Subject: Re: Submission 7b89dcb6 — Guideline 5.1.2 resolved (contacts consent)
Hello, and thank you for the detailed report.
We identified the issue and fixed it. It will be in our next build.
What happened: On the "New client" form, the app performed an automatic background lookup that sent the entered email/phone number to our server to detect whether that person already has a Timint account. This happened without an explicit, separate consent step. That was an oversight.
What we changed:
We removed the automatic upload entirely. Typing or auto-filling a client's details no longer transmits anything.
The "is this person already on Timint?" check is now a manual, opt-in action. The first time a user taps it, we present a clear in-app disclosure explaining that the email/phone they entered will be sent to our servers solely to check for an existing Timint account so the client can be linked to that account. The lookup only runs after the user explicitly consents.
What we do with the data / why: Contacts are uploaded only with the user's explicit in-app consent, and only to find existing Timint users so they can be connected or linked. For the separate "find people you know" feature, contact data is hashed server-side and used only for matching. We do not sell or share contacts, and they are not used for advertising. Our Contacts permission string also discloses that contacts may be uploaded to our servers.
We appreciate your patience and thorough review. Please let us know if any further detail would help.
Best regards,
The TIMINT Team