Privacy Policy
Who we are
Coneker is a personal relationship graph: a record of the people, places, events and ideas you choose to capture. It runs on iPhone, on Android, and in a browser at app.coneker.com. Coneker is operated by FUNTG Limited, a company registered in Hong Kong (“we”, “us”).
FUNTG Limited is responsible for your personal data. Under Hong Kong’s Personal Data (Privacy) Ordinance it is the data user, and under the EU and UK GDPR it is the controller. For any question about this policy, or to ask to see, correct or delete your data, write to support@funtg.com for the attention of our Privacy Officer.
How you may use Coneker is set out in our Terms of Service.
The short version
- Your graph is stored on our servers and is private to your account. No other Coneker user can see it unless you share part of it.
- We show no ads, we do not sell or rent personal data, and your content is not used to train AI models.
- To do their work, parts of your content go to the service providers listed below. These include AI model and speech providers in Hong Kong and the United States.
- You can export your data, and delete your account, from the app or the web.
Where your data lives
Coneker is not an offline app. Your graph is stored on our servers (Amazon Web Services, in Mumbai, India), not only on your phone, so that it survives losing your device and can be reached from a new one. Traffic is encrypted in transit. We do not currently encrypt your graph at rest, which means Coneker staff with database access could in principle read it. We restrict that access to what operating and securing the service requires.
A few things genuinely stay on your device and are not sent to us:
- Your app passcode. Only a salted hash is stored, on the phone.
- The contents of your device calendar (see below).
- Face ID and other biometrics. Your phone’s operating system handles these, and Coneker never receives them.
Two other things are kept on your device, and are also stored with us or sent to us when used: your Ask conversation history, and a cache of recently viewed parts of your graph. See “On your device”.
What we collect
- Account
- Your email address.
- If you sign in with Apple or Google, the identifier that service gives us.
- Your name. You may type it, or Google or Apple may supply it when you sign in.
- A job title and profile photo, if you add them.
- If you set a password on the web, only a salted hash of it. If you add a passkey, only its public key.
- Your settings, such as language, reminders, notifications and weather.
- Your content
- The notes you write, and transcripts of notes you dictate.
- Photos you scan or attach, and text converted from documents you upload.
- The people, places, events, ideas and connections Coneker extracts from all of that.
- Drafts of captures you have not saved yet.
- Meetings you record: the audio, the transcript, and any summary or translation.
- The questions you ask in Ask.
- The capture rules Coneker learns from your corrections.
- Friends and messages. Your friends, friend requests and invitations, including any email address you invite. Also what you share with friends, the messages and attachments you send, and the conversations you are part of.
- Purchases. What you bought, when, the amount, and the payment processor’s reference for it. We never see or store your card number.
- Device and technical
- IP address, browser or device type, and app version.
- Records of your sign-in sessions, and a security log of account events such as sign-ins, password changes and deletions.
- If you turn on push notifications: the notification token your phone issues, its platform, the device’s name, the app version and language.
- Applications and the waiting list. If you apply to test Coneker, what you type into the form: your name, email address, and optionally your device, another way to reach you, how you heard about us and what you would use Coneker for. If you try to sign up while Coneker is full, we record your verified email address and name on the waiting list.
Information about other people
Most of what you record in Coneker is about other people: contacts, business cards, notes about meetings, recordings of conversations. You decide what goes in, and you are responsible for having the right to record it.
- Recording. In many places, recording a conversation lawfully requires the consent of everyone in it. Tell people when you record them, and follow the law where you are and where they are.
- Purpose. Record only what you are entitled to hold, and use it for your own personal and working relationships. Do not use it to track, profile or harass anyone.
- Our role. We store and process this information on your behalf, only to provide Coneker to you. We do not contact the people it is about, and we do not build profiles of them. We do not combine one account’s records with another’s, except when you share something with a friend.
If you believe a Coneker user has recorded information about you, email us. We cannot show you another user’s account, but we will look into it and act where the law requires, including by removing the information.
How we use it
- To run Coneker. We store your graph, extract people and connections, answer your questions, transcribe and translate, find insights, sync your devices, and deliver messages and notifications.
- To keep accounts safe. This covers sign-in checks, the security log, rate limits, and investigating misuse.
- To contact you. We send sign-in codes, security and account notices, receipts, and emails or push notifications about friend activity. You can turn push off in Settings.
- To improve how well Coneker reads a note. We count how often its proposals are kept or corrected. When at least three accounts have independently corrected the same kind of word in the same way, an operator may see that word. They never see a person’s name or the note it came from, and they use it to improve the built-in rules for everyone.
- To meet legal obligations, and to handle refunds, chargebacks and disputes.
We do not use your content for advertising or profiling, we do not train AI models on it, and we do not sell or rent personal data.
Files: what is kept, and what is not
- Photos you scan or attach to a capture are stored with that capture, including a cropped image of each business card. They are deleted when you delete the capture or your account.
- A capture you started but never saved is kept as a draft, text and photos included, so you can come back to it. Unsaved drafts are deleted after 30 days.
- A document you upload is converted to text and the file is dropped. The text is kept with the capture. A PDF with no text in it is turned into images of its pages on our server; those images are sent to our AI model provider to be read, and then they and the file are dropped.
- A dictated note is uploaded and transcribed, and then deleted. That includes a voice note you share into Coneker from another app. The recording is removed from your phone as soon as it has been sent, and from our server once it is transcribed. Our speech provider deletes its copy after transcribing it. The transcript is kept.
- A meeting recording is kept. We store the audio as well as the transcript, so you can play it back and have it transcribed again if the first pass got a name wrong. This is a change from earlier versions of Coneker, which kept no audio. Delete the meeting and the recording goes with it.
- A file attached to a chat message is the message itself, so it is kept so the other person can open it. It is deleted when the message or the conversation is.
What other people can see
- Friends see your name, job title and profile photo. A person you send a friend request to also sees your email address. Anyone who has your friend code can see your name and photo when they send you a request.
- Invitations. If you invite someone by email, we email them your name and your message. We keep their address for up to 90 days so they can accept.
- Sharing. When you share a record with a friend and they accept, a copy is added to their graph, labelled as shared by you. The copy includes the record’s details and up to 50 of its connections. Sharing a meeting copies its transcript, not its recording. The copy belongs to your friend. It stays with them if you later delete the original or your account.
- Messages are stored so the people in the conversation can read them, and each person also has a short preview of the latest one. In a group conversation, every member can read what is sent, including members who are not your friends.
- Coneker staff. Our admin tools show the account details needed to run and secure the service: your email, name, job title, photo, sign-in methods, sessions, usage figures and any application. They also show the security log, with IP addresses and device types. They do not display your graph, your notes or your messages.
Features on your device
Calendar. Coneker reads your device calendar only if you grant permission, and only to show today’s events beside the people they involve. Your events are never uploaded, never stored on our servers, and never sent to any third party. The merge happens entirely on your phone. You can revoke calendar access at any time in iOS or Android Settings. A browser cannot read a device calendar at all, so this applies to the phone only.
Coneker never writes to your calendar by itself. When a capture produces an event, Coneker hands it to your operating system’s own “new event” sheet, which you confirm. If you have not granted calendar access, it gives you an ordinary .ics file through the share sheet instead. Coneker does not hold permission to add, change or delete calendar entries on its own.
Location and weather. Coneker uses location only if you turn weather on. Your phone then does two things:
- It rounds your position to about a kilometre and asks the weather service directly.
- It turns your position into a place name using its own operating system’s service: Apple on iPhone, Google on Android.
Your position is never sent to Coneker.
Camera, microphone and photos are used only when you scan, record, dictate or pick a photo. While a meeting is recording, the microphone stays on in the background, and your phone shows that it is.
Contacts. Coneker does not read your phone’s address book.
On your device. To load quickly, the app keeps your Ask conversation history and a copy of recently viewed parts of your graph on your phone. On the web, the history is kept in your browser’s storage. This copy is protected by your device’s own lock, not by Coneker’s app lock, and it is erased when you sign out.
Service providers
These companies process data for us, each only for the role shown.
| Provider and role | What it receives | Where |
|---|---|---|
| Amazon Web Services hosting, database, email delivery | Everything stored in your account, and the emails we send you | India |
| Alibaba Cloud (Qwen models) AI model |
| Hong Kong |
| Soniox speech-to-text | The audio of dictated notes, voice notes you share in, and meetings. With each recording, up to 80 names from your graph, to help it spell them correctly | United States |
| Apple and Google push notifications | The notification token and the notification itself, for example a friend’s name and “sent you a message”. Never the message’s content | United States |
| Stripe payments on the web | Our internal account number and what you are buying. Stripe collects your email and card itself | United States |
| Apple App Store purchases | Apple handles the purchase under its own terms. We receive the transaction record | — |
| Open-Meteo weather, if on | Your position, rounded to about a kilometre, sent from your phone directly | Europe |
| CARTO map images | The area of the map being drawn, sent from your phone directly. Like any website, it also sees your IP address and device type | Worldwide network |
| OpenStreetMap (Nominatim) address lookup | The address of a place you saved that has no map coordinates. Only the address fields, never the name you gave the place. We keep the result | Europe |
Our agreements with our AI and speech providers do not allow your content to be used to train their models. They process it to return a result to us. Some keep request data briefly, under their own terms, for abuse monitoring or until processing finishes. Results are stored in your account, not with them.
Some actions hand information to another company’s service directly:
- Tapping “Open in Maps” gives the place’s name and address to the map app you choose, such as Apple Maps, Google Maps, Amap or Baidu Maps.
- Signing in with Apple or Google involves that company.
Their own privacy policies apply.
You are asked before anything goes to an AI service
In the Coneker app on a phone, the first time you do something that needs an AI service — capture a note or a card, ask a question, dictate, or record a meeting — the app first tells you what it sends and names who receives it: Alibaba Cloud (Qwen) and Soniox. It asks you to agree. Nothing is sent to them until you do. Where each one processes your data is in the table above.
If you decline, Coneker keeps working — your people, your places, your events, your calendar and your search are all on your own device or on our servers and involve none of those companies. What stops working is the part that needs a model to read: capturing a note or a card, asking a question, dictating, and transcribing a meeting.
You can read the notice again, and withdraw your agreement, at any time under Settings ▸ Privacy & security ▸ “What Coneker sends to AI”. Withdrawing takes effect immediately for anything sent afterwards; it cannot recall something already sent. If we add a provider, or start sending a provider more than it receives today, you will be asked again rather than told quietly.
Your answer is also recorded with your account — which version of the notice, when, and whether it came from an iPhone or an Android phone — so that we can show it was given. The record is removed when you delete your account; the security log keeps the dated entry, like your other account changes.
When Coneker reads the open web
Two features can search the web, and both go through Alibaba Cloud (Qwen), the same AI service named on the notice above. The insights search is currently switched off.
- Insights can be set to search for publicly available information about organizations, topics and places you have written about. It is currently switched off, so insights read only your own notes and graph. When it is on, each search is about one subject, never two joined together. A record Coneker has identified as a person is never searched. A subject’s name is sent exactly as written, so a place or organization named after someone (say, “Wing’s flat”) is searched under that name.
- Ask has a web search switch beside the question box. It is off until you turn it on, and it stays as you leave it. Searches happen only while it is on, and use your question plus up to three earlier questions from the same conversation, so a follow-up like “look that up” can be understood. Those questions may contain names you typed. Your graph, your notes and your friends are not sent to the search.
Nothing found on the web is stored in your graph. It can never become a citation either, because a citation is a record number our own server issued.
International transfers
We are a Hong Kong company, but our servers are in India, and our providers operate in Hong Kong, the United States and Europe (see the table above). So your data is transferred to, and stored in, places outside where you live, whose laws may protect it differently. We use providers whose terms include data-protection commitments. Where the law requires a safeguard for a transfer, we rely on the mechanisms those terms provide, such as standard contractual clauses.
When we disclose information
We do not sell personal data. We disclose it only:
- to the service providers above, to run Coneker;
- when you ask us to, for example by sharing with a friend or sending a message;
- when the law requires it, such as a court order or a lawful request from an authority. We resist requests that are overbroad and, where we are allowed to, we tell you;
- to protect people, to prevent fraud or abuse, or when we believe someone’s safety is at serious risk;
- if FUNTG Limited is part of a merger, acquisition or sale of its business. Your data would pass to the new owner under this policy, and we would tell you before anything about it changes.
How long we keep it
| What | How long |
|---|---|
| Your account, graph, captures, photos, meetings and messages | Until you delete them or your account |
| Unsaved capture drafts, with their photos | 30 days |
| Nightly backups of the database and photos | 15 days. Something you delete can remain in a backup for up to 15 days, then it is gone. Meeting recordings and chat attachments are not backed up, so a restore could bring back a message without its attachment |
| Server logs (IP address, device type, the page or feature requested) | Overwritten automatically, currently after about two weeks. We do not archive them |
| Security records: sign-ins, sessions and account changes, with IP address and device type | Kept after your account is deleted, to investigate abuse and answer legal requests |
| Purchase records | As long as tax and accounting law requires, and at least 7 years |
| Invitation codes: who invited whom | Kept, as the record of how an account came to exist |
| Email addresses you invited who have not joined | Up to 90 days |
| Applications and the waiting list | Until you ask us to remove it, or we do. Deleted with your account |
| Copies of records a friend accepted from you | Theirs, kept in their account |
When an account is deleted, a placeholder for it remains, holding no email, name or photo. It keeps the payment processors’ references, so a late renewal or a refund can still be matched. The security and purchase records above also remain.
Your rights and choices
- See and take your data. Settings ▸ Export (on the web, Settings ▸ Your data) gives you a single file. It contains your records, connections, captures and their text, meeting transcripts, your friends list, activity and usage. It does not contain photo files (it links to them), meeting recordings, chat messages and attachments, saved views or capture rules. Email us for a copy of anything the file leaves out.
- Correct it. Edit it in the app, or email us.
- Delete it. In the app, go to Settings ▸ Security & sign-in ▸ Delete account. On the web, go to Settings ▸ Your data ▸ Delete account. Or email us: we will confirm it is you and complete the deletion within 30 days.
- Deleting your account cancels a Coneker Pro subscription paid on the web.
- A subscription bought through the App Store must be cancelled in your iPhone’s Settings. Deleting your account does not stop Apple’s billing.
- Change your mind. You can turn off location, calendar, notifications, microphone and camera access, and Ask’s web search, at any time.
- Hong Kong. You may ask to access and correct your personal data. We will answer within 40 days, and we may first need to confirm who you are.
- EU, UK and elsewhere. You may also have rights to erasure, restriction, portability and to object.
- We rely on our contract with you to provide Coneker.
- We rely on our legitimate interests to keep it secure and improve it.
- We rely on legal obligations for tax and legal requests.
- We rely on your consent for device permissions and optional features. You can withdraw that consent at any time.
- Complaints. Please contact us first. You can also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong, or to the data-protection authority where you live.
Cookies and browser storage
This website, coneker.com, sets no cookies and runs no analytics. The web app at app.coneker.com uses only cookies it needs to work:
coneker_web_rtkeeps you signed in. It lasts 30 days from your last visit, and you sign in again at least every 90 days.coneker_web_devremembers, for 30 days, that you verified this browser with an emailed code.
The web app also keeps your Ask history in your browser’s storage and clears it when you sign out. It remembers your language and a few display choices there too. There are no advertising or tracking cookies. Apple’s and Google’s sign-in code loads only if you choose to sign in with them.
Security
We protect your data in these ways:
- All traffic is encrypted in transit (TLS).
- Access to your data is scoped to your account.
- Sessions are short-lived and rotated.
- Passwords are stored only as scrypt hashes.
- You can lock the app with Face ID or a passcode, and add a passkey on the web.
No system is perfectly secure, and we cannot guarantee that yours will never be accessed without permission. If a breach affects your personal data, we will tell you, and the authorities where the law requires, without undue delay.
Children
Coneker is for people aged 16 and over. We do not knowingly collect data from anyone younger. If we learn an account belongs to someone under 16, we will delete it.
Changes
We will post any new version of this policy here with a new effective date. For a material change, we will tell you in the app or by email before it takes effect. A material change means, for example, collecting a new kind of data, using it for a new purpose, or giving it to a new kind of recipient.
Language
This policy is published in English and Traditional Chinese. If they differ, the English version prevails.
Contact
Contact FUNTG Limited, attention Privacy Officer, by email at support@funtg.com.