← Back
Privacy Policy
Kontome · Effective 28 August 2026 · Last updated 28 August 2026
The short version. Your phone number and your posts are the only things of substance we hold. Your posts go to the friends you accepted and nobody else. Your number is encrypted and shown only to those friends. We do not run ads, do not sell or rent anything about you, do not track what you read, and do not know where you are. On a free account your content is permanently deleted after 20 days. When you delete something, it is gone — there is no copy to restore.
Who this is
Kontome is a private social platform — a service for sharing with people you actually know, rather than broadcasting to an audience. This policy covers the website, the installable web app, and the iOS and Android apps built from the same codebase.
For any privacy question, correction, or complaint, write to privacy@kontome.com.
What we collect
Your mobile number — required
Your verified mobile number is your account. There is no email address, username, or password. We store it encrypted, and separately store a keyed hash of it that is used for lookups, so the number itself never appears in a database index. The last four digits form part of your public name (for example sarah-4417) and are visible to anyone who can see that name.
What you choose to add
- A display name, which you pick and can change.
- Optionally a short bio, a profile photo, and a cover photo.
- What you post: text, photos, video, comments, replies, and reactions.
- Groups and events you create or join, and your RSVPs.
What the service records to work at all
- Sessions. One record per signed-in device, with a device label you can read and revoke at any time, and the times it was created and last used.
- Verification codes. Stored as a hash, never as the code, and deleted within 24 hours.
- Invitations you send. A keyed hash of the number, plus an encrypted copy so we can show you who you are still waiting on. Both are deleted when the invitation expires, 72 hours after you send it.
- Network addresses. Used to rate-limit abuse and stored only as a hash. We do not keep raw IP addresses, and we do not use them to infer your location.
- Notification subscriptions, if you turn on push notifications.
- Subscription records, if you pay for one. Card details are handled by the payment provider and never reach us.
- Security events, such as failed sign-in attempts, kept narrowly and only as long as needed to investigate abuse.
What we refuse to collect
These are not settings that default to off. There is nowhere in the system to put them.
- Your location. The app never asks for location permission, there is no coordinate field anywhere in the database, and every uploaded photo is re-encoded on arrival specifically to strip the GPS coordinates your camera writes into it.
- Your age, birthday, home address, gender, relationship status, employer, school, political affiliation, or religion. You are never asked, and there is no field for any of it.
- What you look at. We do not record which posts you viewed, how long you spent, or how far you scrolled. We count things like how many posts were made in a day; those counts carry no user identifier, and cannot be traced back to a person.
- Interest or advertising categories. No profile of you is built, because there is nothing here to sell it to.
- Your contacts. There is no address-book import, and the app never reads your contacts at all. When you invite somebody, your own messaging app opens with the invitation written and you choose the person there — inside the address book, which we never see. Not the number, not the name.
Who can see what
- Your posts, photos, comments, and reactions
- The friends you have accepted, and — for something posted to a group — the members of that group. Nothing you post is public, and nothing is visible to a search engine.
- Your phone number
- Accepted friends only. It is decrypted in exactly one place in the code, after the friendship has been confirmed.
- Your friend list
- Only you. Nobody can browse who you know, and there is no mutual-friends feature.
- Your public name, photo, and bio
- Anyone signed in who has your exact public name can view this minimal profile — not your posts, not your number, not your friends. There is no directory and no way to search for people, so in practice this means the people you have given your name to.
- Us
- Staff do not read your posts or messages as a matter of course, and there is no moderation queue that surfaces your content for review. Access happens only where it is operationally unavoidable — investigating a specific fault or a security incident — or where the law requires it.
How long we keep it
- Free accounts: your content is kept for 20 days and then permanently deleted. It is not archived, hidden, or recoverable.
- Paid accounts: your content is kept while the subscription is active. If it ends, the 20-day rule applies again immediately and anything older is deleted.
- Deleted means deleted. There is no bin, no grace period, and no restore. When you delete a post or your account, the rows and the files are removed, including from anywhere the content appeared for other people.
- Verification codes: 24 hours. Invitations: 72 hours. Both are then deleted.
- Deleting your account removes your profile, posts, photos, comments, reactions, sessions, friendships, group memberships, and invitations.
Backups are the one honest exception. Content can persist in an encrypted backup for a short period after deletion until that backup rotates. It is not accessible through the product, and it is not restored to bring deleted content back.
Who else receives your information
We do not sell, rent, license, or trade your information, and we never will. There are no advertisers, no data brokers, no analytics networks, and no tracking pixels or third-party scripts on any page.
Information reaches other companies only where the service cannot work otherwise:
- Our SMS provider receives your mobile number in order to deliver a verification code. This happens when you sign up, add a device, or change your number — not for ordinary notifications. Invitations to friends are sent from your own phone by your own messaging app, so we never receive or transmit the number of anyone you invite by text.
- Our hosting provider stores the database and uploaded files on our behalf.
- A payment provider, only if you subscribe, and only to process that payment.
We may disclose information where we are legally required to, or where it is necessary to investigate a security incident or abuse of the service. We will tell you when we are permitted to.
How it is protected
- Encrypted in transit everywhere, with strict transport security.
- Phone numbers encrypted at rest, with lookups done against a separate keyed hash.
- Sign-in credentials stored only as hashes. Access expires quickly and renews silently, so revoking a device takes effect promptly.
- Photos and video kept outside the public web directory, unreachable by any URL, and served only through a gateway that re-checks on every single request whether you are still allowed to see them.
- Logs are written through a filter that redacts phone numbers.
No service can promise perfect security. If a breach affects you, we will tell you and describe what happened.
What you can do
- Take a copy. Me → Download my data exports your account and content.
- Delete your account. Me → Delete my account, and it is permanent.
- Correct anything. Your display name, bio, photos, and phone number can all be changed in settings.
- Control who reaches you. Accept or decline requests, unfriend, or block — a blocked person cannot see you and is not told.
- Sign devices out. Me → Devices and security revokes any session.
Depending on where you live, you may have additional rights — to access, correct, delete, or port your information, or to object to how it is handled. Write to privacy@kontome.com and we will act on it. We will not charge you for asking, and we will not treat you differently for having asked.
Children
Kontome is not directed at children under 13, and we do not knowingly collect information from them. We do not ask your age, so we rely on being told: if you believe a child under 13 has an account, write to privacy@kontome.com and we will delete it.
Where information is held
The service is operated from the United States and your information is stored there. If you use it from elsewhere, your information is transferred to and processed in the United States.
Changes to this policy
If this policy changes, the date at the top changes with it, and a change that materially affects how your information is handled will be announced in the app before it takes effect. We will not apply a new policy retroactively to information already collected under an older one without asking you.