Privacy Policy
What our apps and this website collect, what they deliberately do not, and what you can ask us to do about it.
Applies to This document covers every app, website, and service published by FrameFlow Tech, unless a specific product states otherwise on its own page.
Who this covers
FrameFlow Tech ("FrameFlow", "we", "us") publishes applications for Apple platforms and operates the websites and services that support them. This policy applies to all of them, and to frameflowtech.com itself.
A single product may add a notice of its own where a feature needs something this document does not describe. Where such a notice exists, it applies in addition to this policy — never in place of it, and never to weaken it.
For the purposes of the GDPR, FrameFlow Tech is the data controller for the processing described here. You can reach us at the address in the final section.
The short version
- Your photos, videos, and files are read on your device and stay there. We do not upload them, and we cannot see them.
- We do not require an account to use our apps, unless a product plainly needs one and says so.
- We ask for the minimum a feature actually requires, and we prefer designs where there is nothing sensitive to hold in the first place.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
The rest of this page is the detail behind those four statements.
What stays on your device
Our photo and video tools read from the libraries and folders you already keep. Media, thumbnails, the indexes we build to make browsing fast, and any ratings, flags, or edits you apply are stored on your device and in your own iCloud or file system — not on our servers.
Where an app syncs your settings or selections between your own devices, it does so through your personal iCloud account. That data is governed by Apple, is encrypted in transit, and is not readable by us.
Deleting an app removes its local data. Data you chose to sync through iCloud is removed through your Apple account settings, not through us.
What we do collect
- Purchases and subscriptions
- Where a product offers a paid upgrade or subscription, the transaction is handled by Apple. To check whether an entitlement is active, we use a subscription management provider that assigns an anonymous identifier to the installation. That identifier is not your Apple ID, your name, or your email address, and we receive transaction metadata rather than payment details. We never see your card.
- Diagnostics and crash reports
- If you opt in to sharing analytics with developers in your device settings, Apple sends us aggregated crash and performance reports. These describe how the software failed, not who you are or what you were looking at.
- Website logs
- Our web servers record standard request data — IP address, timestamp, requested path, referrer, and user agent — for security, abuse prevention, and troubleshooting. IP addresses are handled as personal data and kept only as long as described below.
- Things you send us
- If you write to us, we keep your message and address for as long as it takes to answer you and to keep a record of the issue. Please do not include sensitive information you do not want us to hold.
- Public catalogue data
- Some of our services collect publicly available product and pricing information from app marketplaces. This data describes software, not people, and contains no personal information.
What we do not collect
- The contents of your photos, videos, documents, or messages.
- Your contacts, calendars, or health data.
- Your precise location. Where an app shows your media on a map, it reads the location already embedded in your own files, on your device.
- Advertising identifiers. We do not run third-party advertising in our apps and we do not track you across other companies’ apps or websites.
Our apps request system permissions — the photo library, the camera, local network access — only when a feature you invoked needs one, and iOS and macOS will always ask you first. Declining a permission disables that feature and nothing else.
Cookies and analytics on this website
This website uses a small number of strictly necessary cookies or local storage entries — for example, to remember your language and appearance preference. These are set on your device, contain no identifiers, and are never shared.
Where we measure traffic, we do so with privacy-preserving, aggregate analytics that do not build a profile of you across sites. If a particular FrameFlow website uses a product that requires consent under applicable law, that site will ask you before anything non-essential is set.
Service providers
We use a small number of providers to run our software. They process data only on our instructions and only for the purposes below.
- Apple
- App distribution, in-app purchase and billing, iCloud sync, and opt-in crash reporting.
- Subscription management
- Validating purchase receipts and entitlements for products that offer subscriptions.
- Hosting, CDN, and email
- Serving our websites and APIs, protecting them from abuse, and delivering the messages you send to us.
Links from our sites or apps to services we do not operate — an app marketplace listing, a support forum, a social account — are governed by those services’ own policies, not this one.
How long we keep things
- Web server logs: retained for a short operational period, typically no more than 30 days, then deleted or aggregated beyond identification.
- Correspondence: retained while the matter is open and for a reasonable period afterwards, so we can recognise a recurring problem.
- Subscription records: retained for as long as the entitlement is active and for the period tax and accounting rules require afterwards.
On-device data has no retention period set by us. It lives on your device until you remove it.
Why we are allowed to process it
Where the GDPR applies, we rely on the following legal bases: performance of a contract, to deliver the app or entitlement you paid for; legitimate interests, to keep our services secure, working, and free of abuse; consent, where we ask for it, which you may withdraw at any time; and legal obligation, where record-keeping rules require it.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Residents of California and similar jurisdictions additionally have the right not to be discriminated against for exercising these rights.
Write to us and we will respond within 30 days. We may need to verify that the request comes from you. Because we hold very little that identifies an individual, the honest answer is often that we have nothing on file — we will tell you plainly when that is the case.
If you are in the EEA or the UK and you believe we have handled your data improperly, you may also complain to your local data protection authority.
Children
Our products are not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, write to us and we will delete it.
International transfers
We operate internationally, and the providers above may process data in countries other than your own, including the United States. Where such a transfer involves personal data from the EEA or the UK, it is made under an approved transfer mechanism, such as the European Commission’s standard contractual clauses.
Security
Traffic to our services is encrypted in transit. Access to the systems that hold any personal data is limited to the people who need it. We keep the amount of such data deliberately small, because the most reliable way to protect information is not to hold it.
No method of transmission or storage is completely secure, and we cannot promise absolute security.
Changes to this policy
When this policy changes we update the date at the top of the page. If a change materially affects how we handle your information, we will say so prominently — in the app, on this site, or both — rather than relying on you to notice a new date.
Contact
Questions about this policy, or a request about your data, both go to the same place: [email protected]. A person reads it.