Send a friend request using an existing member’s exact login ID or email. Previously requests were in-app only; the service now attempts a notification to the verified recipient after saving the request. The email links to Friends, where the recipient signs in and accepts or declines. Emails never accept requests automatically or reveal either member’s email to the other. Check Spam as well as Inbox.
With Features permission, open Admin > Categories. Select an existing category in the hierarchy to edit it, or choose Add category. Enter a name, parent, order and enabled state. Additions need a unique lowercase ID of at most 32 letters, digits or hyphens; existing IDs cannot change. Saving requires your current password and confirmation.
With Security permission, open Admin > Security and scroll to Recent visitor IPs. Enter Rows per page from 1 to 1000, then Apply. The initial value is 25. The same control is available on shared mobile app screens.
A previous security update incorrectly rejected normal browser form submissions under the no-referrer privacy policy. The compatibility fix accepts Origin: null only when the browser reports Sec-Fetch-Site: same-origin, then still verifies the session CSRF token. Privacy and cross-site protection remain enabled.
Open Admin > Security for 16 known attack families and controlled block-test scores. A score is passing assertions divided by attempted assertions, not a real-world block rate, threat coverage or security guarantee. Untested, stale and host-managed defenses have no percentage. The table shows request-guard and abuse-review switch state separately.
Search controls are grouped into Item and place, Date and distance, and Display options. Every existing field remains available. Expand City & landmark tools beneath Location for city checks and nearby places; typing suggestions and validation still appear outside that disclosure. Apply and Reset filters keep their existing saved-default behavior. Phone location remains optional.
With Security permission, open IP monitor or Live monitor. Period accepts 1 to 10080 minutes (7 days); the initial period remains 15 minutes. Recent contacts accepts 1 to 1000 rows, default 100. Change either control or press Refresh now. The recent table heading shows the selected limit and actual rows displayed.
Open a chat with an accepted friend. An initially empty chat now catches up from the first unseen message in batches of 50, even if more than 50 arrive before polling. Latest messages shows the newest 50; Older messages provides retained history. The live display stays bounded to 100 messages. Invalid or mixed history cursors are rejected instead of silently showing a different page.
Choose a reporting period for request and location totals. Active IPs · 5 min always counts the last five minutes, including when the selected reporting period is shorter; it still respects the exact-IP filter. Watch alerts also use five minutes, across watched addresses. All figures use only retained events.
Open Admin > IP monitor with Security permission. Top locations defaults to 20; choose any count from 1 to 100. Set Period in minutes from 1 to 10080 (7 days), then Refresh now. Recent contacts defaults to 100; choose any count from 1 to 1000. This caps the newest matching contact rows only, not location/IP totals or their pagination. Changing a control refreshes automatically. The same duration and exact-IP filter apply to the table and map, independently of IP pagination and sorting.
Inbox & claims displays 50 authorized conversations per page. Use Previous and Next to reach older threads; inaccessible private reports are removed before counting or paging, so they cannot crowd out eligible threads.
An item inquiry can become an ownership claim using This may be mine with new private details. The existing messages and original evidence remain private in the same thread. Closed inquiries can restart while the report remains available; closed claims require new claim evidence. Rejected claims stay rejected, including after report renewal. Block a participant to prevent further contact; closing a thread alone is not a block.
Open Feature tests and choose Run this check beside a safe automated check. The chosen result has its own timestamp, release fingerprint, failure detail and debug guide. Informational/manual observations remain labeled; compatibility checks share read-only platform prerequisites.
Open Live monitor for traffic plus hosting usage, or IP monitor for IP-specific statistics. Choose a time period, exact IP, sort and page. Contacts count recorded PHP requests, not people; frequency is per minute averaged across the selected period. City/region (or country fallback) is a local DB-IP Lite estimate, not precise location. Use the Connection locations and map guide for top-count and custom-period controls.
Open Posts → Purge resolved items to preview eligible returned/closed records. The schedule is off by default.
The configured owner keeps full access. Additional assignments are optional and OFF initially; enable Allow assigning administrators in Features to grant approved users a role.
Approved engineers download the sanitized source archive from Engineering. Production credentials, database backups and deployment/signing keys are not included.
Open Backups with backup permission. Schedule changes also require Features permission. Daily snapshots run after the configured UTC hour; Run now queues a job for the maintenance worker. Check status and validate artifact checksums.
Open Compatibility to check the actual current PHP/database versions, required extensions, charset, SQL primitives and transactional engines. Web and cron runtimes can differ.
Open Hosting usage for timestamped account statistics and a current LostaFound database-size estimate. Account totals include all your domains.
Create an account with your email and a unique password of 12–72 bytes. Open the verification email and confirm using that password.
Sign in → Profile. Enter a display name and optional unique login ID, then Save profile. Changing the ID requires your current password. Email still works for login.
Sign in with a verified account. Choose Lost or Found, category, title and description. Keep phone numbers, emails, private addresses and hidden identifying details out of public fields.
In a report, choose a photo, use the camera option on a supported phone, or open Draw and save your drawing. Review the preview before submitting.
Blank keywords match all items allowed by the other filters. Select Lost and/or Found, category, location and reported UTC dates; Apply filters. Category chips follow the other filters.
Type a city; select the intended suggestion, especially for ambiguous city names. Nearby cities and Check city can help. A typed custom location remains available.
Set a city or optional map center, then choose Nearby landmarks and a category. Find landmarks sends the rounded center to the external provider only after your action.
Enter a friend’s exact login ID or email and send a request. They accept it from Friends. Eligible verified existing members receive a notification email when enabled; unknown addresses are never invited. Delivery is subject to provider and anti-spam limits. There is no public account directory. Both accounts have a combined limit of 200 friends and pending requests. A generic response does not confirm delivery to an unknown, unavailable or full account. Remove or cancel unused connections to free slots. Accepting an existing request at exactly 200 uses its current slot; legacy overflow must be reduced first.
Open Friends → Chat beside an accepted friend. Write a message and send. Messages refresh while the page is visible; use older messages for history.
Open a Found item → This may be mine. Describe identifying marks or contents that are not publicly visible. Do not upload identity documents.
Open My reports to edit your own listings and pictures. Mark returned only after an actual return, or close a listing that is no longer relevant.
Choose one of your open reports and a radius; save a matching subscription. Opt into matching emails if wanted.
Open the item or conversation and choose Report abuse. Pick a reason and give useful details without unnecessary personal data.
Verified email, honeypots and account/IP submission limits help reduce fake signups and floods. They cannot prove a real person or legitimate item.
Payments are off by default. When configured and enabled by the owner, a Lost report uses a $1 USD default with optional increase and a 50% conditional finder share. Found reports are free.
Android: use the download page and follow your device’s installation confirmation. Google Play publication requires the owner’s developer-account setup; do not assume the app is listed there.
Visitor counts are distinct server-observed IPs per UTC day, not people. Download counts are link requests, not completed installs. Detailed IP records are private and expire after the configured retention period.