Contactable
Menu
How it works About FAQ

Last updated: 12 August 2026

Privacy

Contactable is built for temporary private contact. The purpose of the service is to let people receive and send messages without immediately revealing their phone number, email address, WhatsApp, social profile, or other permanent contact details.

Who this notice is for

This notice applies to people who create a Contactable token, manage a token, open a public token, send a request, or take part in a temporary thread.

For privacy requests, contact the site operator at privacy@contactable.co.uk. Please make sure you can prove control of the relevant owner link, public thread session, token, or message before requesting information about it. Contactable does not use accounts, so this proof helps avoid disclosing private information to the wrong person.

What we collect

Contactable only aims to collect the information needed to make a temporary contact token work:

  • Token details, including the public token, private owner link, creation time, expiry time, status, and optional intent text.
  • Optional shared passphrase protection. The passphrase itself is not stored in plain text.
  • Message content sent through the temporary thread. Message bodies are encrypted at rest in the database.
  • Thread information, such as whether a request is pending, accepted, declined, opened, read, expired, or destroyed.
  • Essential session and access cookies used to keep the owner or requester connected to the correct temporary thread.
  • Abuse-prevention and rate-limit records. These are generated from technical signals such as IP address and browser user agent, then stored as hashed rate-limit keys.
  • Basic technical server logs created by the web server or application for security, error diagnosis, and service operation.

What we do not collect for the core service

Contactable does not require an account for the core service. It does not ask for your real phone number, email address, name, social account, or payment details to create or use a temporary token.

Contactable does not use advertising profiles, social login, tracking pixels, behavioural marketing, or sale of personal data as part of the core service. If you choose to type personal information into an intent field or message, that information may become part of the temporary thread.

How messages are handled

Messages are private between the people who have the correct token, owner link, passphrase, cookie, or session access. Message bodies are encrypted at rest in the database and are not written to application logs.

This is not end-to-end encryption. The server application must decrypt message bodies to show them to the correct owner or requester page. A person with full access to the server, database, and application key could technically access message content.

Contactable is not a live monitoring or moderation service. We do not routinely read, review, or monitor private message content. Message content may still be processed technically so the service can deliver it to the correct browser, and it may be accessed if required by law, to investigate serious abuse, or to protect the service.

Why we use this data

We use the data to provide temporary messaging, show and manage tokens, deliver messages to the correct thread, apply expiry and deletion, protect the service from bots and abuse, diagnose technical issues, and comply with legal obligations.

The lawful bases are normally the steps needed to provide the service requested by the user, legitimate interests in operating and protecting a private contact service, and legal obligation where the law requires us to keep, disclose, or act on information.

Cookies

Contactable uses essential cookies only. These may include a secure session cookie, owner or requester access state, and passphrase-unlock state for a protected token. These cookies are needed for the service to work and are not used for advertising or cross-site tracking.

If Google reCAPTCHA is enabled on forms, Google may process technical and interaction data to assess whether a request looks human or automated. reCAPTCHA may set a necessary cookie for risk analysis. This helps reduce spam and automated abuse while keeping the form invisible to genuine users.

Sharing

We do not sell personal data. We may share limited data with hosting, database, storage, security, or infrastructure providers where needed to operate the service. We may also disclose information if required by law, court order, regulator, or to protect people, the service, or the server from serious abuse.

How long data is kept

Tokens and messages are temporary. They are deleted when the token expires, when the owner destroys the token, when a request is declined, or when the requester destroys the temporary thread. Expired rate-limit records are removed automatically. Session cookies end according to the browser and server session settings, and public passphrase access cookies last no longer than the token lifetime.

Technical server logs, if created by the hosting environment, should be kept only for the period needed for security, troubleshooting, and abuse prevention.

Security

Contactable uses HTTPS, secure and HTTP-only cookies where configured, CSRF protection, form verification, bot checks, rate limits, private owner links, optional shared passphrases, storage outside the public web root, and encrypted message storage at rest.

No internet service can promise perfect security. You should not use Contactable to send passwords, financial details, identity documents, emergency information, or anything you would not want the other participant to save, copy, screenshot, or share.

Your choices and rights

The simplest way to remove a token and its messages is to use the private owner link or the available Destroy Chat control. You may also ask for access, correction, deletion, restriction, objection, or portability where these rights apply.

Because Contactable has no accounts, we may need enough information to verify that you control the relevant token or thread before acting on a privacy request.

Complaints

If you are unhappy with how your data is handled, please contact us first. You may also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint/.

Changes

This notice may be updated as Contactable develops, if the hosting setup changes, or if legal requirements change. The latest version will be published on this page.

Contactable Ephemeral contact. No accounts. No tracking.
Guides Message without a number Dating safety Temporary contact links Private QR codes
Company About FAQ Privacy Terms