numbers, their code words, and the messages you wrote.
- Phone numbers are not in any searchable index. Lookups go through a keyed hash, so a stolen copy of the database will not tell anyone which numbers have accounts.
- The emergency sign-in can only send. It cannot read a number, change your account, or add anyone. Someone who guessed your PIN could send a message to your own contacts and nothing more.
- Nothing is left on a borrowed device. The session ends with the browser, pages are never cached, and finishing clears what we can.
- Everything travels over HTTPS, and the site is behind a firewall that rate-limits abuse.
The honest limit: a six-digit PIN is not much, and it cannot be given a second factor, because you would be signing in precisely when you have lost the phone a code would go to. We compensate by strictly limiting attempts and by making sure there is very little to steal even if someone gets in.
Who else sees it
Three others, and no more:
- Amazon Web Services hold the database and run the site, in their London region. Nothing is stored outside the UK.
- A mobile network carries every text, and necessarily sees the number and the words. That is unavoidable: it is a telephone network.
- Fastmail carry our email — sign-up confirmations and password resets, so an email address and nothing else. They are an Australian company and may handle it outside the UK, under the standard contract clauses the law provides for exactly that.
We do not sell anything to anyone, and there is no advertising or tracking on this site.