This explains what Thrown & Found actually collects, who we send it to, how long we keep it, and what you can do about it — every claim below matches what the app's code really does, not a generic template.
Last updated 25 August 2026 · version 2026-08-25Table of contents
We use your information to: create and secure your account; show your uploaded items to other users on the map; match items against saved searches ("alarms") and notify you; run automatic photo categorization (see AI-based products); award and track the coin economy (uploading and correcting earns coins, creating an alarm spends them); investigate reports and enforce our Community Guidelines; and prevent abuse (rate limits, duplicate-account checks).
Where GDPR applies, we rely on:
We don't sell your personal information. We do share it with a small number of processors, only as needed to run the app:
We may also disclose information if required by law, or to protect the safety of our users.
Yes, in two specific, narrow ways — both described here so nothing about them is a surprise:
Before a photo ever leaves your device, we run on-device face detection (Google's ML Kit) to find and blur any faces in it. This happens entirely on your phone — the detection result and the original unblurred image are never sent to us or anyone else, only the blurred photo is uploaded. This is a privacy feature, not a way to identify anyone: it never tries to recognize who a face belongs to, only where one is, so it can blur it.
When you upload a photo, we send a cropped copy of it to a third-party AI vision model (routed through OpenRouter) to automatically suggest its category, material, and a short description. This happens without a human reviewing it first, and the AI can get it wrong — that's expected, which is why any user can submit a one-time correction on any listing (including your own). These fields are machine-generated, not written by the uploader.
Thrown & Found is a native mobile app, not a website — we don't use browser cookies. We do use a device push token (see section 1) strictly to deliver notifications you've requested; this is not used for advertising or tracking.
Analytics (Firebase/Google Analytics) is off by default and only activated if you explicitly turn it on in the app's Settings screen. You can switch it on or off at any time — the app records your choice and applies it immediately (Google's Analytics collection is enabled or disabled to match). We do not currently show ads or use any advertising SDK.
Data is encrypted in transit (HTTPS/TLS) between the app and our servers, and our storage and database providers encrypt data at rest. Access to the admin dashboard is restricted to a small, named allowlist of operators. No method of transmission or storage is 100% secure, so we can't guarantee absolute security — but we design for it deliberately, not as an afterthought.
Thrown & Found requires you to be at least 13 years old to create an account — this is checked at signup based on the birthdate you provide, and accounts that don't meet it are rejected outright. If we learn that we've collected personal information from someone under 13, we will delete that account and its data.
Depending on where you live, you may have the right to access, correct, delete, restrict, or export your personal information, and to object to or withdraw consent for its processing. We've tried to make the common ones self-service, directly in the app:
For anything not yet self-service (or if something above doesn't work as described), email [email protected] and we'll handle it directly.
Yes — we'll revise this notice as the app changes, and update the "Last updated" date and version number at the top. If we make a material change, we'll ask you to re-accept it before you can keep using the app, the same way you accepted it the first time.
If you have questions or comments about this notice, email us at [email protected].
See also our Terms of Service and Community Guidelines.