Privacy Policy
How Cinder handles local app data, private iCloud data, purchases, exports, website measurement, and communications you initiate.
1. Scope
This policy covers Cinder, cinderpro.app, email sent to Cinder, and the embedded support form. Merit Advertising Corporation d/b/a Cinder (“Cinder,” “we,” “us,” or “our”) provides Cinder. Apple, Jotform, contact-account providers, and destinations you select have their own privacy practices.
2. Contacts data
Routine review decisions are stored on your device.
Cinder requests Contacts permission to display, organize, merge, mark, backup, rebuild, and, after a separate final confirmation, request deletion. Its reviewable set contains contacts the operating system makes available to Cinder, excluding people protected as Forever Contacts. Limited Contacts access therefore limits review, backup, export, and recovery scope.
Forever Contacts are saved on the device first and privately synchronized through the user's iCloud account when available. Each membership contains a stable Cinder UUID, source Contacts identifier, display name, normalized phone numbers and email addresses, and the date added. Forever membership does not change Apple Favorites or edit Apple Contacts. It applies only inside Cinder; Apple Contacts, synchronized accounts, and other apps can still change or delete the live card.
Cinder does not schedule or run background, automatic, recurring, or monthly backups. While you are using the app with authoritative full Contacts access, it may perform read-only checks for meaningful contact changes. Snapshot creation and updates, contact-photo inclusion, rebuilding, removal, and deletion occur only after an in-app request or express approval. To keep a monthly snapshot fresh, you must reopen Cinder and request or approve it.
3. Private iCloud data and manual exports
When you tap Backup & Delete, you request a Contacts Only VCF Recovery Snapshot containing exactly the contacts confirmed for removal and supported details Cinder can access. A cleanup-screen VCF export has that same removal-set scope. A manual snapshot or export created from Settings → Backups, Import & Export contains every contact then visible to Cinder. You may explicitly rely on your own verified backup instead.
Cinder includes every accessible Contact Note in a new VCF backup and stops if it cannot read, write, and verify a Note exactly. Contact photos are optional: Contacts Only is protected first, and selected photos can follow as a matched companion in the same ordinary snapshot family. Ordinary and Forever exports share one photo rule. Images already within both 2,048 pixels on the longest edge and 2,000,000 encoded bytes remain byte-identical; larger images are orientation-corrected, resized, and high-quality JPEG re-encoded until both limits hold. Invalid photo data fails closed. At 52.4 MB Cinder displays a whole-snapshot advisory, not an Apple or CloudKit limit, and permits a larger transfer when it can be read and verified safely.
Cinder keeps up to the 25 most recent ordinary Recovery Snapshot families in the user's private CloudKit database. A Contacts Only snapshot and its optional matched photo companion count as one family and one slot. Ordinary family 26 normally removes the oldest ordinary family together; Cinder warns if cleanup cannot be confirmed.
The Forever Recovery Vault is separate. It keeps one current verified Forever Recovery Snapshot per stable Forever membership UUID, plus protected pending work while needed. The local versioned vault is stored in protected Application Support. A private-iCloud record stores the recovery VCF asset with its stable Forever UUID, exact hash and byte count, snapshot date, photo policy and projection proof, and schema metadata. Protected local vault state also keeps the source Contacts reference and identity fingerprint, verification and health-check dates, and pending, attention, or deletion state needed for safe retry.
Forever Recovery Snapshots use a reserved namespace in Cinder's existing private CloudKit storage and are excluded from ordinary snapshot discovery. They consume none of the 25 ordinary family slots. Ordinary snapshot deletion cannot touch the Vault, and Vault deletion cannot touch ordinary Recovery Snapshots.
After express approval, Cinder creates Contacts Only first, uploads it, fetches it again, and verifies the exact hash, byte count, and one-card VCF. Accessible Contact Notes are automatic and fail closed. Only after every eligible Contacts Only snapshot in that approved run verifies does Cinder present one all-or-none Add All Contact Photos? choice. If approved, it prepares and round-trip verifies the entire batch before staging any photo upgrade; one preparation failure stages none. Each verified Contacts Only snapshot remains current until its own photo-bearing replacement verifies. Keeping Contacts Only requests no photo work and is remembered for that exact recoverable-data version across devices until the recoverable data changes.
For an approved photo upgrade, protected local state keeps a durable batch receipt containing the batch identifier, stable membership UUIDs, expected photo hashes and counts, timestamps, notification choice, and whether a completion notice was consumed. The app displays completion only when every expected current photo-bearing snapshot is remotely verified and no item is pending or unresolved. Pending work is not cloud-verified.
Notify Me When Verified is off by default. If the user enables it and grants notification permission, Cinder may schedule one count-only completion notification only after the entire receipt is fully verified. The notice contains no contact names, contact fields, hashes, or file paths; it observes 9:00 p.m.-9:00 a.m. quiet hours and opens the Vault when tapped. Delivery depends on notification permission and system scheduling. Deleting the relevant Vault work cancels a delayed completion notice.
Selected preferences also privately synchronize through iCloud: appearance, swipe haptics, merge explanations, final-delete confirmation, onboarding flags, custom Request Info openings, and the photo decision associated with an exact Forever snapshot projection. These assets use the user's iCloud storage. Apple Account access, services, network, permissions, and storage can affect availability.
For ordinary snapshot discovery, Cinder also stores a private Recovery Search Index containing normalized contact names, companies, phone numbers, email addresses, cities, and states. Ordinary search results exclude reserved Forever Recovery Vault records. The ordinary index contains no photo, Note, stable Contacts identifier, or rebuild payload; the verified VCF remains the rebuild source.
Manual exports leave Cinder through the system share sheet. The destination and recipients you select process the VCF under their own terms. A VCF can contain information about many people; protect it carefully.
4. Cinder Pro purchases and preorder reward
Cinder lets you review up to 15 unique contacts free. Cinder Pro is a lifetime, non-consumable in-app purchase with no subscription. It is priced at $0 through September 14, 2026; the regular U.S. $4.99 one-time price returns September 15. Apple displays and processes the current localized price and maintains the App Store entitlement. Use Restore Purchase in Cinder to ask Apple to restore an eligible purchase on the current Apple Account.
Eligible App Store preorders unlock Cinder Pro automatically when Apple verifies the original preorder before August 31, 2026 at 00:00 Eastern. Cinder checks Apple’s cryptographically verified Production AppTransaction on the device for the correct app and coherent dates. TestFlight, Sandbox, and Xcode transactions do not establish eligibility. Restore Purchase refreshes both the purchase entitlement and verified preorder record.
Preorder verification does not send the signed record to a Cinder claim service, allocate an offer code, or require email fulfillment. There is no redemption step or claim deadline. Existing $0 purchasers retain their one-time unlock. Apple’s account, storefront, refund, tax, and purchase terms apply. Acquiring Cinder Pro does not guarantee that any particular contact can be deleted, merged, backed up, synchronized, or rebuilt.
5. Support communications
Emailing support sends the address, message, headers, attachments, and details you include through your email provider. The embedded website form sends the information and optional files you submit directly to Jotform for support handling.
Do not send another person’s contact information unless necessary and authorized. The form’s current fields, formats, and limits appear in Jotform and may change. We and the service providers involved in support may process a submission to receive, secure, respond to, and maintain the request.
6. Website data
The current website uses Meta Pixel ID 1085989653984035, Google Analytics 4 Measurement ID G-EM1XEWDWMF, and Google Ads tag ID AW-993410133. Meta Pixel and Google Analytics measure page views and website interactions. Google Analytics Enhanced Measurement may also record scrolls, outbound clicks, site searches, video engagement, file downloads, and form interactions when those features are present. Google Ads measures page views and selections of live App Store download links. Meta's AppStoreClick and Google's app_store_click mean the browser proceeded toward the App Store; neither means Apple downloaded Cinder or completed a Cinder Pro transaction. Each Cinder event includes one fixed placement label: navigation, launch offer, hero badge, or closing call to action.
When website measurement is on, the browser may request measurement scripts from Meta and Google and may send them the page and referring URLs, browser and device information, IP address, identifiers, and event details. Those providers may read or set cookies or similar identifiers subject to browser settings and their policies. Cinder disables Google Signals and Google ad-personalization signals and does not enable Meta automatic advanced matching. Cinder does not send contacts, email addresses, Cinder review history, support submissions, signed AppTransaction data, or preorder-claim records in these events.
Website measurement is on unless you turn it off for that browser through Privacy Choices. The choice is stored in browser localStorage under the legacy key cinder-meta-pixel; turning it off prevents Meta Pixel, Google Analytics, and Google Ads measurement from loading on future page views in that browser and revokes consent for the current page, but it cannot retract an event already sent. The site also stores the selected light or dark theme under cinder-theme. The embedded support form contacts Jotform. Links to Apple, email software, or other sites leave Cinder's website. The language selected in the website selector is stored in this browser under cinder-language. Initial language matching uses browser language preferences, not location or country.
Web hosts and network providers may create ordinary request, security, and error logs under their own settings and policies.
8. Retention and deletion
Routine review decisions remain local until Cinder removes or resets them, or the app is deleted, subject to iOS backup behavior. Ordinary Recovery Snapshot assets remain in private CloudKit until removed, pruned by the 25-family policy, or made unavailable by Apple Account or service conditions.
The Forever Recovery Vault retains one current verified snapshot per membership and protected pending work while needed. Per-contact removal deletes or safely queues deletion of that contact's dedicated snapshot. Delete All Forever Recovery Snapshots preserves Forever memberships and affects only the Vault. Deletion authority supersedes stale creation, update, and photo work.
Deleting Cinder does not reverse synchronized contact changes, delete manually exported files or sent email, remove private-iCloud Recovery Snapshots, Forever memberships, Forever Recovery Snapshots, portable settings, or send Jotform or another provider a deletion request. Private CloudKit data can remain after uninstall. Support records and website logs may be retained as reasonably needed for support, security, legal obligations, and dispute handling, subject to provider settings and applicable law.
9. Your choices
- Turn Meta Pixel, Google Analytics, and Google Ads website measurement on or off together for the current browser through Privacy Choices.
- In Cinder, open Settings → Contacts Access → Open iOS Contact Settings; the exact system Settings path varies by OS version.
- Add or remove Forever Contacts in Cinder; iCloud may synchronize those changes.
- Choose Create Forever Recovery Snapshots, Update Forever Recovery Snapshot, or Not Now when offered.
- Choose once whether to include all eligible contact photos in an approved Forever run after Contacts Only verifies, and separately choose whether to request a completion notification.
- Review, keep for later, rebuild from, remove, or delete a Forever Recovery Snapshot through the in-app Vault controls.
- View, download, or delete ordinary managed families through Settings → Backups, Import & Export → Recovery Snapshots.
- Choose a destination for a manual VCF export and delete exported files from that destination.
- Use Restore Purchase to refresh Apple’s purchase entitlement and verified preorder record.
- Choose whether to email support or submit the Jotform support form and what to include.
Open Cinder to create or update any snapshot; Cinder does not schedule those actions. Email info@cinderpro.app to ask about access, correction, or deletion of information held by Cinder. We may need to verify the request, and some records may be unavailable to us or retained where permitted or required by law.
10. Security
Cinder uses local file protection, private CloudKit databases, and integrity checks for Cinder-managed state and backups. We also use reasonable safeguards for information we handle. No device, storage system, transmission, or service is perfectly secure.
11. Children
Cinder does not require a Cinder account and is not directed to children under 13. If you believe a child submitted personal information through support, email info@cinderpro.app.
12. Changes to this policy
We may update this policy as Cinder or its providers change. The effective date and version at the top identify the current policy. We will provide additional notice when required by law.
13. Contact
Merit Advertising Corporation d/b/a Cinder
Email: info@cinderpro.app
Use the subject “Cinder Privacy” for privacy questions or requests.