Privacy policy
What FindMore collects, and why.
- You need an account. We store your name, email address, and sign-in sessions.
- When you run a tool, we store what you entered and the result for 30 days, then delete them automatically.
- Every lookup is performed by our server against public data sources. The app itself never contacts those sources.
- We do not run analytics or advertising SDKs, and we do not sell or share your data with data brokers.
- You can delete your account, and everything with it, from inside the app at any time.
What we collect
Account
Your name, email address, and password (stored as a hash), or the identifier returned by Google or Apple if you sign in with them. Sessions record the IP address and device description of the sign-in so you can recognise them; sessions expire after 30 days.
Tool runs
The input you enter (a domain, email address, handle, or IP address) and the normalized result, including the findings shown in the app. If you run the IP address check without entering an address, the result records the public IP address of your connection, its reverse DNS name, and its approximate city and country, but never coordinates. Runs are kept for 30 days and then deleted by a scheduled job; you can delete any run sooner.
Notifications
If you turn on completion notifications, we store the push token for that device so we can send a short alert when a queued scan finishes. The alert never contains what you searched. Turning notifications off, or signing out, removes the token.
What we do not collect
No advertising identifiers, no analytics events, no contacts, no location from your device. The server logs operational errors without your search inputs.
Where lookups go
To answer a check, our server contacts the following services. What each receives is limited to the identifier you entered.
- Cloudflare. Hosts the FindMore server (Workers, Queues, Hyperdrive) and performs DNS lookups over HTTPS.
- Supabase. Hosts the database that stores accounts, sessions, and your 30-day history.
- Expo. Delivers push notifications when you turn them on. Notification text never includes what you searched.
- Public DNS, RDAP, and certificate transparency logs (rdap.org, crt.sh). Used for the domain, certificate, registration, and IP address tools.
- Internet Archive. Used to find archived copies of a site.
- RIPE NCC (RIPEstat). Used for routing and approximate location of an IP address.
- Gravatar. Used only to check whether a public avatar exists for an email address; the address is hashed first.
- GitHub. Used for the GitHub exposure tool and the GitHub check inside username presence.
- Have I Been Pwned. Used for the breach exposure tool. The address you enter is sent to their API.
- Hudson Rock. Used for the infostealer exposure tool. The address you enter is sent to their API; they return credentials already masked.
- The public sites checked by username presence. Each receives a request for the profile page or public API of the handle you enter, and nothing else.
The catalog currently holds 14 tools; any tool added later will be listed here before it is released.
How long we keep things
- Tool inputs and results. 30 days, then deleted automatically.
- Sessions. 30 days of inactivity, or until you sign out.
- Account details and push tokens. Until you delete the account or the token.
Your choices
- Delete any result from its detail screen, or delete your whole account from the Account tab. Deletion is immediate and removes history, saved results, sessions, and device registrations.
- Notifications are off by default and can be switched off at any time.
- Sensitive tools ask you to confirm that the identifier is yours or that you are authorized to check it. See the acceptable use policy.
Contact
Questions or requests about your data: privacy@findmore.me.
Changes to this policy will be published on this page with a new effective date.