Back to Found

Legal

Privacy Policy

Last updated: August 2026

Found is a sapphic-centered community, built around queer women and sapphic people connecting IRL. We take your privacy seriously. This policy explains exactly what we collect, why, and what you can do about it.

Who we are

Found Social Club, a California corporation ("we," "our," or "us"), operates Found, a dating and social app centered on the sapphic community: queer women and sapphic people of all identities, including non-binary and trans members of the community, aged 18 and older, who want to date, meet friends, and connect over real, in-person events. References to "Found" in this policy mean the Found app and the services we provide through it. This Privacy Policy explains what personal information we collect, how we use it, and your rights and choices. We wrote it in plain language on purpose — we want you to actually read it. This policy is a notice that describes what we actually do; it is not a contract. Where the law calls for your consent to something specific, such as the biometric release before your verification selfie, we ask for it separately in the app at the moment it applies. Questions? Contact us at privacy@foundsocialclub.com.

Information you give us

When you create an account or use Found, you may provide: • Identity: Name, age, pronouns, sexual identity • Contact: Phone number and/or email address • Location: The city you select during onboarding, used to show you relevant local events • Profile content: Photos, bio, interests, and what you're looking for • Social: Your Instagram handle, if you choose to add one — it's shown on your profile to other members, just like your photos and bio • Selfie photo: A photo taken during photo verification to confirm you match your profile photos • Communications: Messages you send to other members • Event activity: Events you RSVP to • Reports: If you report a member or an event, we collect the report and what you tell us in it • Support requests: Messages you send to our help, privacy, or safety addresses, and anything you submit through our contact forms You choose what to share on your profile. The more you add, the better your experience — but most fields are optional.

Biometric Data Notice (photo verification)

To protect the safety of our community, Found requires new members to submit a selfie photo during account setup.

Your written release. Before your camera opens, we show you this notice in the app and ask you to agree to it. We do not collect, capture, or process any face data until you do. Agreeing is your choice — you may decline, though you will not be able to finish verification without it. We record the date you agreed and the version of this notice you were shown.

How we handle your selfie: • Your selfie is stored in a private, encrypted storage system on our secure servers — never publicly accessible • Only authorized members of Found's team with a business need can view your selfie, solely to compare it against your profile photos during review. That access requires multi-factor authentication, is restricted by role, and is logged • Found uses automated facial recognition technology provided by Amazon Web Services (Amazon Rekognition) to assist with photo verification. Two operations are performed: face detection, which confirms your selfie contains a human face at all, and face comparison, which measures how closely your selfie matches your profile photos • Your selfie is never shown to other members, used for advertising, or sold to third parties • You may request deletion of your selfie at any time by emailing privacy@foundsocialclub.com

What we collect. Facial recognition technology processes data derived from your face geometry. Found uses it for one purpose only: confirming that the person in your verification selfie is the same person in your profile photos. The comparison returns a similarity score and nothing else. Neither Found nor our processor enrolls your face in any searchable database, face collection, or watchlist, and we never use it to identify you anywhere else.

How long we keep it.

Your verification selfie: deleted as soon as your profile is approved or declined. If your profile is still awaiting review, the selfie is deleted automatically 30 days after it was taken, whether or not review has finished — no verification selfie is retained beyond 30 days under any circumstances.
Face geometry data: never stored by Found. It is processed to produce the similarity score and is not written to our systems in any form. We do not keep a face template or any other biometric identifier derived from your selfie.
The result of the check: the numeric similarity score is erased when your application decision is final, at the same moment your selfie is deleted, and never survives beyond 30 days. Only the pass or fail verdict is kept, for as long as your account exists; after account deletion it survives only with your consent record as described below.
Your record of consent: the date you agreed to this notice and the version you were shown. Kept for as long as your account exists, and retained after your account is deleted as evidence that consent was given.

Destruction. Erasure happens on the schedule above without you having to ask. Deleting your account erases your selfie and any biometric data derived from it, subject to the 30-day grace period described in “Deleting your account.” The record that you consented (the dates and notice versions, with the pass or fail verdict) is retained as evidence that the release was given.

We never profit from it. Found does not sell, lease, trade, or otherwise profit from your biometric data, and we do not disclose it to anyone except the processor named above who performs the comparison on our behalf.

This notice is the written policy describing our retention schedule and destruction guidelines for biometric identifiers and biometric information.

Information we collect automatically

When you use Found, we collect: • Device information: Device type, operating system, and app version • Usage data: Features you use, screens you view, and how you interact with the app • Push notification tokens: To deliver the alerts described below (only on iOS, and only with your permission) • Server logs: Like nearly every online service, our servers log technical details of requests — your IP address, timestamps, and, for failed login attempts, the email tried. Logs exist for security and debugging and are kept only as long as that purpose needs • Purchase records: Which products you bought and when, through receipts and transaction identifiers from Apple and RevenueCat. We never see or store your payment card details • Identifiers and audit records: An internal account ID that ties your data together, and logs of administrative actions taken on accounts (such as approvals or removals), kept so those actions can be reviewed • Crash and error reports: To fix bugs and improve reliability. A report contains technical diagnostics: the error message and stack trace, the error type, the app version, and your device's operating system and version (for errors on our website, the page address and browser version instead). We do not attach your name, account, or messages to reports, and error text is automatically scrubbed of email addresses and long numbers on your device before anything is sent. Reports are processed on our behalf by a service provider Location works like this: if you allow it, we access your device's location once, during signup, to suggest your city. The coordinates are converted to a city name using OpenStreetMap's reverse-geocoding service, which is sent only the coordinates for that one lookup, never your name or profile. Precise coordinates are not retained: Found stores your city and a position rounded to roughly a kilometer, never your exact location. You can skip the suggestion entirely and type your city instead, and we never track your location in the background. Found does not use cookies, analytics trackers, or advertising SDKs.

How we use your information

We use your information to: • Create and maintain your account • Show your profile to other Found members at shared events • Enable matching and in-app messaging between members • Send push notifications you've opted into • Confirm you match your profile photos through selfie review and facial recognition technology (face detection and face comparison). Photo verification does not verify legal identity or age; our 18+ requirement is enforced separately, using the birthday you provide at signup • Show you events relevant to your city • Keep Found safe by detecting fraud, abuse, and violations of our guidelines • Improve the app based on how people use it • Comply with legal obligations We do not use your information to serve you third-party advertisements. We do not sell your data.

Who can see your profile

Different audiences can see different things. Here is the map: • Approved members: Your profile — name, age, pronouns, identity, photos, bio, Instagram handle (if added), interests, and what you're looking for — is visible to other approved members browsing Found, mainly in your city and at events you join. Your phone number, email address, and city are never shown to other members. • Matched and connected members: Messages you send are visible to you and the person you sent them to, and no other member can ever see them. The only exception is the narrow review described under Found's team below. • Event attendees: When you RSVP, members attending that same event can see that you're going. Members at that event with Elite or an Event Pass may also view the attendee list, including after the event ends. • Organizers: See how many members RSVP'd to their event, never who, and never your contact information, unless you separately match or connect with them. • Found's team: Reviews your application when you sign up, including your verification selfie, and looks at profiles and reports when moderating. We do not routinely read private messages; a specific conversation may be reviewed by authorized personnel only when a member reports it, when needed to protect members' safety or the security of the service, or where the law requires it. Administrative actions are logged. • Service providers: Process data on our behalf for the purposes listed in "Information we share." They do not browse profiles. Your selfie is stored privately and is never visible to other members under any circumstances.

Events on Found

Found is built around real-world events — but we don't run them. Events in the app come from a few places: verified organizers who post through our Organizer Portal, community members who submit events, and public listings we pull in from services like Ticketmaster. Found does not own, operate, staff, or control these events, their venues, or the organizations that host them. When you RSVP, your going/interested status is visible to other members attending that event. Organizers can see how many members RSVP'd to their event, but never your private contact information. If you buy tickets through a link in the app, you'll be taken to the organizer's or ticketing platform's own site (such as Ticketmaster), which has its own privacy practices — we encourage you to review them before purchasing. For your responsibilities, and ours, when attending an event hosted by someone else, see our Terms of Service.

Information we share

We do not sell your personal information. We share it only in these limited circumstances: • Infrastructure providers: We use secure cloud infrastructure to operate Found. Our providers process data on our behalf and are contractually prohibited from using your data for any other purpose. • Photo verification: We use Amazon Web Services (Amazon Rekognition) for automated face detection and face comparison. Amazon processes biometric data only as directed by Found, for photo verification only, and does not enroll your face in any collection or database. • Event organizers and ticketing platforms: See "Events on Found" above. • Payment processing: Subscription payments are handled by Apple (via the App Store) and RevenueCat. We share your member ID and purchase state with RevenueCat so purchases attach to your account. We do not receive or store your payment card details. • Notification and email delivery: Push notifications are delivered through Apple's push notification service using your device token. Emails from Found (login codes, required notices, certifications) are sent through our email delivery provider, which processes them on our behalf. • Safety and legal: We may disclose information if required by law, court order, or to protect the safety of our users or enforce our Terms of Service. • Business transfers: If Found is acquired or merges with another company, your information may be transferred. We will notify you before that happens. We do not share your data with advertisers.

Data retention

How long we keep each category: • Profile and account data: for as long as your account is active • Messages: permanently deleted one year after they are sent, even while your account stays active. We do not keep everyone's messages just in case • Verification selfie: until your application is reviewed, and never more than 30 days • Biometric data: never stored; it is processed only to produce the similarity score • Consent and notice records: for the life of your account, and after deletion as evidence the notices were given • Server logs: only as long as security and debugging need; they rotate out on a short schedule • Purchase and billing records: as long as tax, accounting, and dispute rules require • Reports and safety records: as long as an investigation or legal duty requires • Data exports you request: the download link and archive are deleted after 7 days When you delete your account, your profile disappears from Found straight away: nobody can see you, message you, or find you in search. Your account is then deleted 30 days later. If you change your mind during those 30 days, logging back in lets you restore it; after that the deletion is final and cannot be undone. When the 30 days are up, your profile, photos, verification selfie, messages you sent, matches, voice notes, and any data export you requested are erased from our servers. Any biometric data derived from your selfie is erased at the same moment, and in most cases the selfie itself is already gone, since we delete it as soon as your profile is reviewed. What deletion does not erase. A small set of records survives account deletion, each kept only as long as its purpose requires: • Consent and notice records: the dates and versions of the Biometric Data Notice you agreed to and the safety notice you received, with the pass or fail verification verdict. This is our evidence that the notices were given, kept in case of a later dispute. • Safety records: reports you filed or that were filed about you, and the record of any fraud-ban notice we sent, so that investigations and legal duties can be seen through. • Financial records: purchases are processed by Apple and RevenueCat, which keep their own transaction records; we keep what tax, accounting, and dispute rules require us to keep. • Disputes and legal holds: if information is relevant to an active dispute, investigation, or legal proceeding, or we are required by law, subpoena, or court order to preserve it, we keep it until the matter ends and the obligation lapses. • Backups: deleted data may persist for a limited time in system backups before cycling out. Backups exist for disaster recovery only and are not used to restore deleted accounts. A retained safety report is limited to the report itself, not your full profile. You can delete your account at any time in Profile → Settings → Delete Account.

Your rights and choices

You have the right to: • Access the personal data we hold about you • Correct inaccurate information in your profile • Request deletion of your selfie or biometric data without deleting your account • Delete your account at any time; deletion follows the 30-day schedule and the limited retention described above • Choose which push notifications you receive, by category, in Profile → Settings → Notifications • Withdraw consent at any time We offer every right above to every member, wherever you live. Found is currently below the size thresholds that make state privacy laws like the California Consumer Privacy Act apply to a business, so today these rights are voluntary commitments rather than statutory obligations. They work the same way either way: this policy tells you what we collect, you can request a copy of your data, request deletion, and we do not sell personal information. Canada: Canadian members have the rights federal privacy law (PIPEDA) provides: to access the personal information we hold about you, to correct it, to withdraw consent, and to complain to the Office of the Privacy Commissioner of Canada. Found's designated privacy officer is reachable at privacy@foundsocialclub.com. Found is offered in English and is not yet available in Quebec; before offering Found there, we will meet Quebec's French-language and biometric-declaration requirements. Illinois, Texas, and other biometric privacy jurisdictions: You have the right to request deletion of your biometric data (your selfie and any data derived from your face geometry) at any time by contacting privacy@foundsocialclub.com. You may also withdraw the consent you gave in the Biometric Data Notice at any time by the same route; we will stop processing and erase what remains, though your verified status may be affected. EEA, UK, and Switzerland: Found launches in the United States and is not currently offered in these regions. If we expand there, we will publish the full local privacy notice those laws require before accepting members. In the meantime, anyone can exercise the rights listed above by contacting privacy@foundsocialclub.com.

Push notifications

Found sends push notifications for the categories below, and you can turn each one on or off individually in Profile → Settings → Notifications: • Messages & Direct Connects: New messages and Direct Connects • Matches: When you and someone like each other • Event Reminders: Day-of reminders for events you RSVP'd to • New People: When new profiles arrive in Find • Found News: City launches and announcements We also send account-critical notifications — like profile approval — that aren't tied to a toggle. Notifications are only sent if you grant permission when prompted, and you can turn them off entirely at any time in your device's Settings → Notifications → Found.

Children & age requirements

Found is strictly for people aged 18 and older. We do not knowingly collect information from anyone under 18. If we learn that a user is under 18, we will immediately terminate their account and delete their data on the schedule described above.

Security

These are the safeguards we actually run: • Encryption in transit: traffic between your device, our website, and our servers uses HTTPS/TLS • A locked-down database: it accepts connections only from the server it runs on, never from the public internet • Private photo storage: selfies live in a private, access-controlled storage system that is never publicly reachable; the same storage holds profile photos with access restricted to the service • Biometric processing is performed by Amazon Web Services, and no face data from it is ever stored (see the Biometric Data Notice) • Team access to member data is limited to authorized personnel with a business need, protected by multi-factor authentication, restricted by role, logged, and reviewed periodically • Backups are limited to the database, kept for seven days, and never include selfies • We keep an incident-response plan, and our service providers process data under contracts that limit them to working on our behalf No service can promise perfect security, and we do not. If a security incident ever affects your data, we will investigate it, contain it, and notify affected members and regulators as the law requires. Report anything suspicious to privacy@foundsocialclub.com immediately.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the app and update the "Last updated" date. Continued use of Found after any changes means you accept the updated policy.