Privacy Policy
1. Who we are
O-Find is operated by Beyond Evolution Labs LLC (Florida, USA). This policy describes how we handle personal data when you use O-Find (web app, PWA, or native shells that load our service).
2. Who the product is for
O-Find is an 18+ private preference and partner-sharing tool. It is not a public social network. There are no public feeds, followers, or open discovery of intimate data.
3. Key terms we use
To keep this policy, the Terms of Service, and in-app summaries consistent, we use these meanings:
- Personal data means information that identifies or can reasonably be linked to you (for example email, username, or account IDs).
- Preference content means O-ID answers, In-Depth answers, O-Map data, custom questions, and similar intimacy-related content you enter.
- Identifiable intimate content means preference content that is still linked to you as a person (or that we could reasonably re-link to you without special effort).
- Aggregated / de-identified insights means statistics, trends, research summaries, or similar outputs produced so they are no longer reasonably linkable to you, used to improve O-Find or for research and commercial insight products.
4. Data we collect
- Account: email, authentication identifiers, password (hashed by our auth provider).
- Profile: username, body type, bio, optional details (age text, location, pronouns, etc.), avatar image URL, cosmetic preferences.
- Preference content: O-ID answers, In-Depth questionnaire answers and privacy flags, O-Map paint/body-part data, custom questions.
- Connections: partner links, partner requests, blocks, reports you submit.
- Messages: direct messages (retained for a limited window, typically 48 hours).
- Journal: private journal entries and optional voice memos if you use Subscriber journal features.
- Usage & technical: last-active timestamps, device/browser info as needed for security and support, newsletter email if you join the waitlist.
- Payments: subscription and purchase status, renewal state, and related billing metadata via our payment processor (e.g. Stripe). We do not store full card numbers; the processor stores payment methods.
- Legal acceptance: timestamps when you confirm age (18+) and accept Terms/Privacy versions.
5. How we use data
- Provide core product features (profiles, maps, questionnaires, partner share, DMs, journal).
- Authenticate you and protect accounts against abuse.
- Process subscriptions and shop purchases when you buy them, including recurring renewals and cancellation or payment-method updates you request through in-app manage billing / the processor’s Customer Portal.
- Respond to reports and enforce safety rules.
- Improve reliability, security, and product design (including technical analytics).
- Send product emails you request (e.g. updates newsletter) and transactional auth email.
- Produce aggregated / de-identified insights as described in §6.
6. What we do not sell — and how insight products work
O-Find is private partner communication first. Optional subscriptions and cosmetics may be offered. A primary long-term way we fund and improve the product is data-informed insight—learning from patterns across many users—not by putting your private preference content on a public feed.
We do not:
- Sell or license identifiable intimate content (your preference content still linked to you) to advertisers, data brokers, or the public as a personal dossier or ad-targeting package.
- Operate a public marketplace, feed, or open discovery of your preference content.
- Use your private journal entries or direct messages as identifiable commercial insight content or as training material tied to you.
We may:
- Create and commercialize aggregated / de-identified insights (research findings, statistics, category trends, business intelligence) derived from accounts, preference content, and usage.
- Share those outputs with research or commercial recipients under contracts that limit misuse and re-identification attempts.
- Use service providers (hosting, auth, payments, email) as needed to run O-Find.
We design insight work so recipients of commercial or research products should not reasonably re-identify you from what we intentionally publish or license. No de-identification method is perfect; we take reasonable steps and do not attempt to re-identify people who appear only in de-identified sets.
Where U.S. state privacy laws define “sale” or “share” more broadly than ordinary language, we will honor applicable opt-out and disclosure rights when you contact us. Saying we do not sell identifiable intimate content as ad-targeting dossiers does not mean we never create commercial value from de-identified patterns.
7. Who can see your identifiable data
- You: your account, profile, preference content, journal (as the product provides).
- Partners you choose: after mutual connection, partners may see profile fields and preference content you have not hidden.
- Service providers: infrastructure and auth (e.g. Supabase), hosting (e.g. Vercel), payments (e.g. Stripe), email delivery — only as needed to run the service.
- Insight / research recipients: only aggregated / de-identified insights as in §6—not your identifiable intimate content as a personal dossier.
- Legal: if required by law or to protect users from serious harm (e.g. credible underage use reports).
8. Storage & security
Data is stored on secured cloud infrastructure with authentication and database row-level security. No security system is perfect; we work to protect sensitive preference data and limit access. Direct messages are designed to expire automatically after a short period.
9. Retention
We retain account and preference content while your account is active. DMs expire on a short schedule. When you delete your account, we remove associated personal data from active systems (subject to brief backup windows and any legal holds). Aggregated / de-identified insight sets that no longer identify you may be retained. Payment records may be retained by processors as required for finance/tax compliance.
10. Your rights
- Access / export: download a copy of your data from Me → Account → Download my data (signed-in).
- Delete: Me → Account → Delete account permanently removes your account and associated personal data from our active systems (subject to §9). Public instructions (including email requests): Delete your account.
- Correct: update profile and answers in-app.
- Billing: manage or cancel a web subscription and update payment methods via in-app manage billing / the payment processor’s Customer Portal (see Terms §7).
- Control partner sharing: privacy toggles, hide sections, block/remove partners.
- State privacy rights: depending on where you live (e.g. GDPR, CCPA, and similar laws), you may have rights to know, delete, correct, or opt out of certain sales/sharing. Contact us to exercise them. We will not discriminate against you for exercising privacy rights we are required to honor.
11. Children
O-Find is not directed to anyone under 18. We do not knowingly collect data from minors. If you believe a minor has used the service, contact us immediately.
12. International users
We are based in the United States. If you use O-Find from another country, your data may be processed in the U.S. and other locations where our providers operate.
13. Changes
We may update this policy. Material changes will be reflected by updating the version date on this page and, when appropriate, in-app notice. Version: 2026-08-11.