Last updated 7 September 2026
Found & Felt reads your photo library to find the moments worth keeping. That only works if you trust us with the photos, so this page says exactly what we collect, what leaves your phone, and what we will never do with it. Plainly, without hiding anything in the middle of a long sentence.
An email address and a password when you sign up. The password is stored hashed by our authentication provider — we never see it. There are no anonymous accounts; the book has to belong to someone.
With your permission, the app scans the photos already on your device that fall inside your book’s date range. Finding faces and grouping them into people happens on your phone. We do not upload your whole photo library, and we never have a copy of it.
We do keep two small sets of images in your account: the photos that become moments (typically one per week) and the face crops the app uses to recognise the people in your book. They live in our file storage, private to your account, so your book still opens on a new phone or after a reinstall, and so we can print it if you ask. They are deleted with the moment, the person, or the account.
The names you type for the people you tag, and which face belongs to which name. Names are only ever the ones you enter yourself.
Your answers to each moment’s question. This is the actual point of the app, and it’s stored so your book still exists when you reinstall.
If a photo carries location data, we turn those coordinates into a place name (a city, a park, a beach) so a moment can say where it happened. We store the resulting name, and we cache the lookup so we don’t repeat it.
When a scan finishes we keep a technical record of how it went — how long it took, how many photos it looked at, how many faces it found, whether it ran out of memory. Counts, durations, and reason codes only. No titles, no names, no photo identifiers.
This is the part most privacy policies bury, so here it is directly.
To recognise who is in a photo and to write each moment, Found & Felt sends cropped images of faces and the selected photos for a moment to Anthropic’s Claude API. Along with them we send the context the writing needs: the names you gave those people, the date, and the place name. This happens through our own server, so your device never talks to Anthropic directly and our API key stays on our side.
Anthropic processes these images to return a result to us. Under our agreement with them, this data is not used to train their models. We do not send your entire photo library — only the crops and the photos belonging to moments the app is actually writing.
The same crops and moment photos are the ones we store in your account, described in section 2. Nothing else from your library is uploaded.
If you are not comfortable with photos of your family being processed by an AI provider, this app is not a good fit for you, and we’d rather say so here than have you find out later.
No. Finding faces and grouping them into people runs on the phone with on-device face models. What does go to Claude is a subset: face crops so it can double-check the groupings, the handful of candidate photos in the running for each moment so it can pick one, and the chosen photo so it can write. Everything goes through our own proxy function, which forwards the request and records only the model name and token counts. It never stores or logs the images.
No. The app uses Anthropic’s commercial API, and Anthropic’s commercial terms state that API inputs and outputs are not used to train their models unless the customer opts in, which we have not. That is a different policy from the consumer Claude app, where chat training is a setting for individuals.
We use PostHog to understand where people get stuck — which onboarding step loses everyone, how often a scan fails, whether answers get abandoned half-written. It’s hosted in the United States.
In the app, analytics is deliberately narrow. Automatic event capture is off and session replay is off, so nothing is collected unless we wrote a line of code to collect it. Every event carries counts, durations, enums, and opaque identifiers — never book titles (they’re children’s names), never answer text, never photo identifiers, never place names.
On this website we use two things. PostHog tells us which pages people read and whether the early-access form works — whether someone pressed the button, and whether the submission went through. Cloudflare Web Analytics counts visits and shows where they came from; it sets no cookies and doesn’t follow you anywhere else, which is why this site has no cookie banner. The website is the one place session recording may be used; the app never records anything.
We keep this list short on purpose.
Each of these processes data on our instructions to make the app work. None of them are given your data to use for their own purposes.
We keep your book for as long as your account exists, because a book you can’t open later isn’t worth making.
You can delete an individual answer or a moment in the app at any time. If you want your whole account and everything in it deleted, email zenia@foundandfelt.com and we’ll do it — permanently, including your photos in our storage and your answers. Backups roll off on their own shortly afterwards.
Depending on where you live, you may also have the right to ask for a copy of what we hold, to correct it, or to object to how we use it. Same address; a person reads that inbox.
The app asks for access to your photo library. You can say no, or grant access to only selected photos, and you can change your mind later in your phone’s settings. If you revoke access, the app stops scanning — the book you’ve already made stays.
Found & Felt is full of photos of children, but it’s built for the adults who take them. Accounts are for adults only, and children shouldn’t use the app or create an account. If you believe a child has created an account, email us and we’ll remove it.
The app is in early testing with a small group of families. That means things change quickly, and occasionally we look at technical logs to work out why a scan failed on a particular device. Those logs follow the same rule as everything else: counts and reason codes, never your content.
If we change how we handle your data in a way that matters, we’ll tell you in the app or by email before it takes effect — not by quietly editing this page.
Found & Felt is made and operated by O’Fung Studios, LLC, which is responsible for the data described here. Questions, concerns, or a request to delete something: zenia@foundandfelt.com.