1. Who We Are
Find Yourself! is operated by IbiPoint Ltd, a company registered in the United Kingdom. IbiPoint Ltd is the data controller for the personal data described in this policy. When we say "we," "us," or "our," we mean IbiPoint Ltd. When we say "you," we mean you, the user of our app and services.
Contact: [email protected]
2. Data We Collect
Account Information
When you create an account, we collect your email address, display name, and password (stored as a bcrypt hash — we never see or store your actual password). If you sign in with Google or Apple, we receive your name and email address from those services instead.
Profile Information
You may provide additional information including profile photos (up to 3), a personal text, your home country, languages spoken, and your city. All of this is optional and shown to other users as part of your profile.
Location Data
We collect your device's GPS location when the app is open to show you nearby travelers and place your pin on the map. We only use foreground location — we never track you in the background. On the map, other users never see your exact position: your pin is deliberately blurred by a multi-kilometre randomization scheme, and profiles show only your city name and an approximate distance.
Friends & Find (exact-position sharing — only with your consent)
Since version 3.0 you can add other users as friends and, only if you explicitly allow it, let one chosen friend see your exact position (accurate to a few metres) for a limited time. This works as follows:
- Friendships. You can send a friend request from any profile or conversation; every friendship requires the other person's explicit acceptance, declines are invisible to the requester, and requests are rate-limited to prevent abuse. Your friend count and shared-friends count are visible to other users (see "How We Share Your Data").
- Consent first, always. A friend who wants to find you must ask. You see a three-step confirmation in the app and choose the duration yourself (1 hour up to 14 days). If you decline, the friend is not notified. Nothing is shared without your explicit permission — a friendship alone never shares your position.
- Live positions are never stored. While a friend with your permission has the finding screen open, your position is transmitted live from your device to theirs through our server. It is relayed only, never saved — no movement history exists on our server.
- What we do store: the friendship itself; the permission you granted (who, chosen duration, expiry time, and the timestamps of your three confirmations — this is our record of your consent); and a short log of when your friend opened the finding screen (kept 90 days), which powers the "is locating you right now" notification and lets you see how the permission was used.
- You stay in control. You can stop any sharing at any time with one tap (Friends → Stop), or stop all sharing at once. Removing a friend or blocking a user ends any sharing between you instantly. Sharing also ends automatically when the permission expires and when you and your friend are more than 500 km apart.
- You stay informed. You get a notification whenever your friend locates you, a reminder every ~48 hours while a longer permission is active, and a notice when sharing ends. While anyone can find you, the app shows a permanent indicator.
The legal basis for exact-position sharing is your consent (UK/EU GDPR Art. 6(1)(a)), which you may withdraw at any time as described above. Withdrawal does not affect the lawfulness of sharing before the withdrawal.
Messages
Messages you send through the app are stored on our server so we can deliver them and show you your conversation history. Message content is encrypted at rest on our server. Message content is only ever viewed by a human when we investigate an abuse report — and each such access is technically logged. Messages are also subject to automatic deletion (see Data Retention below).
Photo Verification (optional)
If you choose to verify your profile, you take a selfie in the app. Our server compares this selfie to your profile photos using automated face comparison and returns a match result. The selfie itself is never stored — it is processed in memory and discarded immediately after the comparison. Only the yes/no verification result is saved to your profile.
Uploaded Photos
Profile photos are automatically screened by an on-server image classifier for content that violates our guidelines (for example nudity or violence). Flagged images are reviewed by a human before any action is taken. No third-party service receives your photos for this screening — it runs entirely on our own server.
Device Information
We collect your device's push notification token to send you notifications (for example new messages, friend requests, and location-sharing events such as "is locating you right now" and expiry notices), and basic platform information (iOS or Android). Notification content (for example a message preview) is transmitted through Apple's and Google's push services in order to be delivered to your device.
Usage Data
We record activity timestamps (such as when your account was last active) to operate the service. Interactions with the IbiPoint promotional card in the app are counted anonymously — these counters contain no user identifier at all.
3. How and Why We Use Your Data
We use your data to:
- Operate the app — show you nearby travelers, deliver messages, send notifications (legal basis: performance of our contract with you)
- Operate the friends system and, where you have explicitly allowed it, transmit your exact position live to that one friend for the time you chose (friendships and notifications: contract; exact-position sharing: your consent)
- Create and maintain your account and profile (contract)
- Keep the community safe — automated image screening, handling reports and blocks, preventing abuse (legitimate interests in protecting our users, and legal obligations)
- Understand overall usage through aggregated, anonymized statistics (legitimate interests)
We do not use your data for advertising profiles, and we do not carry out automated decision-making that produces legal or similarly significant effects about you.
4. How We Share Your Data
We do not sell your data. We do not share your data with advertisers. Your data is shared only in these limited ways:
- Other users: Your display name, photos, personal text, country, languages, city, and approximate distance are visible to other users. Once you have at least one friend, your number of friends is also shown on your profile, and viewers see how many friends you have in common with them
- A friend you explicitly allowed: your exact live position, only for the duration you chose, only while that permission is active (see "Friends & Find" above)
- Message recipients: Messages you send are delivered to the intended recipient
- Service providers (processors): We use a small number of infrastructure providers to run the service: IONOS (server hosting, United Kingdom), Cloudflare (CDN and security), Expo together with Apple and Google (push notification delivery), and Dropbox (off-site backup storage — backups are encrypted before upload, so Dropbox cannot read them). These providers process data on our behalf
- Legal requirements: We may disclose data if required by law or to protect the safety of our users
5. Data Storage & Security
Your data is stored on our server in the United Kingdom. For users in the European Economic Area: the UK is covered by a European Commission adequacy decision, so your data enjoys an equivalent level of protection.
Security measures include: TLS encryption for all data in transit, encryption at rest for message content, bcrypt hashing for passwords, signed short-lived URLs for photos, firewalling and intrusion mitigation on our server, and nightly encrypted off-site backups. Access to message content by a human is restricted to abuse-report investigation and is logged.
6. Data Retention
- Account data: kept for as long as your account exists. When you delete your account, your profile is erased and your photos and all your conversations (for both participants) are permanently deleted immediately.
- Conversations: deleted automatically after 12 months of inactivity. A first message that never receives a reply is deleted after 6 months.
- Location sharing: live positions are never stored. Expired or revoked sharing permissions (the consent records) are kept for 12 months for accountability, then deleted. The log of finding sessions is kept for 90 days. Friendships are deleted when either side removes the other, blocks, or deletes their account.
- Backups: deleted data disappears from our encrypted backup copies within 8 weeks at the latest, as backup generations rotate out.
- Moderation records: reports and related moderation records may be retained after account deletion for as long as necessary to protect our users and to comply with legal obligations.
- Technical logs: server logs are kept briefly for security and troubleshooting.
7. Your Rights
Under the UK GDPR and, if you are in the European Economic Area, the EU GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Update or correct your data via the app's profile editor
- Erasure: Delete your account and all associated data via the app (Profile → Delete Account) — this takes effect immediately
- Portability: Request your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Stop any exact-position sharing at any time in the app (Friends → Stop, or "Stop all location sharing") — withdrawal takes effect immediately
- Restriction: Request restriction of processing
To exercise these rights, contact us at [email protected]. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or, if you are in the EEA, with your local data protection authority.
8. Children
Find Yourself! is not intended for anyone under the age of 18. We do not knowingly collect data from anyone under 18. If we learn that we have collected data from a minor, we will delete it immediately.
9. Cookies
The Find Yourself! mobile app does not use cookies. Our website (find-yourself.app) uses only essential cookies required for the site to function. The website loads its fonts from Google Fonts; Google's privacy policy applies to that request.
10. Third-Party Links
The app may contain links to third-party services (such as IbiPoint for eSIM connectivity). These services have their own privacy policies, and we are not responsible for their practices.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes through the app or by email. The "last updated" date at the top reflects the most recent version.
12. Contact
For any privacy-related questions or requests:
IbiPoint Ltd
Email: [email protected]
Web: find-yourself.app