FindBack Privacy Policy & Architecture
Last updated: September 2026 • Compliant with zero-trust privacy-by-design principles.
1. Spatial Coordinate Fuzzing
When an item is reported, its exact GPS coordinates are stored securely in internal database tables but are NEVER served directly to unauthenticated or non-owning client requests. The public API and map markers return coordinates that have been blurred with a randomized spatial offset (~300m to 500m) to conceal specific private residences.
2. Private Verification Attributes
Certain attributes (such as wallet contents, device wallpapers, serial initials, and private engraved marks) are flagged with isPrivate: true. These attributes are filtered out of public responses and are exclusively utilized in two-way ownership verification challenges.
3. Communications & Contact Shielding
User phone numbers and email addresses are masked by default. All initial owner-to-finder coordination occurs over WebSocket-backed private conversations. Contact details can only be voluntarily exchanged by the users when planning in-person handovers.
4. Data Retention & Expiration
Reports that remain open without updates for more than 90 days are transitioned to EXPIRED status and removed from public search indexes. Security event audit logs are preserved for compliance and fraud detection.