Last updated August 2026
Privacy
This is the honest version. contactme.co is a page that holds your links and lets people message you. The less we hold, the less there is to go wrong.
What we store about you
- Your account. An identifier and email address from the provider you signed in with (Google, Microsoft, LinkedIn or GitHub), or the address you asked us to send a sign-in link to.
- Your page. Handle, name, headline, bio, location, pronouns, links, theme and any photo you upload.
- Your sign-in address. We notify you at the address you sign in with — there is no separate field to set, so we can never be pointed at somebody who didn't ask to hear from us. It is never returned by any public API and never appears on your page.
- Messages sent to you, including the sender's name and email address, because you need those to reply. This covers both the contact form and — if you switch it on — mail sent to your @contactme.co address.
What we store about visitors
What the page owner sees: daily totals, and nothing else. How many times their page was viewed on a given day, and how many times each link was clicked. No per-visitor record, no referrer, no device data. We can't tell them who visited, because we don't know.
What we see, for our own product: aggregate usage — which pages get visited and roughly where traffic arrives from. It is measured without cookies and without any per-visitor profile: nothing is written to your device, so nothing follows you between visits or between pages. We can count that a page was viewed. We cannot build a picture of you.
A profile page never runs click tracking, and never records a session. The links on it are somebody's phone number and email address, and the form on it is a message meant for one person.
When someone sends a message we keep a salted hash of their IP address so rate limiting works. The address itself is never written down, and the hash can't be reversed into one.
Who else sees it
- Supabase hosts the database, authentication and file storage.
- Resend delivers notification emails, when that's switched on.
- An inbound email provider (Resend, Mailgun, Postmark, SendGrid or Cloudflare, depending on the deployment) receives and spam-scores mail addressed to your @contactme.co address, then hands us the parsed message. We never forward mail, and we never send mail on your behalf.
- PostHog counts aggregate usage, on their US infrastructure. Requests go through our own domain rather than to them directly, and carry no cookie or visitor identifier.
- Vercel serves the site.
We don't sell anything to anyone. Google Ads measures whether an advert we paid for led to a signup. It runs on our own pages only — never on somebody's contact page, which is theirs. Until you allow cookies it stores nothing: it runs with Google's consent signals set to denied, which means no advertising cookie and no identifier, only an anonymous count.
Cookies
One for your login session, always. Then, only if you choose “Allow” — never before, and never if you decline or ignore it — one for analytics, and one an advertiser sets so an advert we paid for can be matched to a signup. Declining changes nothing about how the site works. You can change your mind from “Cookie settings” in the footer at any time.
Deleting it
Settings → Delete your account. Your profile, messages, analytics and login are removed. Your handle is retired rather than released, so nobody can pick it up and pretend to be you.
Contact
Questions about any of this: privacy@contactme.co.

