Legal

Privacy Policy

Last updated: July 20, 2026

This Privacy Policy explains how Frame-IA AI ("Frame-IA", "we") collects, uses, and shares personal data when you use our Service. We aim to comply with the EU GDPR, the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA).

1. Data controller

Frame-IA AI is the controller of your personal data. Contact: privacy@frame-ia.app.

2. Data we collect

  • Account data: email, name, hashed password, language.
  • Billing data: plan, subscription status, Stripe customer ID. Card details are handled by Stripe — we never see them.
  • Usage data: generations, prompts, uploaded images, output URLs, credit consumption.
  • Technical data: IP address, device, browser, log events.
  • Cookies: see our Cookie Policy.

3. How we use your data

  • Provide and secure the Service (contract).
  • Process payments and manage subscriptions (contract).
  • Send transactional and, with consent, marketing emails.
  • Improve product quality and prevent abuse (legitimate interest).
  • Comply with legal obligations.

4. AI processing

When you generate an image, the prompt and the source image are sent to third-party model providers (e.g. Black Forest Labs, Google, OpenAI) via our AI gateway. Providers may temporarily process this content to return the result. We do not use your inputs to train foundation models.

5. Sharing

  • Infrastructure: Supabase (database, auth, storage), Cloudflare (edge).
  • Payments: Stripe.
  • AI providers: as described above, only for the generation you request.
  • Legal: when required to comply with law or protect our rights.

We do not sell your personal data.

6. International transfers

Your data may be processed outside your country of residence, including in the United States. When required, we rely on Standard Contractual Clauses or equivalent safeguards.

7. Retention

  • Account data: for the life of your account.
  • Generations and uploads: until you delete them or delete your account.
  • Billing records: as required by tax law (typically 7–10 years).

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, port, restrict or object to processing, and to withdraw consent. Submit requests at privacy@frame-ia.app or via our account deletion page. You also have the right to lodge a complaint with your supervisory authority.

9. Security

We use industry-standard measures including encryption in transit (TLS), encrypted storage, and least-privilege access. No system is 100% secure — please use a strong password.

10. Children

Frame-IA is not intended for children under 18 and we do not knowingly collect their data.

11. Changes

We may update this policy. Material changes will be communicated by email or in-product notice.

12. Contact

privacy@frame-ia.app