Last updated September 30, 2026
This policy explains what information NeedToFind collects, how it's used, who can see it, and what choices you have. NeedToFind is run by Gray Penguin Development ("we", "us"). We've tried to keep it plain. If anything is unclear, ask us at info@needtofind.app. Using the Service also means agreeing to our Terms of Service.
1. What we collect
What you give us
- Account details: your name, email address, and a password (which we store scrambled, never in plain text).
- Optional details: your location, and how you found us (a choice from a list, plus a few words if you pick "somewhere else"). You can leave these blank and change the location later.
- What you post: wanted ads (title, description, category, budget, location, and photos), responses (message, asking price, contact details, and an optional photo), private messages, alerts you save (keywords and categories), and reports you file about ads.
- API tokens you create for AI assistants (we keep the token's name and when it was used; the token itself is stored scrambled).
- Anything you send us when you contact us. Messages from the contact form (your name, email address, topic, and message) reach us as email, and we keep them like any other correspondence so we can reply and follow up.
What we collect automatically
- Sign-in and sign-up records: when you sign up or sign in, and the IP address it came from, including failed attempts (with the email address that was tried). We use these to keep accounts safe. We keep them for up to 180 days.
- Activity records: a log of what happens on the site, such as posting an ad, responding, sending a message, creating an alert, or using an AI assistant. We use it for security, moderation, and to understand how the Service is used. We keep it for up to 180 days.
- Standard server logs: like most websites, our web server records your IP address, browser type, and the pages requested.
- Cookies (see below).
About photos
When you upload a photo we resize it and save a fresh copy, which removes hidden information such as the GPS location many phones embed. Photos are stored on our server with hard-to-guess file names. Photos on ads are public. A photo attached to a private response is shown in the site only to the buyer and seller, but anyone who has the direct address of the image file could open it, so don't include anything in a photo you wouldn't want the other person to share.
2. How we use it
- To run the Service: show ads, deliver responses and messages, and send the emails that go with them (a response or message you received, an alert match you asked for, an ad that was removed).
- To keep the Service safe: prevent spam and abuse, review reports, and protect accounts.
- To understand and improve the Service, using summaries such as how many people signed up, where they're from, and how they found us.
- To answer you when you contact us, and to meet legal obligations.
We don't send marketing emails today. If that ever changes, you'll be able to say no.
3. Who can see what
| Information | Who can see it |
|---|---|
| Your ads: title, description, category, budget, location, photos, and the name on your account | Anyone, including visitors without an account, and search engines |
| How many responses an ad has | Anyone |
| A response: its message, price, contact details, and photo | The buyer and the seller who wrote it |
| Private messages | The buyer and that seller |
| Your email address | Not shown to other members. It's used to send you notifications. |
| Your optional location and how-you-found-us answer | Only our moderators. Your location is used to pre-fill your ads. |
| Who reported an ad | Only our moderators. The person who posted the ad is never told. |
Our moderators can see account details, public content, and activity records. Our moderation tools don't display the contents of private responses and messages. We may look at them only if we need to investigate abuse, keep the Service secure, or respond to a legal requirement.
4. Who we share it with
We don't sell your personal information to data brokers or advertisers. We share information only in these ways:
- With other members, as described above. What you put in an ad is public, and what you put in a response is shared with the buyer.
- With service providers that help us run the Service: our hosting provider (Linode, part of Akamai) stores the data; Google reCAPTCHA checks sign-ups for bots and receives information such as your IP address and browser details under Google's own privacy policy; and our typefaces are delivered by Bunny Fonts, which sees your IP address when a page loads.
- Through email. We send notification emails ourselves; the message content then passes through the email provider of whoever receives it.
- With AI assistants you connect. If you give an assistant a token, it can read and act on your account information on your behalf, and that assistant's provider handles what it sees under its own terms.
- When the law requires it, or to protect people, the Service, or our rights.
- In a business change, such as a sale or reorganization of the Service, with the same protections for your information.
5. Cookies
We use only the cookies the site needs to work: one that keeps you signed in, one that protects forms from forgery, and, if you tick "Remember me", one that keeps you signed in longer. The sign-up page also loads Google reCAPTCHA, which sets its own cookies. We don't use advertising cookies or analytics tracking today. If that changes, we'll update this page first.
6. How long we keep it
- Your account and content: until you delete them or your account. Ads expire from the site after a set time but stay in your dashboard until you delete them.
- Sign-in IP addresses and activity records: up to 180 days.
- When you delete your account, your ads, photos, responses, messages, alerts, and tokens are removed. A short record that the account was deleted, including the email address, stays in our audit log for up to 180 days. Some copies may remain in backups for a limited time.
7. Your choices
- Update your name, email address, location, and password on your profile page.
- Turn off alert emails with the link in any alert email, or from the Alerts page. Your saved alerts are kept.
- Revoke API tokens from your profile page at any time.
- Delete your account from your profile page.
- Ask us for a copy of your information, or to correct or delete it, by emailing info@needtofind.app.
Depending on where you live, such as California, the European Economic Area, or the United Kingdom, you may have additional rights over your personal information, including the right to access it, correct it, delete it, or object to how it's used. Email us and we'll help. We won't treat you differently for asking.
8. Security
Passwords are stored scrambled, connections to the site are encrypted, and access to our systems is limited. No system is perfectly secure, so please use a strong, unique password. If you find a security problem, please tell us at info@needtofind.app.
9. Children
NeedToFind is for people 18 and older. We don't knowingly collect information from children. If you think a child has given us information, tell us and we'll delete it.
10. Where your information is kept
NeedToFind is run from, and our servers are located in, the United States. If you use the Service from another country, your information will be transferred to and handled in the United States.
11. Changes to this policy
If we change this policy in a way that matters, we'll tell you by email or with a notice on the site and update the date at the top.
12. Contact
Questions or requests about your information? Email info@needtofind.app.