Privacy Policy
Phase 1
What we collect
When you file a report at /report, we store the device details you provide (type, brand, model, color), where and when it was last seen, a description, your contact email, an optional phone number, and an optional photo. We don't collect anything beyond what's on that form.
How it's used
Your report is stored so the case can be looked up by its case ID. Anyone with the case ID can see the device details, last-seen location, and status — never your email, phone number, or the free-text description. Only signed-in administrators on the allowlist can see the full report, including contact details.
Where it's stored
Reports and photos are stored with Supabase (Postgres and file storage). Photos live in a private storage bucket that isn't publicly accessible; only server-side code with administrator privileges can read it. Every database table has row-level security enabled, so access is enforced at the database layer, not just in the app.
What we don't do
We never sell or share report data with third parties. We never access Find My iPhone, Find My Device, or any carrier location data — we have no technical means to, and this registry doesn't attempt to.
Retention
A case stays on record until it's marked found or closed, and for a reasonable period afterward so the case history remains checkable. If you'd like your report removed, contact the site administrator.
Questions
This policy describes Phase 1 functionality only and should be reviewed before a production launch. For questions or data requests, contact the site administrator directly.