Privacy Policy — FindEvo

Last Updated: August 3, 2026 · Effective Date: August 3, 2026

This version replaces the policy dated May 30, 2026. It corrects our description of the AI provider we use, the analytics and email services we use, how long scored posts are kept, and how access control is enforced.

1. Who We Are

FindEvo (“we”, “our”, “us”) is operated by an individual founder based in Ankara, Turkey, who is the data controller for the personal data described here. This policy explains what we collect, why, and what you can do about it, when you use the Service at gofindevo.com. We also send email from getfindevo.com.

By using FindEvo you agree to the handling of information described in this policy.

2. Information We Collect

2.1 Information you provide

  • Account information: email address and password (handled by Supabase Auth; passwords are stored hashed and are never visible to us)
  • Product information: your website URL, product description and target audience
  • Onboarding survey answers: goals, audience type, industry, outreach preferences
  • Negative ICP settings: the customer types you want excluded from your feed
  • Subreddit preferences: the communities you choose to monitor
  • Reddit account handle: the public username you nominate for a product, so we can compare its public karma and account age against a subreddit’s stated requirements. We never ask for, receive or store your Reddit password or OAuth tokens.
  • Lead pipeline data: leads you save, their stage, your notes, next steps and follow-up dates
  • Drafts you submit to the AI-writing check (see Section 4.2)
  • Support correspondence you send us

2.2 Information collected automatically

  • Usage data: pages visited, features used, actions taken in the app, collected through PostHog product analytics
  • Engagement log: the outreach actions you record, used to calculate your daily quota and warnings
  • AI usage counters: number of scores, approach guides and site analyses performed
  • Technical data: IP address, browser and device information, and server logs, used for session management, security and abuse prevention
  • API usage: requests made with an API key, for rate limiting and security auditing

2.3 Information from third-party sources

  • Reddit content: publicly available posts and comments, including title, body, subreddit, timestamp, score and the author’s public username. This is retrieved through our ingestion provider ScrapeBadger and, as a fallback, Reddit’s public endpoints.
  • Subreddit rules: publicly published sidebar rules and pinned moderator posts
  • Website content: publicly available content from URLs you submit for analysis
  • Payment status: subscription and payment state from Creem.io. We do not receive your card number.

2.4 What we do not collect

We do not collect special-category data, we do not buy data from data brokers, we do not access private Reddit messages or non-public Reddit content, and we do not require or store Reddit credentials.

3. How We Use Information and Our Legal Bases

PurposeLegal basis
Create and operate your account, provide the features you subscribe toPerformance of a contract
Analyze your product, suggest subreddits and keywords, score posts, generate approach guidancePerformance of a contract
Assess subreddit ban risk and check drafts for AI-writing patternsPerformance of a contract
Track your lead pipeline and engagement quotaPerformance of a contract
Process payments and keep billing recordsContract and legal obligation
Send transactional email: welcome, digest, billing and service noticesContract
Enforce plan limits and prevent abuseLegitimate interests
Secure the Service, investigate incidents, audit API usageLegitimate interests
Understand feature usage and improve the productLegitimate interests
Record new signups in our internal customer pipeline (see Section 6)Legitimate interests
Send optional product or marketing emailConsent, withdrawable at any time

We do not sell personal data, and we do not use it for advertising or profiling for advertising.

4. AI Processing

4.1 What is sent to an AI provider

We use OpenRouter as our AI gateway. The model currently in use is DeepSeek V4 Flash (deepseek/deepseek-v4-flash). We may change the model or provider as the product develops; the current provider is always stated in this section, and we will update this policy when it changes.

The following is sent to the AI provider:

  • Content from the website URL you submit, and your product description, for product analysis
  • Public Reddit post and comment content, for intent and fit scoring
  • Public Reddit post content and your product context, to generate approach guidance

We do not send your password, your payment data, your lead notes, or your drafts.

We instruct our provider not to use submitted content for model training. The provider processes data under its own privacy terms.

FindEvo does not generate ready-to-send messages. All AI output is strategic guidance. You write your own text.

4.2 The AI-writing check does not use AI

The draft checker is deliberately built without a model. When you submit a draft, it is analyzed on our own server by deterministic pattern rules, the result is returned to you, and the text is discarded. Your draft is never sent to an AI provider and never written to our database.

4.3 Automated decisions

Intent scores, ICP fit scores and ban risk levels are automated. They rank and filter information for you; they have no legal or similarly significant effect on any person, and you remain free to ignore them.

5. Reddit Data

FindEvo works only with publicly visible Reddit content. We do not:

  • Access private messages or any non-public content
  • Store Reddit passwords or OAuth tokens
  • Build persistent, cross-post profiles of Reddit users
  • Use Reddit data for any purpose other than helping you find and evaluate relevant conversations

We store public post and comment content together with the author’s public username and the signals we derive for a specific post, such as intent score, fit score and whether the author appears to be selling something themselves. These signals are calculated per post and per product; they are not aggregated into a persistent profile of an individual.

If you save a post as a lead, the associated public username and your own notes are stored in your pipeline until you delete the lead or your account.

Rule and risk caches are not personal data. Subreddit rule summaries and ban risk reports describe a community, not a person, and are cached and shared across accounts to avoid repeated requests to Reddit.

If you are a Reddit user and want content about you removed from our systems, email contact@gofindevo.com.

6. Sharing and Sub-processors

We do not sell your personal data and do not share it with advertisers or data brokers. We share it only with the providers below, each acting on our behalf under their own terms:

ProviderPurposeLocation
SupabaseDatabase and authenticationEU / US
VercelApplication hosting, request logsGlobal edge / US
RailwayBackground scanning and scheduled jobsUS
ScrapeBadgerReddit content ingestionUS
OpenRouter (routing to DeepSeek)AI processing of website, product and public post contentUS / global
Creem.ioPayment processing as Merchant of RecordEU
ResendTransactional email deliveryUS
PostHogProduct analyticsEU / US
NotionInternal record of new signups (email address and signup metadata only)US

We may also disclose data where required by law, to enforce our Terms, or in connection with a sale or transfer of the business, in which case we will notify you beforehand.

7. International Transfers

We are based in Turkey and our providers are located in the European Union, the United States and other countries. Where personal data of EU, UK or Turkish residents is transferred outside its home jurisdiction, we rely on the receiving provider’s standard contractual clauses or equivalent safeguards. You may request details of these safeguards.

8. Payments

Payments are processed by Creem.io, acting as Merchant of Record. We do not receive or store your full card details. We receive only the subscription status, plan, and the identifiers needed to link a payment to your account. Creem.io handles your payment information under its own privacy and security terms, and retains transaction records as required by tax law.

9. Security

  • Access control is enforced in our application layer. Every request that touches your data is checked against the account that owns it. A request for a record you do not own is refused.
  • Row-Level Security is enabled in the database as an additional layer of defence for client-side access. It is not our only control, and we do not rely on it alone.
  • All traffic is encrypted in transit (HTTPS/TLS). Data is encrypted at rest by our database provider.
  • Passwords are hashed by Supabase Auth and are never visible to us.
  • API keys are stored as SHA-256 hashes; the plaintext key is shown to you once and cannot be recovered by us. Revoking a key marks it permanently unusable rather than deleting the record.
  • We do not store Reddit credentials of any kind.

No system is perfectly secure. If a breach affecting your personal data occurs, we will notify affected users and the relevant authority without undue delay and, where required, within 72 hours of becoming aware of it.

10. Data Retention

DataRetention
Account and product dataUntil you delete your account
Scored posts and commentsKept while the related product exists, so your feed, history and saved leads remain usable. Deleted when you delete the product or your account. Older scored content may be pruned periodically.
Approach guidesKept per post while your account is active
Lead pipeline data and notesUntil you delete the lead or your account
Engagement logKept while your account is active, for quota calculation
Subreddit rule and ban risk cacheUp to 30 days, then refreshed (not personal data)
Reddit account karma and age snapshotUp to 7 days, then refreshed
AI usage counters90 days
API keysHash kept until revoked; the revocation record is kept for security auditing
Server and security logsUp to 90 days
Product analytics eventsUp to 12 months
Signup record in our internal pipelineRemoved on request or when you delete your account
Billing recordsRetained by Creem.io for the period required by tax law

Backups may retain deleted data for up to 30 days before they are overwritten.

11. Your Rights

Depending on where you live, you may have the right to:

  • Access a copy of your personal data
  • Correct inaccurate data, via your account settings or by contacting us
  • Delete your account and associated data via Settings → Account → Delete Account
  • Export your data in a portable format
  • Object to or restrict certain processing, including processing based on legitimate interests
  • Withdraw consent for optional email at any time, without affecting prior processing
  • Complain to your data protection authority. In Turkey this is the KVKK Board; in the EU or UK it is your national supervisory authority.

To exercise any of these, email contact@gofindevo.com. We respond within 30 days. We do not discriminate against you for exercising a right.

If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising.

12. Cookies and Analytics

  • Essential cookies: session cookies set by Supabase Auth to keep you signed in. Disabling them prevents login.
  • Analytics: we use PostHog to understand how the product is used. PostHog sets a first-party identifier and records events such as page views and feature usage, linked to your account once you sign in. It is configured without session recording, without cross-site advertising identifiers, and with IP data used only for coarse geography and security.
  • We do not use advertising or third-party ad-tracking cookies.

You can block cookies in your browser or use a browser Do Not Track / Global Privacy Control signal, which we honour for analytics.

13. Children's Privacy

FindEvo is not intended for anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it.

14. Changes to This Policy

We may update this policy. Significant changes are announced in the app or by email. The “Last Updated” date at the top always reflects the current version. Continued use after a change constitutes acceptance.

15. Contact

FindEvo is operated by an individual founder based in Ankara, Turkey.