Last updated: September 26, 2026
ContactLogo ("we", "our", or "us") matches business contacts to public brand marks so your address book shows a logo instead of grey initials. This policy covers the web app at contactlogo.com, the iOS app, the macOS app, and the Android app.
Imported vCards and CSVs are reviewed in the browser. Google Contacts import reads contacts from Google when you choose it; selected-photo sync sends approved updates back to Google. Logo requests use business domains and can reach external image services.
ContactLogo does not create accounts. We do not store your address book, and we do not sell contact data. Closing the web tab leaves the imported book behind in that session only.
To find a mark, the app may request a public image using only a sanitized business domain (for example fedex.com), never a person's name, email, or phone. Depending on the surface and your settings, those lookups can reach:
cdn.simpleicons.org)raw.githubusercontent.com)logo.clearbit.com)t1.gstatic.com)icons.duckduckgo.com)The first-party logo cache and external image services can receive the business domain and standard request metadata (such as IP address and user agent). ContactLogo does not send the imported address-book file as a logo request.
If you tap Import Google Contacts or Apply to Google Contacts, the browser talks to Google using OAuth. Scopes cover reading your Google Contacts and, when you choose write-back, updating contact photos you approved. Google is the processor for that data. ContactLogo never sees the OAuth refresh token on a ContactLogo server, because there is no ContactLogo account server.
When public keys are configured for a build:
alt text is off. Session Replay is off.If those keys are absent, telemetry stays dark. Telemetry payloads are not supposed to include contact display names, emails, phone numbers, or photos. Logo CDN URLs keyed by domain may appear in resource timing.
The native apps read the on-device Contacts database with system permission. Applied logos are written back as contact photos. Undo, where implemented, keeps prior photo bytes in app-private storage on the device, not in iCloud or Google Drive. Android backup of that private store is disabled.
The web app may keep an optional Google client id in this browser's storage so you do not re-paste it. Native apps may keep Brandfetch keys in the system keychain. There is no advertising cookie and no cross-site tracker.
Questions: support@contactlogo.com. You can also open an issue on the public GitHub repository. See also the Terms of Use.