Contact Removal Agreement
Contact Removal Acknowledgment and Terms of Use
Please read this entire agreement carefully. Cinder allows you to review, organize, combine, mark, and ultimately delete contact records. Although marking a contact for removal does not immediately delete it, later confirmation may permanently remove that contact from your device and from accounts or devices synchronized with your address book.
If the current version is not already accepted, Cinder presents this agreement before Apple’s purchase confirmation when you unlock Cinder Pro. It may also present it after the Removal List and before Final Confirmation. Choosing Not Now stops the current purchase or deletion path; existing review decisions remain available.
1. Agreement, Eligibility, and Authority
These Contact Removal Acknowledgment and Terms of Use (the “Terms”) are between you and Merit Advertising Corporation d/b/a Cinder (“Cinder,” “Merit,” “we,” “us,” or “our”) concerning your access to and use of the Cinder mobile application, related contact-review features, backup and rebuilding tools, websites, communications, and services collectively referred to as the “Service.” These Terms supplement the licensed-application terms identified on Cinder’s App Store product page and Apple’s purchase terms. By selecting “I Have Read & Agree” or “Agree & Continue to Apple,” as applicable, you acknowledge that these Terms were presented to you, that you had the opportunity to review them, and that you agree to them. If you do not agree, choose Not Now and do not continue with the purchase or final deletion. You represent that you are legally capable of entering into this agreement. If you are not legally capable of doing so, a parent, guardian, or other legally authorized person must review and accept these Terms on your behalf. You further represent that you own, control, or are lawfully authorized to access and modify every address book, account, device, and contact record you choose to process through Cinder.
2. What Mark for Removal Means
Selecting Mark for Removal, swiping in the removal direction, marking original contacts during a duplicate merge, or taking an equivalent action is designed to place the applicable contact into a Removal List for later review. It is not intended to immediately delete that contact. You may be able to undo the decision or remove the contact from the Removal List before final deletion. A contact is intended to be deleted only after you reach the final removal process, review the contacts selected for deletion, and provide a separate final confirmation. Nevertheless, you must treat every removal decision carefully. Software defects, interrupted processes, operating-system behavior, account synchronization, changes made outside Cinder, user error, or future modifications to the Service may affect the availability or operation of review and undo functionality. You should not mark a contact for removal unless you are prepared for the possibility that the contact may ultimately be permanently deleted. The agreement does not appear in response to an individual mark and does not require you to mark a contact again. If it has not already been accepted during purchase, Cinder presents it when you request Final Confirmation after reviewing the Removal List.
3. Efforts to Limit Deletion to Selected Contacts
Cinder is designed to request deletion only of contact records associated with contacts appearing on the Removal List that you finally confirm for deletion. Safeguards intended to reduce unintended deletion include separating an initial removal decision from actual deletion, providing a Removal List, permitting contacts to be removed from that list, requiring a separate final confirmation, and using device-provided contact identifiers when requesting deletion. These safeguards are intended to reduce, not eliminate, the possibility of an incorrect, unintended, incomplete, or excessive deletion. Neither Cinder nor any other software system is infallible. Software defects, programming errors, operating-system behavior, contact linking or unification, stale or changed contact information, synchronization conflicts, third-party account behavior, unexpected identifiers returned by a platform service, and other circumstances may cause Cinder to delete, modify, fail to delete, or appear to delete a contact differently from what you expected. Cinder therefore does not guarantee that only the contacts you intended to delete will be affected, that every selected contact will be deleted, that an affected contact will be limited to one device or account, that linked or synchronized records will remain unaffected, or that an unintended deletion can be reversed or completely rebuilt. A residual risk of unintended and irrecoverable contact deletion remains. If you are unwilling to accept that risk, do not use final deletion functionality.
4. Final Deletion and Synchronized Accounts
When you provide final confirmation, Cinder will attempt to delete selected contacts through functionality made available by your device and operating system. Deleting a contact from your device may also delete or modify that contact in any synchronized account, service, device, or address book connected to it, including iCloud, Google, Microsoft Exchange, Outlook, CardDAV, employer-managed accounts, shared accounts, and additional Apple devices. Synchronization may occur immediately or after a delay. Cinder does not control the timing, direction, conflict resolution, retention policies, recovery features, or availability of any synchronized or third-party account. Deletion may therefore affect records on devices that are not currently in your possession. A synchronized address book is not necessarily a backup. A deletion may synchronize to services or devices you believed were backup copies. You are responsible for checking which accounts are connected to your device and understanding their synchronization behavior before confirming deletion.
5. Your Responsibility to Review and Preserve Contacts
You are solely responsible for reviewing the identity, contents, source account, and continued usefulness of every contact selected for removal. Cinder cannot determine whether a contact is personally meaningful, required for an emergency, legally important, needed for business or employment purposes, associated with an active contract, subject to litigation or regulatory retention duties, or otherwise valuable to you. A contact that appears incomplete, outdated, unused, duplicated, or unnecessary may contain information that you later need. You should independently inspect each contact and must not rely exclusively upon a name, photograph, company, phone number, email address, timestamp, area code, filter category, duplicate suggestion, or other summary displayed by Cinder. Contact records may contain personal, professional, confidential, proprietary, regulated, or sensitive information concerning other people. If contacts are owned or managed by an employer, school, organization, client, household member, mobile-device administrator, or other third party, you must obtain any required authorization before using Cinder with those contacts.
6. Automated Suggestions, Filters, and Duplicate Merging
Cinder may identify, rank, filter, or group contacts using automated rules, matching systems, device-provided information, or other software analysis. These features are organizational aids and are not authoritative determinations of identity, duplication, relevance, ownership, location, accuracy, recency, or value. A duplicate suggestion may group different people, and Cinder may fail to recognize records belonging to the same person. Area codes are clues only and do not establish where someone lives or works. Missing-information filters may not account for notes, linked contacts, directories, custom fields, third-party services, or information stored elsewhere. When you merge possible duplicates, Cinder may create a new combined contact using fields you select and then mark original contacts for removal. A merged record may not preserve every field, label, relationship, account association, image, note, identifier, linked-contact relationship, directory connection, or provider-specific item. You must review the merged record and the originals before confirming deletion.
7. Recovery Snapshot and Your Backup Choices
By tapping Backup & Delete, you expressly request a Contacts Only VCF Recovery Snapshot containing exactly the contacts confirmed for removal and supported details Cinder can access and, after verification, deletion of that confirmed removal set. Cinder saves the snapshot in your private iCloud database. A cleanup-screen VCF export has that same removal-set scope. Cinder does not intentionally begin deletion until the requested snapshot is verified or you explicitly choose to rely on your own backup. If the snapshot cannot be created, you can retry, save and share a supported VCF of the confirmed removal set, open Backups, Import & Export, use a current backup you already trust, or cancel without deleting. The requested Recovery Snapshot, cleanup export, CloudKit storage, backup history, and rebuilding features are safeguards, not guarantees. Cinder does not schedule or create the snapshot autonomously in the background. A separate backup should be stored apart from the live synchronized address book being modified. Merely enabling iCloud Contacts, Google Contacts, Exchange synchronization, or another synchronization service may not constitute a separate backup because deletion may synchronize to those services. If you choose to use your own backup, you are responsible for confirming that it exists, can be accessed, contains the information you intend to preserve, and is stored somewhere deletion or synchronization will not affect it. If a Cinder Recovery Snapshot or another backup appears incomplete, cannot be checked, produces an error, or is unavailable, cancel deletion unless you have another current backup you trust. Proceeding with a backup you cannot confirm carries a risk that deleted contacts may be permanently lost.
8. What Cinder Backs Up and Cannot Restore
Cinder's requested pre-deletion Recovery Snapshot, cleanup export, manual snapshot, and manual export use the same vCard (.vcf) format but not the same contact set. Pre-deletion snapshots and cleanup-screen exports contain contacts confirmed for removal. Manual snapshots and exports created from Backups, Import & Export contain every contact visible to Cinder. Subject to the device's operating system, contact provider, granted permissions, and the limitations below, Cinder is designed to preserve core available contact-card information, including names and name components, nicknames and previous family names, organizations, departments, job titles, phone numbers, email addresses, postal addresses, website addresses, birthdays, certain other labeled dates, related names, instant-messaging addresses, and some social-profile information and labels. Limited Contacts access limits every snapshot and export. Cinder includes every accessible Contact Note and stops rather than keeping or rebuilding a stripped result if it cannot read, write, and verify the Note exactly. Contact photos are optional. Cinder protects Contacts Only first, then may create a matched Contacts + Photos companion in the same snapshot family. Ordinary and Forever snapshot exports use one photo rule: an already-valid image at or below both 2,048 pixels on the longest edge and 2,000,000 encoded bytes remains byte-identical; a larger valid image is orientation-corrected, resized, and high-quality JPEG re-encoded until both limits hold. Invalid photo data fails closed. At 52.4 MB Cinder displays a whole-snapshot advisory, not an Apple or CloudKit limit, and permits a larger upload or import when it can be read and verified safely. Requested photos still must pass Note and photo write-and-read verification. Cinder does not preserve contact groups or lists and their membership, the original source account or container, linked-contact structure, original identifiers, creation or modification timestamps, ringtones, text tones, favorite or blocked status, directory associations, or provider-specific metadata and fields. Some otherwise included information, particularly social-profile usernames or labels, phonetic organization names, custom labels, non-Gregorian dates, related names, and Apple-specific fields, may be incomplete, reformatted, or unsupported when another app, provider, or operating-system version reads the file. Cinder is designed to keep the 25 most recent ordinary Recovery Snapshot families in your private iCloud database. A Contacts Only snapshot and its optional matched photo companion count as one ordinary family and one slot. Ordinary family 26 normally removes the oldest ordinary family and its available companions together; Cinder warns if cleanup cannot be confirmed. Forever Recovery Snapshots are outside those families, use none of their slots, and are not deleted by ordinary snapshot controls. Vault deletion cannot touch ordinary Recovery Snapshots. These assets count against your personal iCloud storage; Cinder does not include an iCloud or iCloud+ storage plan. You are responsible for maintaining Apple Account access, sufficient storage, and independent copies of information you cannot afford to lose. Cinder does not guarantee that a family or Vault snapshot will remain available. The Forever Recovery Vault may keep one current verified Forever Recovery Snapshot per stable Forever membership UUID, plus protected pending work while needed. After express approval, Cinder verifies every eligible Contacts Only snapshot in the run by upload and fresh private-iCloud readback before presenting one all-or-none contact-photo choice for that run. If approved, Cinder prepares and round-trip verifies the entire photo batch before staging any photo upgrade; one preparation failure stages none. A photo batch is complete only when every expected current photo-bearing snapshot is remotely verified and no item is pending or unresolved. Pending work is not cloud-verified, and the last verified Contacts Only snapshot remains current until its replacement verifies. Notify Me When Verified is off by default; after separate opt-in and permission, Cinder may send a count-only notice only after the entire batch verifies, subject to system scheduling and quiet hours. Accessible Contact Notes are automatic and fail closed. Creation, update, contact-photo inclusion, rebuild, removal, and deletion require an in-app request or express approval. A failed replacement does not displace the last verified snapshot. Removing a Forever Contact deletes or safely queues deletion of that contact's snapshot without deleting the live Apple contact; Delete All Forever Recovery Snapshots preserves Forever memberships. Rebuilding creates new contact records from the information that can be read from the backup file; it does not return the address book to its prior state. Rebuilt contacts may receive new identifiers, may be flattened instead of relinked, and are normally added to the device’s default contact account or container rather than their original location. Cinder does not recreate groups or group membership. If Cinder identifies an existing contact with a phone number or email address and the same normalized supported contact-card content, it may skip the corresponding backed-up occurrence as an existing match instead of adding it or merging fields. Same-name-only and partial matches are presented for your review rather than treated as definitive duplicates. Cinder does not guarantee that a backup operation will begin or finish, that every contact or field will be included, that an exported file will be readable or recoverable, that a CloudKit asset will upload, remain stored, download, or remain accessible, or that a displayed success message proves every contact was preserved. A backup may fail without immediately apparent symptoms. A file may exist while being incomplete, corrupted, inaccessible, or unsuitable for rebuilding. CloudKit functionality depends upon Apple services, your Apple Account, network connectivity, available storage, device configuration, permissions, and conditions beyond Cinder’s control. Cinder intentionally describes recovery as rebuilding rather than perfect restoration. Cinder is not an archival provider, legal-hold system, records-management platform, or guaranteed disaster-recovery service.
9. Permissions and Changes Made Elsewhere
Cinder’s ability to display and modify contacts depends upon the permission level granted through your operating system. If you grant access only to selected contacts, Cinder may not display or process your entire address book. Contacts may be created, changed, linked, synchronized, restricted, or deleted by you, another device, another application, an account administrator, a contact provider, or a synchronization service while Cinder is in use. Information displayed during review may therefore differ from the current record when final deletion is attempted. A re-fetch or consistency check cannot eliminate every possibility of a conflicting or unexpected change.
10. Local Processing, Cloud Features, and Privacy
Cinder is designed as a local-first contact-cleanup application. Routine review decisions remain on the device. After your Backup & Delete request, Cinder may write the confirmed removal set to a Recovery Snapshot and store it in the user's private Apple CloudKit database. Manual snapshots and exports created from Backups, Import & Export cover every contact then visible to Cinder; a destination you select through the share sheet may receive an exported file. Cinder does not run scheduled, automatic, recurring, or monthly backup jobs in the background; snapshots require an active app session and an in-app request or approval. Forever Contacts are stored on the device first and privately synchronized through the user's iCloud account when available. A synchronized Forever membership contains a stable Cinder UUID, Apple contact identifier, display name, normalized phone numbers and email addresses, and the date added. The separate Forever Recovery Vault uses protected local Application Support storage and reserved records in the user's private CloudKit database. Each Vault record is keyed to the stable Forever UUID and contains a recovery VCF asset with integrity, snapshot-date, photo-policy, and schema metadata. Protected local Vault state also retains source identity, verification, health, pending, and deletion data needed for safe retry. Selected preferences also privately synchronize, including the photo decision for an exact Forever snapshot data version. Ordinary snapshot discovery excludes reserved Vault records. You are responsible for protecting exported contact files and choosing appropriate recipients, storage locations, sharing methods, and retention periods. Cinder’s handling of personal information is described in the Privacy Policy. Additional information concerning collection, use, sharing, retention, deletion, and privacy choices is provided in Cinder’s Privacy Policy. The Privacy Policy controls if these Terms conflict with it regarding how personal information is handled.
11. Agreement Copies
The agreement remains available inside Cinder and on this website. Cinder 1.0 does not send or store an email address entered on the Email This Agreement screen; that screen reports that delivery is not connected and no email is sent. Receiving or failing to receive any future email copy would not replace the in-app or officially published agreement.
12. Cinder Pro Purchase, License, and Acceptable Use
Cinder permits review of up to 15 unique contacts free. Cinder Pro is a lifetime, non-consumable purchase with no subscription. Apple displays and processes the current localized price and maintains the App Store entitlement. The promotional price is $0 through September 14, 2026; the regular U.S. $4.99 one-time price returns September 15. Cinder provides a Restore Purchase control to ask Apple to restore an eligible purchase on the current Apple Account. Apple’s confirmation, account requirements, storefront availability, refund rules, taxes, and other purchase terms apply. Payment or a promotional acquisition does not guarantee that a particular contact can be deleted, merged, backed up, synchronized, or rebuilt. Subject to these Terms and the licensed-application terms identified on Cinder’s App Store product page, Cinder grants you a limited, personal, revocable, non-exclusive, non-transferable license to use the Service on supported devices you own or control. You may not misuse the Service, interfere with its operation or security, attempt unauthorized access, process contacts without authority, circumvent access restrictions, or use Cinder in violation of applicable law or another person’s rights.
13. Third-Party Services, Availability, and Changes
Cinder interacts with iOS, Contacts, private iCloud and CloudKit, App Store purchasing services, synchronized contact-account providers, and destinations the user selects. Apple and other providers control their own functionality, terms, availability, and data handling. We may modify, suspend, limit, replace, or discontinue portions of Cinder subject to applicable law. We do not guarantee that the Service will always be available, error-free, compatible with every device or account, or capable of processing every contact. You must not rely upon Cinder as the exclusive location or method for retaining, backing up, or recovering important information.
14. Disclaimer of Warranties
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, CINDER AND THE SERVICE ARE PROVIDED “AS IS,” “AS AVAILABLE,” AND WITH ALL FAULTS. CINDER DISCLAIMS EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, SATISFACTORY QUALITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, RELIABILITY, AVAILABILITY, QUIET ENJOYMENT, TITLE, AND NON-INFRINGEMENT. CINDER DOES NOT WARRANT THAT CONTACT SUGGESTIONS WILL BE CORRECT; THAT DELETION WILL BE LIMITED TO A SINGLE DEVICE, ACCOUNT, OR RECORD; THAT A BACKUP WILL BE COMPLETE OR RECOVERABLE; THAT REBUILDING WILL RESTORE ORIGINAL RECORDS; OR THAT THE SERVICE WILL OPERATE WITHOUT INTERRUPTION, DELAY, CORRUPTION, LOSS, OR ERROR. NOTHING IN THESE TERMS EXCLUDES A WARRANTY OR STATUTORY RIGHT THAT CANNOT LAWFULLY BE EXCLUDED.
15. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, CINDER AND ITS OWNERS, OFFICERS, EMPLOYEES, CONTRACTORS, AFFILIATES, LICENSORS, AND SERVICE PROVIDERS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF CONTACTS, DATA, COMMUNICATIONS, BUSINESS OPPORTUNITIES, REVENUE, PROFITS, GOODWILL, OR RECORDS, ARISING FROM OR RELATING TO THE SERVICE. THIS LIMITATION APPLIES WHETHER A CLAIM IS BASED UPON CONTRACT, WARRANTY, TORT, NEGLIGENCE, STRICT LIABILITY, STATUTE, OR ANOTHER THEORY, EVEN IF THE POSSIBILITY OF DAMAGE WAS KNOWN OR REASONABLY FORESEEABLE. TO THE MAXIMUM EXTENT PERMITTED BY LAW, CINDER’S TOTAL AGGREGATE LIABILITY ARISING FROM THE SERVICE WILL NOT EXCEED THE GREATER OF THE AMOUNT YOU PAID FOR CINDER OR FIFTY U.S. DOLLARS. SOME JURISDICTIONS DO NOT PERMIT CERTAIN EXCLUSIONS OR LIMITATIONS, AND THESE PROVISIONS APPLY ONLY TO THE MAXIMUM EXTENT PERMITTED THERE.
16. Preservation of Consumer Rights and Limited Indemnification
Nothing in these Terms excludes, restricts, or modifies a warranty, remedy, liability, or consumer right that cannot lawfully be excluded, restricted, or modified. Nothing limits liability for fraud, willful misconduct, gross negligence, or another liability that applicable law prohibits Merit from limiting. To the extent permitted by law, you agree to indemnify Merit against third-party claims arising directly from your knowing unauthorized access to another person’s contacts, your unlawful use of the Service, or your material violation of these Terms. This provision does not apply to claims arising from a defect in Cinder or conduct attributable to Merit.
17. Electronic Acceptance, Agreement Records, and Revisions
By selecting “I Have Read & Agree” or “Agree & Continue to Apple,” as applicable, you consent to accepting this agreement electronically. Cinder stores the accepted agreement version and acceptance timestamp in local app preferences. Its acceptance path does not send an acceptance record to Merit and does not store an app version or technical identifier with that record. Cinder may require acceptance of a revised version before a purchase or Final Confirmation. Settings displays whether the current version was accepted and, when available, its local acceptance date. We may revise these Terms and will provide notice when required by law. Deleting Cinder removes the local acceptance values subject to iOS backup behavior. It does not reverse contact changes, retrieve deleted contacts, remove exported files, promise deletion of private-iCloud ordinary Recovery Snapshots, Forever memberships, Forever Recovery Snapshots, or portable settings, or send a third-party provider a deletion request.
18. Legal Holds, Apple Terms, and Contact Information
Cinder is not a legal-hold, compliance, emergency-information, business-continuity, or professional records-management system. Do not rely upon Cinder to determine whether a contact is subject to a legal, contractual, employment, medical, safety, evidentiary, or regulatory retention duty. These Terms are between you and Merit, not Apple. Merit, not Apple, is responsible for Cinder and its content, subject to the licensed-application terms identified on Cinder’s App Store product page. Apple has no obligation to provide maintenance or support except as stated in applicable Apple terms. Apple and its subsidiaries are third-party beneficiaries of applicable licensed-application terms and may enforce them as permitted by those terms and applicable law.
Contact: info@cinderpro.app