Privacy Policy
This Policy explains how FindMe handles personal data when people create temporary live-location sessions, navigate toward one another, communicate, or use social and safety controls.
1. Controller and scope
FindMe is operated by George Osipidis, 51 Stadiou Street, 2058 Strovolos, Nicosia, Cyprus. The operator is the data controller for personal data processed through FindMe. Privacy, legal, support, and account-deletion requests may be sent to osipidisgeorge@gmail.com.
This Policy applies worldwide. It is designed around Regulation (EU) 2016/679 (GDPR), Cyprus Law 125(I)/2018, and privacy-by-default principles. Additional mandatory rights under the law where you live remain available to you. FindMe is intended only for people aged 16 or older.
2. Data FindMe processes
FindMe processes only data needed to provide accounts, social connections, temporary meeting sessions, routing, safety controls, and advertising where enabled.
- Account and profile data: user ID, email address, display name, optional username, optional profile photo, language, settings, and acceptance of legal-document versions.
- Guest access data: Firebase anonymous user ID, device-bound display name, current legal-document acceptance, device token, request status, Firebase account-lifecycle status, hashed invitation-token metadata, rate-limit metadata, friendships, private contact groups, favourites, and blocks. Guest identities have no verified email, phone number, or username and are not publicly searchable. A guest may submit one selected or manually entered contact email address or phone number for blind account resolution, or use a private friend QR code or link; the complete address book is never uploaded and selected identifiers are removed after resolution.
- Social data: friendships, requests, favourites, private contact groups, blocks, availability, recent session participants, invitations, RSVP and participant roles.
- Location and navigation data: current coordinates, accuracy, heading, speed, timestamps, selected precision, temporary approximate areas, pair-specific Reveal Nearby state, route requests, travel mode, meeting points, distance, ETA, arrival state, and short visibility leases.
- Map-search data: address or place text entered by the user, app language, and the current map centre used only to bias results. FindMe sends this information transiently to openrouteservice and does not keep search history.
- Findable Mode data: temporary audience, connection type, expiry, approximate search cell, current server-only coordinate, connection proofs, requests, private-code or QR token hashes, and abuse-prevention counters.
- Communication data: invitation notes, temporary session chat messages, quick messages, announcements, controlled meeting-point references, mute state, and unread counts.
- Safety and service data: reports and optional notes, blocks, coarse battery/GPS/connection status when explicitly enabled, notification tokens, installation identifier, platform, and service-security/rate-limit metadata.
- Request help data: feature enablement, mutually approved help contacts, help category and optional note, selected recipient channels, short-lived exact requester location for approved help contacts and accepted responders, coarse proximity matching for eligible nearby friends, response state, request expiry, rate-limit metadata, and minimal abuse-review records. FindMe does not retain movement history for Request help.
- Media and permissions: a selected or captured profile picture and QR scanner input. FindMe accesses device contacts only after permission; contact names, phone numbers, and the complete address book are not uploaded. A user-selected email may be submitted for exact registered-user discovery. Registered users may optionally link a phone credential through Firebase Phone Authentication; the number is not published in FindMe profiles.
- Advertising data: Google Mobile Ads and the User Messaging Platform may process device, consent, IP-address, advertising-identifier, interaction, and diagnostic information according to user choices, applicable law, and Google's policies.
3. Why data is used and legal bases
Accepting the Terms is not blanket consent to location sharing or personalized advertising. Each meeting session and privacy mode retains its own explicit controls, and Google UMP manages advertising choices where required.
- Contract: creating and securing an account, maintaining relationships, delivering invitations, sessions, chat, routing, notifications, and requested account controls.
- Consent: sharing precise or approximate live location, Reveal Nearby, Findable Mode, optional device status, profile-photo access, contacts/camera permissions, notifications, and advertising choices where consent is required. Consent may be withdrawn through the relevant control.
- Legitimate interests: preventing fraud, guessing, spam and abuse; enforcing limits; securing the service; investigating reports; maintaining reliability; and defending legal claims, after considering user rights and the sensitive nature of location data.
- Legal obligation: responding to lawful requests, data-protection rights, and obligations imposed by Cyprus, EU, or other applicable law.
4. Live location and participant visibility
Location sharing does not start merely because someone sends an invitation or because Findable Mode is visible. A participant must accept and choose a sharing precision. Accepted participants receive only the view authorized for them: precise, approximate, or precise after the Reveal Nearby conditions are met.
FindMe keeps one current server-side exact input when needed to generate privacy-safe projections, evaluate proximity, or route an authorized participant. Clients cannot read raw protocol-v2 inputs. Exact access is revoked when sharing stops, a lease expires, privacy is reduced, a participant leaves or is blocked, or the session ends. Routes and navigation history are not stored by default.
Direct Guest contact requests disclose no registered-account presence before acceptance and upload no Guest location before acceptance. A dedicated Guest open QR or link invitation may be accepted by a registered user or another active Guest, and only the first acceptance succeeds. Those direct requests create a precise, one-to-one session for no more than one hour. Guest sessions created through the ordinary friend, group, QR, or link controls use the organizer's selected participant, precision, schedule, duration, note, and meeting-point settings.
5. Sharing and recipients
Authorized accepted participants receive profile identity, session metadata, communication content, and the current location precision allowed by the sharing participant. Pending invitees and waiting-room users do not receive live locations or chat access.
FindMe uses service providers to operate the app. Depending on the feature, data may be processed by Google Firebase services (Authentication, Firestore, Cloud Functions, Cloud Storage, Cloud Messaging, and Hosting), Google Mobile Ads and UMP, openrouteservice for routes, matrices, places and address geocoding, OpenStreetMap tile/data services, OpenFreeMap vector-map services, and the Apple or Google app-store platform. Map and network providers may receive IP address, device/network metadata, requested map areas, and map-search text or a selected coordinate when those functions are used. Route requests necessarily contain an authorized origin and destination.
FindMe does not sell personal data. It does not disclose exact location to advertisers. Google may process advertising data as an independent controller or service provider under its own terms and the consent choices presented to the user.
6. International processing
FindMe is operated from Cyprus, but providers may process data in other countries. Firebase Authentication is operated from United States data centres, while other Firebase services may use global infrastructure or configured Google Cloud locations. Provider contracts and applicable transfer mechanisms, such as adequacy decisions, the EU-US Data Privacy Framework, and Standard Contractual Clauses where applicable, are used for restricted transfers. No statement in this Policy guarantees that every provider request remains inside the EEA.
7. Retention and deletion
The in-app Delete account action removes the Firebase account and associated FindMe data after recent authentication. A user who cannot access the app may request deletion by email from the registered address.
- Live location, navigation, ETA, arrival and device-status projections use short leases, normally 45 seconds for location/navigation and 60 seconds for optional device status, and disappear when not refreshed. Stop, leave, block, end and expiry initiate immediate cleanup.
- Temporary session chat becomes read-only when a session ends and is deleted after a one-hour grace period.
- Findable requests generally expire after five minutes, invitations and immediate share links after 10 to 15 minutes, scheduled links no later than seven days or session start, and expired Findable metadata is retained for no more than about 24 hours for cleanup and abuse prevention.
- Direct Guest contact requests and dedicated Guest open QR or link invitations expire after five minutes. Raw invitation tokens are not stored; hashed token records are invalidated when an invitation is accepted, revoked, or expires. FindMe does not set a fixed expiry for a device-bound Guest identity, but access is not recoverable or guaranteed to remain available. Leaving Guest mode deletes the identity and its related data immediately; clearing app data or losing the device may permanently remove access. Converting the same identity to a registered account preserves its friendships and private groups. A direct Guest request session lasts no more than one hour, while other Guest sessions follow their selected session settings. Selected contact identifiers are not retained after request resolution.
- Recent-participant summaries are retained for 30 days. Privacy-access permission records are retained for 90 days after sharing ends. Safety reports and related anti-duplicate metadata are retained for up to 180 days.
- Session updates are short lived, generally from 24 hours to seven days depending on their purpose. Profile, friendship, settings, template, device-token and legal-acceptance data remain while the account exists or until replaced or removed.
- Profile photos are removed when replaced or deleted, and account deletion removes both storage slots. Providers may retain limited backups, security logs, or service data for periods required by their contracts or law.
8. Security
FindMe uses Firebase Authentication, server-side lifecycle functions, authorization rules, expiring tokens, single-use or hashed invitation credentials, rate limits, short data leases, transport encryption, screen-privacy controls, and optional device authentication. No system is completely secure. Session chat and location data are not described as end-to-end encrypted because authorized server functions process them for routing, privacy projection, arrival, and abuse controls.
9. Your choices and rights
You may reject invitations, stop sharing, leave sessions, change precision, disable Findable Mode, mute chat, block users, remove a profile photo, manage advertising choices when available, and delete your account. Under the GDPR you may request access, correction, erasure, restriction, portability, or object to processing. You may withdraw consent without affecting processing that was lawful before withdrawal.
Requests should be sent to osipidisgeorge@gmail.com. FindMe may request reasonable identity verification and normally responds within one month. You may complain to the Office of the Commissioner for Personal Data Protection in Cyprus or another competent supervisory authority.
10. Automated features
FindMe automatically calculates routes, approximate areas, proximity, arrival, ETA, fair meeting-point suggestions, late warnings, and Findable proximity. These features coordinate sessions and do not make decisions producing legal or similarly significant effects. Safety reports are not used for automatic punishment.
11. Children
FindMe is not directed to children under 16 and does not provide a parental-consent workflow. A person under 16 must not create an account or use the service. Contact the controller if you believe an underage account exists.
12. Changes
This Policy may change when FindMe features, providers, or legal obligations change. The current version and effective date are shown in the app and on the public website. Material changes will be communicated clearly. A privacy notice is not converted into consent merely by being updated.