Privacy Policy

Effective: 25 July 2026 · Version: 2026-07-25-v7

This Policy explains how FindMe handles personal data when people create temporary live-location sessions, navigate toward one another, communicate, or use social and safety controls.

1. Controller and scope

FindMe is operated by George Osipidis, 51 Stadiou Street, 2058 Strovolos, Nicosia, Cyprus. The operator is the data controller for personal data processed through FindMe. Privacy, legal, support, and account-deletion requests may be sent to osipidisgeorge@gmail.com.

This Policy applies worldwide. It is designed around Regulation (EU) 2016/679 (GDPR), Cyprus Law 125(I)/2018, and privacy-by-default principles. Additional mandatory rights under the law where you live remain available to you. FindMe is intended only for people aged 16 or older.

2. Data FindMe processes

FindMe processes only data needed to provide accounts, social connections, temporary meeting sessions, routing, safety controls, and advertising where enabled.

3. Why data is used and legal bases

Accepting the Terms is not blanket consent to location sharing or personalized advertising. Each meeting session and privacy mode retains its own explicit controls, and Google UMP manages advertising choices where required.

4. Live location and participant visibility

Location sharing does not start merely because someone sends an invitation or because Findable Mode is visible. A participant must accept and choose a sharing precision. Accepted participants receive only the view authorized for them: precise, approximate, or precise after the Reveal Nearby conditions are met.

FindMe keeps one current server-side exact input when needed to generate privacy-safe projections, evaluate proximity, or route an authorized participant. Clients cannot read raw protocol-v2 inputs. Exact access is revoked when sharing stops, a lease expires, privacy is reduced, a participant leaves or is blocked, or the session ends. Routes and navigation history are not stored by default.

Direct Guest contact requests disclose no registered-account presence before acceptance and upload no Guest location before acceptance. A dedicated Guest open QR or link invitation may be accepted by a registered user or another active Guest, and only the first acceptance succeeds. Those direct requests create a precise, one-to-one session for no more than one hour. Guest sessions created through the ordinary friend, group, QR, or link controls use the organizer's selected participant, precision, schedule, duration, note, and meeting-point settings.

5. Sharing and recipients

Authorized accepted participants receive profile identity, session metadata, communication content, and the current location precision allowed by the sharing participant. Pending invitees and waiting-room users do not receive live locations or chat access.

FindMe uses service providers to operate the app. Depending on the feature, data may be processed by Google Firebase services (Authentication, Firestore, Cloud Functions, Cloud Storage, Cloud Messaging, and Hosting), Google Mobile Ads and UMP, openrouteservice for routes, matrices, places and address geocoding, OpenStreetMap tile/data services, OpenFreeMap vector-map services, and the Apple or Google app-store platform. Map and network providers may receive IP address, device/network metadata, requested map areas, and map-search text or a selected coordinate when those functions are used. Route requests necessarily contain an authorized origin and destination.

FindMe does not sell personal data. It does not disclose exact location to advertisers. Google may process advertising data as an independent controller or service provider under its own terms and the consent choices presented to the user.

6. International processing

FindMe is operated from Cyprus, but providers may process data in other countries. Firebase Authentication is operated from United States data centres, while other Firebase services may use global infrastructure or configured Google Cloud locations. Provider contracts and applicable transfer mechanisms, such as adequacy decisions, the EU-US Data Privacy Framework, and Standard Contractual Clauses where applicable, are used for restricted transfers. No statement in this Policy guarantees that every provider request remains inside the EEA.

7. Retention and deletion

The in-app Delete account action removes the Firebase account and associated FindMe data after recent authentication. A user who cannot access the app may request deletion by email from the registered address.

8. Security

FindMe uses Firebase Authentication, server-side lifecycle functions, authorization rules, expiring tokens, single-use or hashed invitation credentials, rate limits, short data leases, transport encryption, screen-privacy controls, and optional device authentication. No system is completely secure. Session chat and location data are not described as end-to-end encrypted because authorized server functions process them for routing, privacy projection, arrival, and abuse controls.

9. Your choices and rights

You may reject invitations, stop sharing, leave sessions, change precision, disable Findable Mode, mute chat, block users, remove a profile photo, manage advertising choices when available, and delete your account. Under the GDPR you may request access, correction, erasure, restriction, portability, or object to processing. You may withdraw consent without affecting processing that was lawful before withdrawal.

Requests should be sent to osipidisgeorge@gmail.com. FindMe may request reasonable identity verification and normally responds within one month. You may complain to the Office of the Commissioner for Personal Data Protection in Cyprus or another competent supervisory authority.

10. Automated features

FindMe automatically calculates routes, approximate areas, proximity, arrival, ETA, fair meeting-point suggestions, late warnings, and Findable proximity. These features coordinate sessions and do not make decisions producing legal or similarly significant effects. Safety reports are not used for automatic punishment.

11. Children

FindMe is not directed to children under 16 and does not provide a parental-consent workflow. A person under 16 must not create an account or use the service. Contact the controller if you believe an underage account exists.

12. Changes

This Policy may change when FindMe features, providers, or legal obligations change. The current version and effective date are shown in the app and on the public website. Material changes will be communicated clearly. A privacy notice is not converted into consent merely by being updated.