This policy covers both the Phound waitlist at phoundit.app and the Phound mobile app. The sections below explain what each service collects, why we use it, where it goes, and the choices available to you.
What the waitlist collects
When you join the waitlist, we collect:
Your email address, required, so we can send your confirmation and keep you updated.
Your name, optional, used on your registrar card and in emails.
A registrar title you choose or shuffle to on the signup card. This is cosmetic and not sensitive.
A referral code we generate for you, and, if someone referred you, a link to their entry.
Your IP address at signup, used only with our rate-limiting provider to prevent abuse such as fake signups and self-referral farming. We don't use it for advertising or tracking.
Timestamps for when you signed up, confirmed, and, if applicable, unsubscribed.
What the Phound mobile app collects
Phound helps you identify physical objects, understand what they could be worth, keep a record of them, and, if you choose, prepare them for sale. To provide those features, the mobile app collects and processes the following information:
Photos and identification evidence. When you use the camera to identify an object, Phound sends the photo off your device to our server and to Google Gemini for identification. A second, independent check of the identification is performed by OpenAI's GPT models, accessed through the kie.ai API service, which also performs the photo cleanup that places items you save to your Holdings on a plain backdrop. Google Cloud Vision may process the image for web-detection and optical-character-recognition evidence. When configured, Voyage AI may process a cleaned image to create a numeric image embedding. Identification records do not store the original image bytes. They may store a SHA-derived image reference, extracted text and evidence, model outputs, pricing information, and a numeric image embedding. If you save an item to your Holdings, its image is stored on our server and linked to your account. Holdings images do not currently have a fixed automatic deletion or expiration period.
Account information. If you create an account, we collect your email address and create an internal user ID. Your email is normalized for account use. Your password is protected with a salted cryptographic hash and is never stored as plaintext. The app uses a session token to keep you signed in, while our server stores a hash of that token.
Purchases and memberships. Apple StoreKit and RevenueCat process purchases and subscription status. Phound's server stores records such as the product ID, RevenueCat transaction ID, scan grants, and membership tier, linked to your internal user ID. Phound and RevenueCat do not receive your raw payment-card details from Apple.
Product analytics. We send authenticated product-usage events to PostHog through Phound's own API. These events can include feature use, scan and quota activity, paywall and purchase lifecycle events, review-prompt events, and correction or note text you choose to enter. They are linked to your internal user ID and used to operate and improve Phound. We do not use this information for advertising or link it with other companies' data for advertising purposes.
Selling integrations. If you choose to connect eBay or Etsy and initiate a listing, we send the marketplace the listing details needed to perform your request, which may include the title, description, price, category, and image. Phound stores the marketplace OAuth tokens needed to keep your connection working. We do not send this information to eBay or Etsy unless you connect the service and use the selling feature.
Location. Phound does not request or collect precise or approximate device location.
No advertising or cross-company tracking. Phound has no advertising SDKs, does not sell personal information, and does not use your information to track you across other companies' apps or websites.
Who we share it with
We use a small number of vendors to provide the waitlist and mobile app:
Supabase stores your waitlist entry and is used to verify Google sign-in for the mobile app.
Replit hosts the Phound mobile app's server and database, including your account, Holdings and their images, and scan records, and relays identification requests to the AI services listed here.
Resend, our email provider, delivers your confirmation and update emails.
Upstash, used only to rate-limit signups by IP address for abuse prevention. This data is short-lived and not used for anything else.
Vercel hosts this website and keeps standard request logs.
Google Gemini and Google Cloud Vision, which process object photos for identification, web detection, and text evidence.
kie.ai, an API service that provides access to OpenAI's GPT models, which process object photos to independently verify identifications and to clean up photos of items you save.
Voyage AI, which may process cleaned object photos to create image embeddings when that service is configured.
RevenueCat and Apple StoreKit, which process purchases, subscriptions, and entitlement status. Apple handles your payment details.
PostHog, which processes first-party product analytics linked to your Phound user ID.
eBay and Etsy, only when you connect one of those services or ask Phound to perform a related marketplace action.
We do not sell your personal information, and we never will.
Email and unsubscribing
Every email we send includes a one-click unsubscribe link. Clicking it stops all future email immediately and automatically, no login or confirmation required. You can also email us directly to ask that your entire waitlist entry be deleted, not just muted, see Your choices below.
Children
Phound is not directed at children under 13, and we do not knowingly collect information from anyone under 13. If we learn we've collected information from a child under 13, we'll delete it.
Your choices
Unsubscribe from email at any time using the link in any email we send.
Request a copy of what we have on file for you by emailing us.
Delete your account in the app at any time: open THE REGISTER, scroll to the bottom, and tap DELETE ACCOUNT, then confirm. This immediately and permanently deletes your Phound account along with your sign-in sessions, saved Holdings and their images, scan usage and purchase records, review feedback, and any connected eBay or Etsy credentials. Identification records from past scans never contain the original photo; after deletion they are no longer linked to you. Deleting your account does not cancel an App Store subscription; cancel that in your iPhone's Settings.
Request deletion by email of your waitlist entry, or of your Phound account if you can't access the app, by emailing privacy@phoundit.app. We will act on every request.
How long we keep it
We keep waitlist data for as long as the waitlist is active, or until you ask us to delete it, whichever comes first.
Mobile-app account data, saved Holdings images, scan records, purchase and entitlement records, and connected-marketplace credentials do not currently have a fixed automatic deletion or expiration period. We keep them while your account or the related feature remains active, unless a longer period is required for security, fraud prevention, legal compliance, or resolving a transaction. You can delete your account and this data yourself at any time from THE REGISTER in the app (see Your choices), or by emailing us.
Security
We rely on established, security-focused vendors for storage, processing, delivery, and hosting. We use measures such as salted password hashing and hashed server-side session tokens. Marketplace OAuth credentials are kept on the server rather than exposed to the mobile app. No method of transmission or storage is completely secure, but we take reasonable, industry-standard steps to protect your information.
Changes to this policy
If we make a material change to this policy, we'll post the update here. When appropriate, we may also notify active waitlist members or app users by email or in the app.