Privacy Policy
Last updated September 10, 2026
This policy explains what FindMySensi collects, why, and what choices you have. FindMySensi is a free, open-source aim trainer. We try to collect as little as possible.
Who we are
FindMySensi (“we”, “us”) is operated by Hitesh Mahay. For any privacy question or request, contact hitesh@hiteshmahay.com.
What we collect
Account data. When you create an account we store your username, email address, a hashed password, and your confirmation that you are 18 or older. Email verification uses a one-time code.
Training and score data. When you sync a practice run we store the run’s results (score, accuracy, timing, scenario and scoring version) linked to your account. Your best scores per mode are shown on public leaderboards next to your username and any cosmetic avatar, frame, or tag you have selected.
Technical data. Our hosting and email providers process standard request logs (IP address, user agent, timestamps) to deliver the service and protect it from abuse.
Stored only in your browser. Local training history, achievements, selected avatar, and interface preferences are kept in your browser’s local storage and are never sent to us unless you sync a run. A short-lived session storage entry holds your pending verification email during sign-up. Clearing site data removes all of it.
We do not currently run third-party advertising or cross-site tracking. If we add privacy-respecting analytics we will update this policy and list the provider here before enabling it.
How we use it
- To create and secure your account and sign you in.
- To send account email you request (verification, password reset).
- To calculate and display your scores, ranks, and leaderboards.
- To detect and prevent cheating, abuse, and fraud.
- To operate, debug, and improve the service.
We rely on your consent (account creation), on the performance of our agreement with you (running the trainer), and on our legitimate interest in keeping the service safe and working.
Cookies and similar technology
We use a single essential cookie to keep you signed in. It is not used for advertising or profiling. Local storage and session storage are used as described above for features you trigger. Because we use only strictly necessary storage, no consent banner is required for it; this will change if analytics is added.
Who we share it with
We do not sell personal data. We share data only with providers that run the service on our behalf, under contract:
- A cloud hosting and edge platform (application hosting).
- A managed database provider (account and score storage).
- A transactional email provider (verification and reset email).
We may also disclose data if required by law, or to protect the rights, safety, and integrity of the service and its users. Leaderboard entries (username, best score, rank, chosen cosmetics) are public by design.
How long we keep it
Account data is kept while your account exists. Synced runs and leaderboard entries are kept while your account exists or until you delete them. Provider request logs follow each provider’s own retention period, typically a few weeks to a few months. When you delete your account we remove your account data and detach or delete your scores within 30 days, except where we must retain something to comply with law or resolve disputes.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can change your email and password in account settings. For any other request, email hitesh@hiteshmahay.com and we will respond within a reasonable time. You may also complain to your local data protection authority.
Children
FindMySensi is not directed to children. You must be 18 or older to create an account, and we ask you to confirm this at sign-up. If you believe a child has given us personal data, contact us and we will delete it.
International transfers
Our providers may process data in countries other than yours, including the United States and the European Union. Where required, we rely on the providers’ standard contractual clauses or equivalent safeguards.
Security
Passwords are hashed, traffic is encrypted in transit, and a strict Content Security Policy is enforced per request. No system is perfectly secure; if a breach affects you we will notify you and the relevant authority as required by law.
Changes to this policy
We will post any changes on this page and update the date above. The current version is effective as of September 10, 2026. Material changes will be announced in the app or by email.
This document is provided in good faith and in plain language. It is not legal advice.