How we protect your data
Updated June 28, 2026Quick Contact protects your contacts with end-to-end encryption and biometric authentication. We don't collect data. We don't sell access to your contacts. Your address book is encrypted and stored only on your device.
π End-to-End Encryption (AES-256-CBC)
Task titles and descriptions are encrypted on-device with AES-256-CBC + HMAC-SHA256. The server Worker receives only ciphertext. Even Quick Contact admins cannot read your data.
π Cryptographic keys in SecureStore
All keys (device key, team tokens) are stored in iOS Keychain / Android Keystore β OS-level encryption. Not accessible via system backups, not exportable without authorization.
π€ Biometric Lock (Face ID / Touch ID)
Biometric authentication required at app launch. Toggleable from Settings. On return from background, biometrics required again β 30-second inactivity timeout.
π΅ Zero System Backup
System auto-backup is completely disabled. Cryptographic keys are NOT included in QCB exports. Only password-protected export with explicit user consent.
π Automatic token rotation
Team tokens are rotated on every API call via dual-hash fallback. If a token is compromised, rotation automatically invalidates it. Zero downtime during rotation.
π HTTPS+TLS Communication
All data in transit is encrypted with TLS 1.2+. No unencrypted communication between app and server.
β±οΈ Automatic session timeout
Auto logout after 30 minutes of inactivity. Maximum session duration: 24 hours. Prevents unauthorized access if device is lost.
π‘οΈ OAuth 2.0 (No password)
Login via Google OAuth 2.0. Quick Contact never sees your Google password. Access token is securely stored in SecureStore and deleted on logout.
2οΈβ£ 2FA TOTP (RFC 6238)
10 backup codes generated cryptographically at setup. Each code is single-use (10 attempts maximum). Biometric fallback if authenticator app unavailable.
π Biometric reauthentication
Face ID / Touch ID required before: Exporting data, Viewing 2FA backup codes, Deleting account, Modifying security settings.
β¨ HMAC Integrity Check
Every encrypted field is protected by HMAC-SHA256. Tampering detected instantly β decryption refused if HMAC doesn't match.
π What we DON'T do
- β We don't collect usage analytics
- β We don't track your location
- β We don't store business card images on servers
- β We don't sell data to third parties
- β We don't use advertising tracking cookies
- β We have no access to your encrypted data
π¬ Security questions?
Quick Contact β Security email