Privacy Policy
1. Summary
Findy is a personal swipe-file app that gathers the things you save across platforms into one library. This policy explains what we collect, why, who we share it with, and the choices you have.
2. Information we collect
- Account information. Your email address and a securely hashed form of your password. We never store your password in plain text.
- Your saved content. The bookmarks you create, import, or sync — URLs, titles, text excerpts, thumbnail image URLs, source platform, author names, tags, collections, and timestamps.
- Connected-platform tokens. When you connect an account (e.g. Reddit, Tumblr, Pinterest, YouTube, X), we store the OAuth refresh token issued by that platform so we can sync your saved items. We do not receive or store your password for those platforms.
- Payment information. If you subscribe, payments are processed by Stripe. We store only your Stripe customer and subscription identifiers and your plan status. We do not store card numbers.
- Technical and log data. Standard server logs (IP address, request metadata, timestamps, errors) used for security and reliability.
The browser extension additionally accesses, on your device:
- Your browser bookmarks (to sync them, only when you choose to), and
- The content of posts you explicitly save on facebook.com, instagram.com, and tiktok.com via the extension's save button.
The extension uses the bookmarks and storage permissions and network access to your Findy server only. It does not read pages you do not choose to save, and it does not sell or transmit your data to any third party other than your own Findy server.
3. How we use information
- To provide the Service: store, organize, sync, and display your bookmarks.
- To authenticate you and keep your account secure.
- To sync saved content from platforms you connect.
- To process subscriptions and manage billing (via Stripe).
- To operate, monitor, debug, and improve the Service.
- To communicate with you about your account (verification, password resets, service notices).
We do not sell your personal information, and we do not use your saved content for advertising.
4. How information is shared
- Stripe — payment processing. See Stripe's privacy policy.
- Connected platforms — we call their APIs on your behalf using the tokens you authorized; their handling of that data is governed by their own policies.
- Error tracking — if enabled, diagnostic error data may be sent to Sentry.
- Email delivery — transactional emails may be sent via our email delivery provider.
- Legal — where required by law or to protect rights and safety.
- Business transfers — as part of a merger, acquisition, or asset sale, subject to this policy.
5. Data retention and deletion
We keep your data while your account is active. You can disconnect any platform at any time (which deletes the stored token), and you can delete bookmarks. To delete your account and associated data, contact hello@findy.so. We may retain limited records as required by law or for legitimate business purposes (e.g. billing records).
6. Security
Passwords are hashed with a strong key-derivation function; session and email tokens are stored only as hashes. Data is transmitted over HTTPS in production. No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your information.
7. Cookies and local storage
The web app stores your session token in your browser's local storage to keep you signed in. The extension stores your session token and settings using the browser's extension storage. We do not use third-party advertising or tracking cookies.
8. Your rights
Depending on your location (e.g. GDPR/EEA, UK, CCPA/California), you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these, contact hello@findy.so.
9. Children
The Service is not directed to children under 13, and we do not knowingly collect their data.
10. International transfers
Your data may be processed in the European Union or other countries where our hosting providers operate. Where required, we use appropriate safeguards for cross-border transfers.
11. Changes
We may update this policy; material changes will be posted at findy.so/privacy with an updated effective date.
12. Contact
Questions or requests: hello@findy.so