Privacy Policy
Last updated: August 22, 2026
This Privacy Policy explains what personal data Findest processes when you use the Service, why, who else sees it, and the rights you have over it. Findest is operated by Javier Silgo Merino, self-employed (autónomo) in Spain, DNI 49836587A, acting as the data controller. Contact for anything related to this policy: [email protected].
1. Data we collect
Account data
Email address and password (hashed) when you sign up, plus any name you add to your profile or team.
Mail from your connected Gmail
When you connect your Gmail, Findest reads new mail as it arrives to find attachments that match your rules. We log the sender, subject, and date of every new email so you can see what happened in your History, but we only download and keep the attachment itself when it matches one of your rules — everything else is checked and then left alone.
AI classification results
For each document: the label the AI assigned, its confidence score, and any structured data it extracted (e.g. issuer, amount, date on an invoice), so the rules engine and your History can use it.
Cloud and email connections
OAuth tokens for the cloud and email accounts you connect (Google Drive, Microsoft OneDrive, Dropbox, Gmail), and metadata about the connection (which account, since when, last error). The tokens themselves are stored in a database table with no read policies at all — not even your own logged-in session can query it; only trusted backend processes can use them to act on your behalf.
Rules and filing history
The filing rules you create and a record of every document processed: its status, where it was filed (or why it wasn't), and timestamps.
Billing data
Your plan and subscription status. Card details and invoicing are handled entirely by Lemon Squeezy, our payment processor — we never see or store your payment card number.
Technical data
Standard web server logs (IP address, browser, timestamps) for security and troubleshooting.
2. Why we process it, and the legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Operate the Service: receive, classify, and file your documents | Performance of a contract |
| Process payments and manage your subscription | Performance of a contract |
| Respond to support requests | Performance of a contract / legitimate interest |
| Security, fraud prevention, abuse detection | Legitimate interest |
| Send service emails (confirmations, password reset, plan/failure alerts) | Performance of a contract |
| Legal and tax record-keeping for invoices | Legal obligation |
3. What each cloud provider can see and do
When you connect a storage account, Findest requests full read/write access to it — not a scope limited to files Findest itself creates — because the folder browser lets you pick and reuse folders you already have, instead of confining you to an app-only folder:
- Google Drive: the
drive.filescope (only the folders you pick in Google's picker and the files Findest writes into them; the rest of your Drive is not accessible). - Microsoft OneDrive:
Files.ReadWrite. - Dropbox: full read/write access to your Dropbox.
- Gmail: read-only IMAP access using an app
password — Findest can never send, delete, or modify anything in
your mail, and never marks a message as read. Outlook uses the
equivalent
Mail.Readpermission instead.
In practice, Findest only reads folder names and metadata to show you the folder browser, and only writes the files it classifies for you — but the storage permission itself is broad, and you should be aware of that before connecting an account. You can disconnect any provider at any time from Connections, which revokes its stored token.
Findest's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Who we share data with
We don't sell your data, and we don't use your documents to train AI models. We share data only with the providers that operate the Service on our behalf ("subprocessors"), strictly to the extent needed:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, authentication, private file storage, and backend functions | EU (eu-west-2) |
| Google (Gemini API) | Reads document content to classify it and extract data | Google's infrastructure, may process outside the EU under standard contractual clauses |
| Google (Gmail API) | Reads new mail via the read-only connection you grant, to find attachments that match your rules | Google's infrastructure, may process outside the EU under standard contractual clauses |
| Google Drive / Microsoft OneDrive / Dropbox | Destination cloud storage you connect and control | Per your own account with each provider |
| Resend | Sends account emails (confirmation, password reset, security alerts) | EU (eu-west-1) |
| Lemon Squeezy | Payment processing and billing, acting as merchant of record | Global payment infrastructure |
| Hostinger | Hosts the public website and app (not your documents), and our contact mailbox | EU |
We may also disclose data if required by law, or to protect the rights, safety, or property of Findest or others.
5. How long we keep data
The final destination of your documents is your own cloud storage. Findest keeps a temporary copy in private storage while it processes a document and to allow retries if an upload fails — it isn't deleted the instant filing succeeds, since keeping it briefly is what makes retries possible, but it's isolated per user at the database level and you can delete it from your dashboard at any time. Filing history (metadata, not the file itself) is kept as long as your account exists, so you can see what happened to a document later. Deleting your account deletes all of it: documents, rules, connections, and history, in cascade, with nothing left behind.
6. Your rights
Under GDPR, you can:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Delete your account and all associated data, at any time, from Settings — no need to ask us.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent where processing relies on it.
To exercise any right that isn't self-service in the app, email [email protected]. You also have the right to complain to your national data protection authority — in Spain, the Agencia Española de Protección de Datos (AEPD).
7. Security
Documents are stored in per-user isolated storage enforced at the database level (row-level security), not just in application code. Cloud OAuth tokens are kept in a table with zero read policies, reachable only by trusted backend processes, never by a browser session — even your own. Platform secrets are encrypted at rest and read at runtime, not stored in plain configuration. Webhook calls into our backend (incoming email, payment events) are signature-verified. No system is perfectly secure, but these are concrete, structural choices, not just a promise. See Security for more.
8. Cookies
The public website and app use technical cookies/local storage needed to keep you signed in and remember your preferences (e.g. language). The public website also measures aggregate traffic (pages viewed, referrers, country) with Cloudflare Web Analytics, which doesn't use cookies or any device fingerprinting and can't identify individual visitors — this one is always on, as it doesn't process personal data.
If you accept the optional cookie in the banner, the public website also loads the Meta Pixel, which helps us measure how our ads perform and, if we ever run paid campaigns, show them to people likely to be interested. It's never loaded before you accept, and rejecting means it's never loaded at all. You can change your choice any time from "Cookie settings" in the footer, and you can also opt out of Meta's ad personalization directly in your Facebook ad settings or in your browser's tracking-protection settings.
The same optional acceptance also loads PostHog, which we use to understand how visitors move through the public website (pages viewed, general location, referring site) so we can fix confusing pages and see which ones actually work. It runs on PostHog's EU servers. The signed-in app (app.findest.site) also uses PostHog to understand product usage — which features get used, where people get stuck — tied to your account so we can act on it, never sold or used for advertising.
9. Children
Findest isn't directed at children, and you must be at least 16 to use it.
10. Changes to this policy
If we materially change what we collect or how we use it, we'll notify you by email before the change takes effect. The date at the top of this page always reflects the latest version.