Privacy Policy
Found is an app that turns an Instagram reel link into a list of the places the reel talks about, as Google Maps links. This policy explains what information the app and its backend service collect, why, who else handles it, how long it is kept, and what you can ask us to do with it.
Found is operated by Eyal Harel ("we"). You can reach us at eyalh747@gmail.com.
1. What we collect
Account information
You sign in with your Google account. From Google we receive your email address and Google's confirmation that it is verified. We store the email address to create and identify your account. We do not receive or store your Google password, your contacts, your photos, or any other Google data, and we do not request access to your Instagram account.
Reel links you submit and the results
When you share a reel with the app we store, linked to your account:
- the Instagram reel link you submitted and when you submitted it;
- an identifier generated by the app for that submission, so a repeated share is not processed twice;
- the result: the place names we found, their Google Place IDs and the Google Maps links we produced;
- technical details of the processing: which steps ran, how long they took, and any error messages.
Content fetched from Instagram
To find the places, our server fetches the reel's public caption and video from Instagram. The video is downloaded to a temporary folder on our server and deleted when processing finishes, usually within a minute. The caption is used during processing and is not kept afterwards; only the place names derived from it are stored with the result.
Technical and log data
Like any online service, our servers and hosting infrastructure keep standard technical logs that may include your IP address, the time and type of each request, and basic information about your device or app version sent by your phone. We use this to keep the service secure, to limit abuse (for example, rate limiting sign-in attempts) and to diagnose problems. These logs are kept for a limited period and are not linked to your account for any other purpose.
App usage analytics
The app uses Firebase Analytics (a Google service) to understand how the app is used: for example that a reel was shared, whether processing succeeded, and whether a map was opened. Each event carries the submission identifier mentioned above, the app version, the device type and operating system version, and a random identifier Firebase assigns to your installation of the app. Advertising ID collection is turned off. We do not use this data for advertising. Firebase also derives an approximate, city-level location from your IP address for aggregate usage reports. The IP address itself is masked and not stored with the event.
What we do not collect
- your phone's precise location (Found never asks for the location permission);
- your contacts, photos, or files;
- your Instagram login or any content from your own Instagram account;
- payment information;
- your advertising ID.
2. How we use it
- to provide the service: sign you in, process the reels you share, and show you the results and your history;
- to keep the service reliable and secure, and to fix problems;
- to understand how the app is used so we can improve it;
- to comply with legal obligations.
We do not sell your information and we do not show advertising.
3. Who else handles your information
Processing a reel involves several third-party services. Each one receives only what it needs for its step.
| Service | What it receives | Why |
|---|---|---|
| Google Sign-In | Your sign-in with Google; we receive your email address. | Authentication. |
| Instagram (Meta) | A request for the public reel, made by our server. It does not include your identity. | Fetching the caption and video. |
| DataImpulse | The reel link, as the page requests to Instagram may be routed through DataImpulse's proxy network. It does not receive your identity or the video. | Keeping reel fetching reliable. |
| Apify | The reel link, only when the direct fetch fails. Apify fetches the caption and a copy of the video, which it stores for a few days. | Backup method for fetching reels. |
| Groq | The reel's caption text. | Finding place names in the caption. |
| Google Gemini | The reel's video, only when the caption does not already name a specific place. We use the paid Gemini API, under which Google does not use the video to train its models, and Google deletes the uploaded file automatically within 48 hours. | Finding places shown or spoken in the video. |
| Google Places and Google Maps | The place names we found. | Matching them to real places and producing map links. Opening a link takes you to Google Maps, which is covered by Google's own privacy policy. |
| Firebase Analytics (Google) | The app usage events described above. | Usage analytics. |
| Hostinger | Everything stored by the service, on a server in France. | Hosting. |
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We may also disclose information if required by law, or to protect the rights, safety or property of our users or ourselves.
4. Where your information is processed
Our server is located in France. Some of the services listed above process data in the United States or other countries. Where that involves a transfer of personal data out of your country, it happens under the provider's standard contractual safeguards.
5. How long we keep it
- Account and reel history: until you delete your account or ask us to delete it.
- Downloaded videos: deleted from our server when processing finishes.
- Video copies held by processors: Google deletes Gemini uploads within 48 hours; Apify keeps its copy for a few days.
- Technical logs: a limited period, then deleted.
- Backups: we keep a nightly backup of our database for up to 7 days, so deleted data can remain in a backup for that long before it is gone.
- Place lookups: we keep a table of place names matched to Google Place IDs so repeat lookups are faster. It contains no information about you.
6. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict how we use it. You can exercise any of these by emailing eyalh747@gmail.com. We will respond within 30 days.
Deleting your account: in the app, open Settings and choose Delete account; your account, reel history and sign-in token are removed immediately. Or email us from the address you signed in with and we will do it for you. Full details are at /account/delete/. Signing out of the app does not delete your data.
If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your local data protection authority.
7. Security
All traffic between the app and our server is encrypted (HTTPS). Access to the server and its database is restricted, and sign-in tokens are stored only on your device and our server. No method of transmission or storage is completely secure, but we work to protect your information appropriately.
8. Children
Found is not directed at children under 13 (or under 16 where that is the applicable age), and we do not knowingly collect information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
9. Changes to this policy
If we change how we handle your information, we will update this page and the date at the top. Significant changes will also be announced in the app.
10. Contact
Eyal Harel
eyalh747@gmail.com