Privacy Policy
ELSEFOUND is designed to use only the information needed to provide small quests and FOUND records.
1. Archive and session
ELSEFOUND uses a session identifier to maintain Archive continuity, including Guest Archives. The mobile app uses WebKit's persistent website data store so normal app termination and relaunch do not intentionally clear the session.
If you preserve an Archive with an external identity provider such as Google, an immutable provider identifier may be used to link the Archive. ELSEFOUND does not collect your Google password.
2. Location
The mobile app uses device location only when you explicitly choose Find current city.
Precise GPS coordinates are processed on-device to suggest a city and are not sent to or stored on ELSEFOUND servers. City, administrative-area, and country text that you select or confirm may be sent to the service.
3. FOUND and public records
A FOUND may contain quest, time, city, visibility state, and optional information you add such as one line or a photo.
A FOUND set to public can be viewed by other people. Visibility and record-removal controls follow the current controls and policies shown in the service.
4. Photos
Photo access is used only when you explicitly choose to add a photo to a FOUND record. Camera or photo-library permission is requested only when that feature is used.
5. Notifications
Notification permission is not requested merely because the app launches. System permission is requested when you choose to allow notifications in Settings.
Current mobile defaults are Signals on, with Events, World Quests, and Quest-ready notifications off. Each category can be changed by the user.
6. Technical logs and security
For operation and security, a request IP address may be processed by Cloudflare for request delivery and short-window rate limiting. ELSEFOUND does not write raw IP addresses to its application observability logs or D1 database.
ELSEFOUND is designed without advertising-tracking identifiers and does not sell location, Archive, or FOUND data for advertising.
7. Account and Archive deletion
In the mobile app, you can start deletion from Settings > Delete Archive / Account. Deletion removes callsigns, one-line text, photos, external links, authentication links, sessions, and other account-linked information.
Issued FOUND numbers, World/Country/City ordinals, event_id, quest/city/time facts, and Certificates are preserved permanently as anonymous records to maintain record integrity and prevent number reuse. A deleted FOUND number is never issued again.
8. Contact and changes
This policy may be updated as features or legal requirements change. Material revisions will update the date shown on this page.
Operations and privacy contact: found@elsefound.club