Everyone has the photo. Nobody can share it.
A package lands on the wrong porch. The finder knows an address, the owner knows a tracking number — but there’s no directory of doors, and posting it publicly is a privacy problem wearing a good deed.
Handback is built on an awkward truth: the helpful thing is also the dangerous thing. So the system is designed to leak nothing — even when it works.
The system knows less than it seems
A finder photographs the label — never a name, never a lookup. The app runs OCR on the photo itself, matches name-and-address against claims privately, and the finder’s result looks identical whether or not anyone matched.
Only the verified recipient ever learns a package exists. Nobody can probe the system for “did my neighbor report my parcel” — the answer is a shrug, by design.

Two photos, one code
Capture is deliberately tiny: front of label, back of label, done. From there the handoff is a meetup arranged in-app and confirmed with a rotating pickup code — the finder only hands the box to the person who holds it.
ID verification through Didit is the gate that makes the whole thing safe: the person claiming has to be the person on the label.

Where it sits now
Version 1.0 is live on the App Store and Google Play, backed by a gateway that rate-limits and screens requests before they ever reach the API — App Check, Redis limits, a private core that does matching with Postgres trigrams.
Private recovery turns out to be mostly an exercise in saying less. The neighborly part is easy; the privacy part is the product.