Found at School Privacy Policy
Last updated: September 10, 2026.
Found at School is a lost-and-found service for schools. Parents and guardians use it to report a child's lost belongings; school staff use it to log found items and return them. This policy explains what the service collects, why, who can see it, how long it is kept, and the choices you have. It is written to be read alongside the school district's own privacy policy and the agreement between the district and Found at School.
Who we are and whom this covers
Found at School is a product of Line Lead, Inc., a Delaware corporation ("Found at School," "Found," "we," "us," or "our"). Line Lead, Inc. is the legal operator of the service and the service provider for the student information it handles; contact privacy@foundat.school, 4183 Franklin Rd, Ste B1, Murfreesboro, TN 37128. The service is provided to schools under an agreement with the school or district. Where the district makes the service available to its families, Found at School acts on the district's behalf for the student information involved, in the way a school official would under the Family Educational Rights and Privacy Act (FERPA), and the district's agreement governs.
Accounts are for adults only: parents or guardians, and school staff. Children do not use the service and no account is created for a child. Because no child uses the service directly, the Children's Online Privacy Protection Act (COPPA) rules for online collection from children do not apply; information about a child is provided by that child's parent or guardian, and by school staff describing found belongings.
What we collect
From a parent or guardian
- Your email address and the sign-in identity you choose (Google or Apple). We never see your password.
- For each child you register: first name, grade, teacher's name, and an optional clothing size. We do not ask for a last name, date of birth, photo of the child, student ID, or address.
- For each lost-item report: up to three photos of the item, its category, colors, brand, size, and an optional description you write.
- Your device's push-notification token, if you allow notifications.
From school staff
- Email address and sign-in identity.
- For each found item: up to three photos of the item and the location in the school where it was found.
Automatically
- A record of significant actions in the service (for example, who viewed an item's photos, who claimed a match, who handed an item back), with the account, role, time, and the internet address the request came from. This is the audit trail the district relies on to answer "who accessed my child's information".
- Standard server logs with technical identifiers. Server logs are written to exclude names, emails, and photo links.
Photos and faces
Photos are meant to show belongings, not people. Before a photo leaves your device, the app detects and blurs faces on the device. The server runs a second detection with a stronger model on every photo. If the server cannot verify that check for a staff photo, the item is held and its photos are visible only to the person who uploaded it and to a school administrator until a person confirms no face is visible. A parent's photo that cannot be checked is refused so it can be retaken. Location and camera metadata embedded in photos is removed before storage.
How artificial intelligence is used, and how it is not
To match found items to reports, the service sends the three photos of a found item (never a lost-item report, never a child's information) to an artificial-intelligence vision service operated by Anthropic. The service returns a description of the item: category, colors, brand, size, and distinctive features such as wear or a patch. It is instructed not to transcribe handwriting, names, initials, phone numbers, addresses, or classroom or teacher names, and not to describe any person, and its answers are filtered again on our servers to remove quoted text and personal descriptors. Photos are fetched by the vision service through links that expire within an hour.
Matching is a suggestion, not a decision. Each suggested match shows the reasons behind it (category, color, brand, size, location, and distinctive features). Nothing changes hands until the parent confirms the match and school staff hand the item back in person.
Who can see what
- You see your own children, your reports, the matches suggested for them, and a log of who has viewed the photos on each of your reports (by role and time, never by name).
- Staff at your child's school see found items at their school and the reports that may match them. They see what an item looks like. They do not see your child's identity from a report: the child's identifier and your written description are withheld from staff views.
- A school administrator additionally manages who belongs to the school, the roster of parent emails the district provides, the school's enrollment code, and the audit trail for the school.
- Other families never see your child's information. A family sees a found item in two ways: when it has been suggested as a match for one of their own reports, or when they search the school's unclaimed found items by description (for example "purple sneakers") to look for something they did not register. Search shows only items that are on the shelf and not claimed, with faces blurred, and every search is recorded in the school's access log. Asking to claim an item from search creates a report for your child; school staff decide whether it is yours, and nobody is notified until they do.
- No information is sold, and none is used for advertising.
Service providers
We use the following providers to run the service. Each processes data only to provide the service.
| Provider | What it processes | Purpose |
|---|---|---|
| Supabase | Accounts and sign-in, the database, and photo storage (private bucket, encrypted in transit and at rest) | Hosting the data |
| Render | The application servers and their logs | Running the service |
| Anthropic | Photos of found items, through expiring links; the returned item description | Describing found items for matching |
| Apple | Push notifications (category-level text only, for example "a jacket may match your report"); Sign in with Apple | Notifications and sign-in |
| Sign in with Google | Sign-in |
The district may request the current terms of each provider from us.
How long we keep information
| Information | Kept until |
|---|---|
| An item you registered and its photos | Until you remove it, remove the child it belongs to, or delete your account |
| A found item and its photos | 90 days after it is found, unless the district sets a different period |
| A report or item with a pickup in progress | The pickup is completed, then the period above |
| Notifications | 90 days |
| A child's first name, grade, teacher, and size | Until you remove the child or delete your account |
| Your account | Until you delete it |
| The audit trail | Two years, then removed |
Removal is automatic, runs nightly, and deletes photos from storage as well as the records.
Your choices and rights
- Download your data. From Profile, "Download my data" produces a file with everything the service holds about your account.
- See who looked. Each of your reports has a "Who has seen this" view.
- Correct or remove a child. You can edit or remove a child at any time.
- Delete your account. From Profile, "Delete account" removes your children, your reports, their photos, and your notifications, revokes your sign-in, and anonymizes the account record. It cannot be undone. School staff who delete their account keep the found items they logged in the school's records, without their name.
- Notifications can be turned off in your device settings at any time.
- Questions or requests about a child's records can also be made to the school, which can answer them from the audit trail.
Security
Data is encrypted in transit. The database refuses access from anything other than the service itself; the sign-in key built into the app cannot read any data. Every request is verified locally against the sign-in provider's keys, and access is limited by role and by school. The service records who accessed what in an append-only trail. We test for the failure cases that matter most: an item at another school is invisible, a photo cannot be served without a record, and a photo whose face check failed cannot be processed.
Changes and contact
If this policy changes in a way that affects what is collected or how it is used, the district and account holders will be told before the change takes effect. Questions: privacy@foundat.school. Postal address: 4183 Franklin Rd, Ste B1, Murfreesboro, TN 37128.