Privacy Policy — FindEvo
Last Updated: August 3, 2026 · Effective Date: August 3, 2026
This version replaces the policy dated May 30, 2026. It corrects our description of the AI provider we use, the analytics and email services we use, how long scored posts are kept, and how access control is enforced.
1. Who We Are
FindEvo (“we”, “our”, “us”) is operated by an individual founder based in Ankara, Turkey, who is the data controller for the personal data described here. This policy explains what we collect, why, and what you can do about it, when you use the Service at gofindevo.com. We also send email from getfindevo.com.
By using FindEvo you agree to the handling of information described in this policy.
2. Information We Collect
2.1 Information you provide
- Account information: email address and password (handled by Supabase Auth; passwords are stored hashed and are never visible to us)
- Product information: your website URL, product description and target audience
- Onboarding survey answers: goals, audience type, industry, outreach preferences
- Negative ICP settings: the customer types you want excluded from your feed
- Subreddit preferences: the communities you choose to monitor
- Reddit account handle: the public username you nominate for a product, so we can compare its public karma and account age against a subreddit’s stated requirements. We never ask for, receive or store your Reddit password or OAuth tokens.
- Lead pipeline data: leads you save, their stage, your notes, next steps and follow-up dates
- Drafts you submit to the AI-writing check (see Section 4.2)
- Support correspondence you send us
2.2 Information collected automatically
- Usage data: pages visited, features used, actions taken in the app, collected through PostHog product analytics
- Engagement log: the outreach actions you record, used to calculate your daily quota and warnings
- AI usage counters: number of scores, approach guides and site analyses performed
- Technical data: IP address, browser and device information, and server logs, used for session management, security and abuse prevention
- API usage: requests made with an API key, for rate limiting and security auditing
2.3 Information from third-party sources
- Reddit content: publicly available posts and comments, including title, body, subreddit, timestamp, score and the author’s public username. This is retrieved through our ingestion provider ScrapeBadger and, as a fallback, Reddit’s public endpoints.
- Subreddit rules: publicly published sidebar rules and pinned moderator posts
- Website content: publicly available content from URLs you submit for analysis
- Payment status: subscription and payment state from Creem.io. We do not receive your card number.
2.4 What we do not collect
We do not collect special-category data, we do not buy data from data brokers, we do not access private Reddit messages or non-public Reddit content, and we do not require or store Reddit credentials.
3. How We Use Information and Our Legal Bases
| Purpose | Legal basis |
|---|---|
| Create and operate your account, provide the features you subscribe to | Performance of a contract |
| Analyze your product, suggest subreddits and keywords, score posts, generate approach guidance | Performance of a contract |
| Assess subreddit ban risk and check drafts for AI-writing patterns | Performance of a contract |
| Track your lead pipeline and engagement quota | Performance of a contract |
| Process payments and keep billing records | Contract and legal obligation |
| Send transactional email: welcome, digest, billing and service notices | Contract |
| Enforce plan limits and prevent abuse | Legitimate interests |
| Secure the Service, investigate incidents, audit API usage | Legitimate interests |
| Understand feature usage and improve the product | Legitimate interests |
| Record new signups in our internal customer pipeline (see Section 6) | Legitimate interests |
| Send optional product or marketing email | Consent, withdrawable at any time |
We do not sell personal data, and we do not use it for advertising or profiling for advertising.
4. AI Processing
4.1 What is sent to an AI provider
We use OpenRouter as our AI gateway. The model currently in use is DeepSeek V4 Flash (deepseek/deepseek-v4-flash). We may change the model or provider as the product develops; the current provider is always stated in this section, and we will update this policy when it changes.
The following is sent to the AI provider:
- Content from the website URL you submit, and your product description, for product analysis
- Public Reddit post and comment content, for intent and fit scoring
- Public Reddit post content and your product context, to generate approach guidance
We do not send your password, your payment data, your lead notes, or your drafts.
We instruct our provider not to use submitted content for model training. The provider processes data under its own privacy terms.
FindEvo does not generate ready-to-send messages. All AI output is strategic guidance. You write your own text.
4.2 The AI-writing check does not use AI
The draft checker is deliberately built without a model. When you submit a draft, it is analyzed on our own server by deterministic pattern rules, the result is returned to you, and the text is discarded. Your draft is never sent to an AI provider and never written to our database.
4.3 Automated decisions
Intent scores, ICP fit scores and ban risk levels are automated. They rank and filter information for you; they have no legal or similarly significant effect on any person, and you remain free to ignore them.
5. Reddit Data
FindEvo works only with publicly visible Reddit content. We do not:
- Access private messages or any non-public content
- Store Reddit passwords or OAuth tokens
- Build persistent, cross-post profiles of Reddit users
- Use Reddit data for any purpose other than helping you find and evaluate relevant conversations
We store public post and comment content together with the author’s public username and the signals we derive for a specific post, such as intent score, fit score and whether the author appears to be selling something themselves. These signals are calculated per post and per product; they are not aggregated into a persistent profile of an individual.
If you save a post as a lead, the associated public username and your own notes are stored in your pipeline until you delete the lead or your account.
Rule and risk caches are not personal data. Subreddit rule summaries and ban risk reports describe a community, not a person, and are cached and shared across accounts to avoid repeated requests to Reddit.
If you are a Reddit user and want content about you removed from our systems, email contact@gofindevo.com.
6. Sharing and Sub-processors
We do not sell your personal data and do not share it with advertisers or data brokers. We share it only with the providers below, each acting on our behalf under their own terms:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU / US |
| Vercel | Application hosting, request logs | Global edge / US |
| Railway | Background scanning and scheduled jobs | US |
| ScrapeBadger | Reddit content ingestion | US |
| OpenRouter (routing to DeepSeek) | AI processing of website, product and public post content | US / global |
| Creem.io | Payment processing as Merchant of Record | EU |
| Resend | Transactional email delivery | US |
| PostHog | Product analytics | EU / US |
| Notion | Internal record of new signups (email address and signup metadata only) | US |
We may also disclose data where required by law, to enforce our Terms, or in connection with a sale or transfer of the business, in which case we will notify you beforehand.
7. International Transfers
We are based in Turkey and our providers are located in the European Union, the United States and other countries. Where personal data of EU, UK or Turkish residents is transferred outside its home jurisdiction, we rely on the receiving provider’s standard contractual clauses or equivalent safeguards. You may request details of these safeguards.
8. Payments
Payments are processed by Creem.io, acting as Merchant of Record. We do not receive or store your full card details. We receive only the subscription status, plan, and the identifiers needed to link a payment to your account. Creem.io handles your payment information under its own privacy and security terms, and retains transaction records as required by tax law.
9. Security
- Access control is enforced in our application layer. Every request that touches your data is checked against the account that owns it. A request for a record you do not own is refused.
- Row-Level Security is enabled in the database as an additional layer of defence for client-side access. It is not our only control, and we do not rely on it alone.
- All traffic is encrypted in transit (HTTPS/TLS). Data is encrypted at rest by our database provider.
- Passwords are hashed by Supabase Auth and are never visible to us.
- API keys are stored as SHA-256 hashes; the plaintext key is shown to you once and cannot be recovered by us. Revoking a key marks it permanently unusable rather than deleting the record.
- We do not store Reddit credentials of any kind.
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify affected users and the relevant authority without undue delay and, where required, within 72 hours of becoming aware of it.
10. Data Retention
| Data | Retention |
|---|---|
| Account and product data | Until you delete your account |
| Scored posts and comments | Kept while the related product exists, so your feed, history and saved leads remain usable. Deleted when you delete the product or your account. Older scored content may be pruned periodically. |
| Approach guides | Kept per post while your account is active |
| Lead pipeline data and notes | Until you delete the lead or your account |
| Engagement log | Kept while your account is active, for quota calculation |
| Subreddit rule and ban risk cache | Up to 30 days, then refreshed (not personal data) |
| Reddit account karma and age snapshot | Up to 7 days, then refreshed |
| AI usage counters | 90 days |
| API keys | Hash kept until revoked; the revocation record is kept for security auditing |
| Server and security logs | Up to 90 days |
| Product analytics events | Up to 12 months |
| Signup record in our internal pipeline | Removed on request or when you delete your account |
| Billing records | Retained by Creem.io for the period required by tax law |
Backups may retain deleted data for up to 30 days before they are overwritten.
11. Your Rights
Depending on where you live, you may have the right to:
- Access a copy of your personal data
- Correct inaccurate data, via your account settings or by contacting us
- Delete your account and associated data via Settings → Account → Delete Account
- Export your data in a portable format
- Object to or restrict certain processing, including processing based on legitimate interests
- Withdraw consent for optional email at any time, without affecting prior processing
- Complain to your data protection authority. In Turkey this is the KVKK Board; in the EU or UK it is your national supervisory authority.
To exercise any of these, email contact@gofindevo.com. We respond within 30 days. We do not discriminate against you for exercising a right.
If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising.
12. Cookies and Analytics
- Essential cookies: session cookies set by Supabase Auth to keep you signed in. Disabling them prevents login.
- Analytics: we use PostHog to understand how the product is used. PostHog sets a first-party identifier and records events such as page views and feature usage, linked to your account once you sign in. It is configured without session recording, without cross-site advertising identifiers, and with IP data used only for coarse geography and security.
- We do not use advertising or third-party ad-tracking cookies.
You can block cookies in your browser or use a browser Do Not Track / Global Privacy Control signal, which we honour for analytics.
13. Children's Privacy
FindEvo is not intended for anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it.
14. Changes to This Policy
We may update this policy. Significant changes are announced in the app or by email. The “Last Updated” date at the top always reflects the current version. Continued use after a change constitutes acceptance.
15. Contact
- Email: contact@gofindevo.com
- Website: https://gofindevo.com
FindEvo is operated by an individual founder based in Ankara, Turkey.