Privacy Policy
Last updated: September 1, 2026
1. What We Collect
When you sign up, we collect:
- Your email address (from Google or GitHub OAuth)
- Your name (from your OAuth provider)
- Your IP address (for abuse prevention and rate limiting)
- Your OAuth provider account ID (to prevent duplicate accounts)
When you use the API, we collect:
- Request metadata (timestamp, API key, endpoint, response time)
- The name and GitHub URL you submit in each request
- Credit usage and billing history
2. How We Use Your Data
- To authenticate your account and manage sessions
- To process payments and track credit usage
- To enforce rate limits and detect abuse
- To improve the Service (aggregate, anonymized metrics)
- To comply with legal obligations
3. What We Do NOT Collect
- We do not store the full results of your API queries beyond what is needed for billing
- We do not sell your data to third parties
- We do not use your data for advertising
- We do not track you across other websites
4. Data Sources
PersonFinder aggregates publicly available data from:
- Public developer profiles and commit history
- Public personal websites and portfolios
- Public web search results
- Public search engine results
All data returned by the API is publicly accessible on the internet. We do not access private data, breach authentication systems, or circumvent access controls.
5. Data Storage
Your account data is stored in PostgreSQL on Cloud SQL. API keys are stored as hashes — we never store the raw key after the one-time reveal.
Query results (the contacts found) are not permanently stored unless you explicitly save them through the dashboard. The engine processes results in memory and returns them in the API response.
6. Data Retention
- Account data: retained until you delete your account
- Usage logs: 90 days
- Abuse detection data: 7 days after the lock expires
- Billing records: 7 years (as required by Indian tax law)
7. Your Rights
Under applicable data protection laws (including the Digital Personal Data Protection Act, 2023 (India) and GDPR for EU users), you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to legal retention requirements)
- Export your data in a machine-readable format
- Withdraw consent for data processing
To exercise these rights, email privacy@personfinder.dev.
8. Security
We protect your data with: OAuth-only authentication (no passwords), SHA-256 hashed API keys, IP-based abuse detection, rate limiting, encrypted data in transit (TLS), and least-privilege IAM on cloud infrastructure.
9. Third-Party Services
We use these third-party services that may process your data:
- Google / GitHub OAuth — for authentication
- Razorpay — for payment processing
- Web search providers — for discovering public data
- AI model providers — for email selection
- Cloud hosting providers — for infrastructure
Each service has its own privacy policy. We share only the minimum data necessary for each service to function.
10. Cookies
We use a single session cookie for authentication. We do not use tracking cookies, analytics cookies, or advertising cookies.
11. Children's Privacy
The Service is not available to anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact privacy@personfinder.dev.
12. Changes
We may update this Privacy Policy at any time. Material changes will be notified by email. Continued use after changes constitutes acceptance.
13. Contact
For privacy questions or requests, email privacy@personfinder.dev.