Foundit Privacy Policy
This policy explains the information handled by the Foundit mobile app. It should be read together with the Parent and Child Safety Notice.
This policy covers Foundit during its Friends & Family testing phase.
Effective date: August 23, 2026
Found It Labs LLC ("Foundit," "we," "us," or "our") provides a family scavenger-hunt application that lets an adult set up a hunt and a player find photographed objects.
1. Important notice for parents and guardians
Foundit is designed for family use with adult involvement. Adults should create hunts, choose whether to use AI naming, decide whether to share a hunt, and supervise children.
The in-app arithmetic adult gate is intended to reduce accidental access to adult actions. It is not a substitute for parental supervision and is not represented as verifiable parental consent under law.
2. Information handled on the device
The app may store the following in its private application storage:
- hunt names, item names, clues, and progress;
- photos an adult takes of hidden items;
- photos a player takes when finding items;
- imported copies of a shared hunt; and
- settings and local achievement/passport progress.
Found-item photos are designed to remain on the device and are not uploaded by Foundit application code. Deleting the app may delete locally stored information, subject to the device platform's behavior and backups.
3. Information processed online
Optional AI item naming
When an adult chooses to identify a hidden object, the selected hidden-item photo is resized and sent through Foundit's authenticated Supabase function to the configured AI service. The service returns a suggested item name. Foundit application code does not intentionally store that photo in Foundit cloud storage as part of AI naming.
Private cross-device sharing
When an adult deliberately shares a hunt, Foundit processes:
- hunt and item names;
- clues;
- resized hidden-item photos;
- an opaque share identifier and related security/expiration metadata; and
- a persistent anonymous installation identifier used to authenticate and protect the share.
Found-item photos are not included. QR codes and links contain only an opaque, revocable share code—not photos, hunt text, or storage paths. Shared hidden-item photos are stored in a private bucket. Redemption uses temporary signed image links valid for 10 minutes; the receiving device downloads the images and does not persist the signed links.
Reliability and security information
Foundit may process limited technical information needed to operate and secure the service, such as request timing, rate-limit counters, status/error codes, app version, device/operating-system type, and crash information.
Sentry crash reporting is configured not to attach user identity, screenshots, screen/view hierarchy, console logs, session replay, or performance traces. Foundit also applies filters intended to remove hunt names, item names, clues, photos, URLs, location fields, credentials, and share codes from crash context. No technical safeguard can guarantee that an unexpected error will never contain unintended information.
Notifications
If notifications are enabled, the operating-system and notification providers may process a device notification token and delivery metadata.
4. How information is used
Foundit uses information to:
- provide, secure, and troubleshoot the app;
- name an adult-selected hidden item when the adult requests AI assistance;
- create, redeem, revoke, and delete private hunt shares;
- prevent abuse through authentication, limits, and security logs;
- send enabled service notifications; and
- comply with law and protect users, Foundit, and others.
Foundit does not use personal information for targeted advertising and does not sell personal information.
5. Service providers
Foundit uses service providers that process information on our behalf, including:
- Supabase for authentication, database, private storage, and Edge Functions;
- the configured AI provider for adult-requested hidden-item naming;
- Sentry for privacy-restricted crash/error reporting;
- Expo and Apple/Google platform services for app delivery and notifications, as applicable.
6. Retention and deletion
- Same-device hunt data remains on the device until deleted in the app, removed with the app, or affected by device backup/restore behavior.
- Shared server copies expire automatically no later than 30 days after creation, through a scheduled and verified deletion process, and can be deleted sooner by the adult.
- Temporary signed image links expire after 10 minutes.
- Security and crash records are retained according to operational need and configured provider retention.
We retain information longer when reasonably necessary for security, fraud prevention, legal obligations, or dispute resolution.
7. Parent and consumer choices
Adults can:
- avoid AI naming and enter an item name manually;
- keep a hunt only on one device;
- revoke/delete an active share;
- delete hunts and imported local photos in the app;
- disable notifications in device settings;
- delete their account at any time, directly in the app, from the account/settings area — this permanently deletes the adult's account through an authenticated server-side process that only ever deletes the account making the request; the app's local data is cleared only after that deletion is confirmed; and
- request access, correction, or other applicable privacy rights, or get help with deletion, by emailing privacy@gofoundit.com.
We may need to verify the requester's identity and authority for an emailed request. A child should ask a parent or guardian to contact us. We will not require a new account solely to submit a privacy request.
8. Children's privacy
We seek to minimize children's information and keep found-item photos on-device. We do not knowingly sell children's personal information or use it for targeted advertising.
If we learn that information was collected from a child in a way that requires parental authorization and authorization was not obtained, we will take appropriate steps, including deletion when required. Parents may contact us at privacy@gofoundit.com to review or request deletion of a child's information.
9. Security
We use safeguards including private storage, authentication, expiring signed links, opaque share codes, rate limits, input validation, restricted service credentials, and privacy-filtered error reporting. No system is completely secure. Adults should share codes only with intended recipients and delete shares when no longer needed.
10. U.S. state privacy rights
Depending on where you live and whether a law applies to Foundit, you may have rights to know, access, correct, delete, or obtain a copy of personal information and to opt out of certain processing. Foundit does not currently sell personal information, use it for targeted advertising, or profile users for decisions producing legal or similarly significant effects.
Texas residents may contact us using the method below.
11. International use
Foundit is operated from the United States.
12. Changes
We may update this policy. If a change materially affects information collected from children or a parent's prior authorization, we will provide any notice and obtain any renewed consent required by law before applying that change.
13. Contact
Found It Labs LLC
14205 N Mo Pac Expy Ste 570
Austin, Texas 78728
Email: privacy@gofoundit.com
No public telephone number is published for Foundit at this time; email is the current contact channel.