Legal
Privacy Policy
Last updated: September 15, 2026
Who we are
FindHue is made by EduMon Studios LLC. If you have questions about this policy or your data, see Contact below.
The short version
FindHue is a daily color-matching photo game you play with friends. Private capture attempts stay on your device unless you deliberately publish a Find, but the app and its service providers also process account, connection, security, diagnostic, analytics, and advertising information needed to operate the service. We don't sell your data. The sections below explain what's collected, why, and who else may process it.
Information you provide directly
- Display name and avatar. You can set a display name (shown to friends) and a profile picture. Your avatar photo stays on your device only — it is never uploaded anywhere. Your display name is stored on our server (Supabase) so friends can see who's who.
- Sign in with Apple. FindHue works from the moment you open it, with no account or login screen — an anonymous session is created automatically so server-backed features can work without requiring you to sign in. If you choose Settings → Save account with Apple, FindHue uses Sign in with Apple to attach a permanent identity to that same anonymous account. Depending on what you allow Apple to share, this can include your name and an email address (which may be an Apple-generated private relay address rather than your real one). We store Apple's own stable, per-app identifier for your account for reference; we do not use it for anything beyond making sign-in work.
- Friend connections. Adding a friend (by invite code or QR scan), accepting or declining a friend request, and removing or blocking someone are all stored against your account so the Friends feature works.
- Friend Groups. Creating, joining, or leaving a Friend Group, and your membership/role in it, are stored the same way.
- Reports. If you report another user's Find, we store who filed the report, who/what was reported, the reason you selected, and any note you added. Reports are visible only to FindHue for review — never to other users, including the person you reported.
The daily photo challenge
- Every private capture attempt is saved locally, whether or not you ever publish it — including photos you retake or never share. Taking or scoring a photo does not itself upload it. Local history may include the photo, challenge date, score, target and found colors, selected point, and related local metadata. FindHue does not cloud-sync this entire history.
- Publishing a Find is a separate, deliberate action ("Make This My Find"). Only photos you explicitly choose to publish as your Find are uploaded to our storage provider (Cloudflare R2); private attempts you do not publish remain on your device. If you replace a Find, the replacement photo may also be uploaded, along with its score, challenge date, target color, detected color, selected point, internal account identifier, and required technical metadata.
- Photos are re-encoded before upload, which removes normal embedded EXIF/GPS and device metadata from the uploaded image. FindHue does not request precise iOS location permission for the challenge and does not intentionally upload GPS coordinates from Find photos. Third parties such as Google may infer coarse location from network or IP information.
- Your device never receives a permanent public link to an uploaded photo — only short-lived, expiring download links generated on demand by our server, and only for people who are actually allowed to see that photo (you, or an accepted friend once it's approved and revealed).
- Published Find photos are scheduled for automatic deletion approximately 48 hours after posting. Operational failures, retries, legal or security needs, or similar circumstances may occasionally cause deletion to occur later. Metadata may be retained longer (see Retention).
Automated content moderation
Every newly published Find is screened by Microsoft Azure AI Content Safety before it is shown to other users. When you choose to publish a Find, the app tells you that the photo will be checked by Microsoft Azure AI Content Safety before it is shared. If you proceed, FindHue sends the image needed for moderation; profile or social information is not intentionally included in that image request. Moderation failures fail closed: a transient failure or unrecognized result holds the Find back rather than approving it automatically. We may retain the verdict, category, severity, provider, policy, and timestamp for moderation and safety operations. Automated moderation is not infallible.
Friends, groups, and reactions
Your Finds may be visible to accepted friends and eligible Friend Group members only after moderation, and only for a short window: the current and immediately prior challenge. FindHue does not keep a scrollable public history of old posts. Hearts are tied internally to an account for enforcement but anonymous to other users. FindHue may calculate Closest Match and Crowd Favorite; these are entertainment and social features, not financial prizes.
Automatically collected technical data
Backend infrastructure and SDKs may process technical information such as IP address, operating system, device and platform data, app version and build, request timestamps, network/server logs, internal account identifiers, crash data, stack traces, performance data, advertising interactions, and related ad-delivery information.
How we use information and legal bases
FindHue uses information for account and authentication, publishing, Friends and Friend Groups, moderation, reporting and blocking, reactions and reveals, anti-abuse limits, rewarded ads, diagnostics, analytics, security and fraud prevention, and legal obligations. Depending on the situation, our legal basis may be performance of the service contract, legitimate interests, consent, or legal obligations. Consent is not the legal basis for every processing activity.
Privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent, and complain to a data-protection authority. These rights may be subject to applicable exceptions and verification requirements. You can manage device permissions through iOS Settings, delete your FindHue account from Settings → Delete account, or contact us about other privacy requests using the details below.
Analytics and crash diagnostics
FindHue uses PostHog for basic product analytics and crash/error reporting, active only in production/TestFlight builds (never during local development). What this does and doesn't include:
- FindHue identifies analytics records to PostHog using an opaque internal account identifier rather than your name or email. We do not intentionally send your display name, email address, or avatar as analytics properties.
- Every event FindHue sends goes through an allow-listed vocabulary of specific product events (e.g., "a Find was published," "a rewarded ad was watched") — not a general activity log.
- FindHue applies a defense-in-depth filter intended to remove tokens, passwords, email addresses, photo/file URIs, invite codes, and similar sensitive values from analytics events and error reports before transmission.
- Session replay, precise location/GeoIP enrichment, surveys, and remote feature flags are all turned off — FindHue doesn't use any of them.
- Crash reports may include technical diagnostic information (device/OS type, app version, stack traces) needed to fix bugs.
Advertising
The first 3 Find submissions or replacements per challenge day are free. After that, an additional Find submission may require one successfully completed and server-verified rewarded ad. Private captures and scoring remain unlimited and do not require an ad. FindHue requests non-personalized ads, does not request App Tracking Transparency permission, and does not intentionally provide Google with your Find photo, display name, email, friend list, or private history. Google and ad infrastructure may nevertheless process IP address, coarse location inferred from IP, device and app identifiers, ad interactions, advertising and consent data, crash/performance information, and related ad-delivery data. Rewarded-ad completion is granted only after server-side verification.
Note: AdMob and Google's underlying ad-serving infrastructure are third-party services we don't fully control — see Third-party services below.
Third-party services
FindHue relies on service providers and third-party services to operate the app. Each may process the categories described below under its own terms and privacy practices.
| Service | What it's used for | What it can see |
|---|---|---|
| Apple | Sign-in, App Store distribution, push infrastructure (not currently used for social notifications) | Whatever you choose to share via Sign in with Apple |
| Supabase | Our backend database and authentication | Your account, profile, friend graph, groups, reports, and Find metadata |
| Cloudflare R2 | Temporary storage for published Find photos | The selected photo, generally scheduled for deletion after ~48 hours |
| Microsoft Azure AI Content Safety | Automated photo moderation | The photo file only, at the moment you publish |
| PostHog | Analytics and crash reporting | An opaque account identifier and sanitized event/crash data |
| Google AdMob | Optional rewarded video ads and consent management | Ad-request, device/app, IP/coarse-location, consent, interaction, crash, and performance data |
Where FindHue shares user data with a third-party service provider, we use providers that are subject to applicable contractual, legal, and platform obligations to protect that data. Those providers are required to provide the same or equivalent protection for user data as described in this Privacy Policy and required by applicable platform rules. Providers may maintain their own operational and security logs and may process information for permitted service-related purposes under their own privacy notices. FindHue does not control those independent systems and cannot guarantee security or conduct outside our reasonable control.
Retention and deletion
- Local device data (your private capture history, avatar, app settings, reminder time) stays on your device until you clear it or uninstall the app.
- Published Find photos are scheduled for deletion approximately 48 hours after posting, but operational failures, retries, legal/security needs, or similar circumstances may delay deletion. Metadata may remain longer.
- Find metadata (score, date, target/found color, whether it was published) is kept as part of your personal history for as long as your account exists.
- Reports, blocks, and moderation records are kept for as long as your account exists, to keep the reporting/blocking system working correctly.
- Deleting your account (Settings → Delete account) permanently removes the server-side account/auth identity and associated social and account data. See Account deletion below for exactly what this does.
Account deletion
Settings → Delete account is available to anyone using the app — you don't need to have saved your account with Sign in with Apple first. It:
- Deletes your profile and, through it, every friendship, friend request, group membership, report, block, reaction, and Find record tied to your account.
- Deletes the underlying account identity itself (not just the data associated with it), so nothing about you remains sign-in-able afterward.
This can't be undone. Cloud-object deletion may finish asynchronously. Deleting your account is separate from Settings → Clear all records, which erases local-only private captures from that device; uninstalling the app also handles local-only data. Delete account does not necessarily synchronously erase every local file.
Local device data
Your private capture history (every Find attempt, published or not), your avatar photo, your app preferences, and your reminder settings are stored only on your device using standard iOS local storage. FindHue does not upload private capture attempts unless you explicitly choose to publish them as a Find. Photos you publish as a Find, including replacement Finds, may be uploaded as described above.
Security
Data in transit to and from Supabase, Cloudflare R2, and Azure is encrypted (HTTPS/TLS). Access to data on our backend is restricted using database-level row-level-security and application authorization rules. Photo storage uses short-lived, single-purpose links rather than permanent public URLs. No system is perfectly secure, and we can't guarantee absolute security of any information you transmit to us.
International data processing
FindHue's backend and analytics infrastructure run on servers operated by our service providers, which may be located in the United States or other countries. By using FindHue, you understand your information may be processed outside your own country.
Children
FindHue is not directed to users below the minimum lawful age for independent use in their jurisdiction. Where applicable, users must obtain required parent or guardian permission. If you believe a child has provided us information improperly, contact us using the details below.
Changes to this policy
We may update this policy as FindHue changes and will update the "Last updated" date above. Material changes may receive additional notice. We will request affirmative consent where legally required; continued use is not treated as consent to every new processing activity.
Contact
Questions about this policy or your data: support-findhue@edumon.studio, or visit our Support page for other ways to reach us.