Last updated: 14 September 2026
NFound is a lost-and-found service run by NFound Samaritan Project, a nonprofit organisation based in California, United States ("NFound", "we", "us"). This policy explains what we collect when you use the NFound app and website, why, who we share it with, how long we keep it, and the choices you have. It applies to the NFound mobile app, the tag landing pages at nfound.org, and the staff console.
If anything here is unclear, write to privacy@nfound.org.
1. What we collect
Account. The phone number you sign in with (verified by SMS code through Google Firebase), the display name you choose, an optional email address and profile photo. We never see your password — there isn't one.
Reports. The title, description, category, photos, an optional reward and the map location of every lost-or-found report you publish. Reports are public: anyone using NFound near that location, and anyone with the link, can see them. Public views show the location rounded to roughly 100 m; signed-in users and staff see the exact pin.
Location.
- - *While you use the app* — to centre the map, show nearby reports and let you pin a report.
- - *In the background, only if you turn on "Share my location" in a tracking group* — your position is sent to our servers roughly every 10 metres of movement, even when the app is closed, and shown live to the members of that group. A persistent notification is displayed on Android while this is on. You can turn it off per group at any time.
- - *Route history, only if you also turn on "Save my route" for a group* — the trail of positions for that group is kept for 14 days and visible to that group's members and to you. Turning it off removes the past trail from the group's view; you can also erase it yourself.
- - *During an SOS* — your live position is sent to the people you chose to alert (see §4) until you mark yourself safe.
- - *Home area* — if you set one, the rough centre and radius you chose, used only to decide which "nearby" alerts to send you.
Emergency contacts. The names and phone numbers you enter under *Emergency contacts*. These are other people's details; by entering them you confirm you may share them with us for this purpose. They are used only to reach those people when you raise an SOS.
Messages and calls. Text, photos and voice messages you send in chats; the fact, time and participants of audio/video calls (call audio and video are not recorded or stored). Messages you delete are removed from view; the conversation record keeps a placeholder.
Purchases and donations. When you order QR tags: the items, the shipping name, address and phone you enter, and the order history. When you donate: the amount. Payment card details go directly to Stripe and never reach us. We receive from Stripe a payment reference, the payment status, and dispute or refund notices.
Device and technical. An installation identifier, push-notification tokens, your app version and platform, the times you use the app, and standard server logs (IP address, requested pages, timestamps). If you report a problem from inside the app, the message you write plus your app version and device model.
Tag scans. When anyone scans a physical NFound tag, we record that the tag was scanned and when. If the scanner is signed in, we record who scanned it; a stranger scanning a tag is not identified.
We do not use third-party analytics or advertising SDKs, and we do not sell personal information.
2. Why we use it
- - To run the service: publish reports, show the map, deliver messages, calls, alerts and SOS.
- - To notify you: replies, sightings, nearby reports (if you set a home area), incoming calls, SOS from people you are connected to, order and shipping updates.
- - To fulfil orders and process donations, and to keep records the tax and payment rules require.
- - To keep NFound safe: rate limiting, abuse and fraud detection, moderation of reported content, and enforcing our Terms.
- - To understand use of the service in aggregate (counts of active users, posts, scans) — never by profiling individuals for advertising.
3. Who can see what
Data — Who can see it
Your report (text, photos, rounded location) — Everyone; exact location: signed-in users and staff
Your display name and photo — Other users you interact with, group members, staff
Your phone number — Only you and staff (and, if you register a tag with contact details, whoever scans that tag)
Live location / route history — Members of the group you shared it with; you; staff on request
SOS position — The people you chose when raising it; staff
Messages — The other participants; staff when a message is reported
Shipping address — Staff who pack orders; the courier
Emergency contacts — Only you and staff
Service providers that process data for us, under contract, only as instructed: Amazon Web Services (hosting, storage, email), Google Firebase (phone sign-in, push notifications), LiveKit (audio/video calls), Stripe (payments), Twilio (SOS text messages, where enabled), Google Maps Platform (maps, address lookup). Each sees only what its job needs.
Legal. We disclose information when the law requires it, to protect someone's life or safety, or to enforce our Terms.
4. SOS
When you raise an SOS you choose who is told: your emergency contacts (by text message and, if they use NFound and you follow each other, by in-app alert), the tracking groups you pick, and — if you opt in — NFound volunteers within about 5 km whose location is recent. All of them receive your name, your position and a map link, and can say they are on their way. When you mark yourself safe, the same people are told. SOS records are kept for 90 days.
5. How long we keep it
Data — Kept
Account — Until you delete it
Reports — Until you remove them; removed reports are retained for moderation and legal purposes, not shown
Route history — 14 days
Live position — Overwritten as you move; removed when you stop sharing or leave the group
Notification history — 90 days
Messages — Until deleted by you or the conversation is removed
Orders and donations — 7 years (accounting), anonymised after account deletion
Server logs — 30 days
Photos you upload but never attach — 24 hours
6. Your choices and rights
- - Delete your account in *Settings → Delete account* (you will be asked to verify your phone again). Your account, reports, group memberships, location data, messages you sent (their content is removed; the conversation keeps a placeholder), emergency contacts and photos are deleted; orders and donations are anonymised and kept as accounting records. You can also request deletion at <https://admin.nfound.artsol.dev/account-deletion> without the app.
- - Location and notification permissions can be revoked in your device settings at any time; background sharing can be turned off per group in the app.
- - Access, correction, portability, objection — write to the address above. Residents of the EEA/UK have these rights under the GDPR; California residents have equivalent rights under the CCPA. We answer within 30 days and do not discriminate for exercising them.
7. Children
NFound is not for children under 13, and we do not knowingly collect their data. If you believe a child has an account, tell us and we will delete it.
8. Security
Data travels over TLS. Sessions can be revoked instantly from our side. Card data never touches our systems. Access to personal data is limited to staff who need it, and staff actions are logged. No system is perfectly secure; if a breach affects you we will tell you as the law requires.
9. International transfers
Our servers are in the United States (AWS, us-west-1). If you use NFound from elsewhere, your data is transferred to and processed there.
10. Changes
We will post changes here and, for material changes, tell you in the app before they take effect.
11. Contact
NFound Samaritan Project · California, United States · privacy@nfound.org